Trellix Confirms Source Code Breach With Unauthorized Repository Access
2026-05-02T07:24:10Z•5027445e767a64ac58b159cc03814c44f2e60bcdb2f90502aafe641daf37429a
AccountDumplingDEEP#DOORGoogle-AppSheetSSO-abuseSaaS-extortionVECT-2.0active-exploitationbackdoorchina-linkedcredential-theftdprk-linkedetherRATgit-repo-rcegithub-actions-tamperinggo-modulesnation-state-espionagephishingphishing-relayruby-gemssource-code-breachsupply-chainsupply-chain-npmsupply-chain-pypivishingwiper-ransomware
What happened
Aggregated reporting from The Hacker News describes a wave of high-impact incidents and active threats across software supply chains, cloud/SaaS environments, and nation-state espionage. Notable items include a Trellix source-code repository compromise, a large Google AppSheet-based phishing operation (AccountDumpling) affecting ~30,000 Facebook accounts, and rapid SaaS-targeting extortion using vishing and SSO abuse by criminal clusters (Cordial Spider / Snarky Spider). Multiple supply chain campaigns and credential-stealing malware were observed — including malicious Ruby gems, Go modules, N
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- the_hacker_news
- Record identifier
- 5027445e767a64ac58b159cc03814c44f2e60bcdb2f90502aafe641daf37429a
- Enrichment time
- 2026-05-02T07:24:10Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.