
When the Security Scanner Became the Weapon: Inside the TeamPCP Supply Chain Attack
Source: YouTube · SANS Cloud Security · published Mar 27, 2026 · 59:03
BLUF: This webcast analyzes a critical CI/CD supply chain attack involving a stolen token that cascaded across five ecosystems in six days, exploiting GitHub Actions to compromise multiple software projects 0:14.
Key Takeaways:
• The attack is described as potentially the most significant CI/CD supply chain incident to date, with immediate operational relevance as the campaign remains active 0:14.
• A single stolen token was the initial vector, leading to a cascading failure across five distinct ecosystems over a period of six days 0:48.
• The structure of the analysis breaks the incident down into four acts, starting with the initial compromise and technical details of the attack vector 0:43.
• GitHub Actions played a central role in enabling the attack, highlighting vulnerabilities in how CI/CD pipelines handle authentication and permissions 0:26.
Closing Statement:
Attendees are urged to take immediate action to secure their CI/CD environments against similar token-based supply chain attacks.
Sources:
Generate CPE Credits
Generate a professional CPE document from this video's transcript.
Estimated credit: 1 CPE hours
Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.
Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.
Free account. One generation at a time, with a daily limit.
CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.
Transcript Preview
First 800 characters of the transcript
Well, welcome everybody to the Sans emergency webcast. I'm Ken Hartman, a Sans certified instructor, and I'm joined by my friend and colleague Eric Johnson. He's a Sans fellow. We're here because of what may be the most significant CI/CD supply chain attack we've seen to date. Over the next hour, we'll walk you through exactly what happened, how it worked, and why GitHub Actions made it possible. And most importantly, what you can do about it right now. This campaign is still active as of today, so everything we're covering has immediate operational relevance. And here's our agenda. We've structured this as a story in four acts. First, we'll tell you what happened, how one stolen token cascaded across five ecosystems in six days. Then Eric will take us through the technical details of how …