Threat group UNC6780 conducted extensive supply chain compromises targeting PyPI, npm, and Docker Hub ecosystems.
Feb 1, 2026
182d agoKey Details
- Exploited GitHub Actions pull_request_target triggers to steal secrets
- Deployed SANDCLOCK credential stealer malware
- Attempted to pivot from compromised AI software to enterprise networks