Cyber Magazine October 2026 | Page 27

This is a cocktail that enterprises drink at their peril in the age where software supply chain attacks are constant – Axios, LiteLLM, TanStack and Trivy are some recent supply chain poisonings with enormous downstream blast radius.
Zeki picks Altered Spider, the adversary commonly referred to as TeamPCP, as an example.“ We saw them target over 300 software dependencies in a single day,” he says.“ And literally what we’ re seeing nearly every other day is one of these library files being targeted by highly capable threat actors, utilising them to do various things – to get it into organisations, deploy crypto miners all the way down to trying to steal sensitive information such as administrational passwords and usernames to be sold off elsewhere.”
Hence,“ organisations are opened up to massive supply chain risk”, Zeki says, as they bring in“ new technologies into their environment that they don’ t know or understand, while the adversary is already well ahead trying to target them because they see it as being a soft area of target.”
cybermagazine. com 27