Trellix Confirms Source Code Breach With Unauthorized Repository Access

2026-05-02T07:24:10Z5027445e767a64ac58b159cc03814c44f2e60bcdb2f90502aafe641daf37429a
AccountDumplingDEEP#DOORGoogle-AppSheetSSO-abuseSaaS-extortionVECT-2.0active-exploitationbackdoorchina-linkedcredential-theftdprk-linkedetherRATgit-repo-rcegithub-actions-tamperinggo-modulesnation-state-espionagephishingphishing-relayruby-gemssource-code-breachsupply-chainsupply-chain-npmsupply-chain-pypivishingwiper-ransomware

What happened

Aggregated reporting from The Hacker News describes a wave of high-impact incidents and active threats across software supply chains, cloud/SaaS environments, and nation-state espionage. Notable items include a Trellix source-code repository compromise, a large Google AppSheet-based phishing operation (AccountDumpling) affecting ~30,000 Facebook accounts, and rapid SaaS-targeting extortion using vishing and SSO abuse by criminal clusters (Cordial Spider / Snarky Spider). Multiple supply chain campaigns and credential-stealing malware were observed — including malicious Ruby gems, Go modules, N

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
the_hacker_news
Record identifier
5027445e767a64ac58b159cc03814c44f2e60bcdb2f90502aafe641daf37429a
Enrichment time
2026-05-02T07:24:10Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.