// 2 ZERO-DAY · 4 CVE · 2 EXPLOIT · 1 ADVISORY IN THE LAST 24H→
The EC breach documents a disturbing pattern: install-time malware on npm packages steals cloud credentials before execution, turning developer workstations and CI/CD runners into gateways for institutional breaches.

On March 19, 2026, a threat actor obtained an AWS secret with management rights over other European Commission accounts. From there, they exfiltrated 91.7 GB compressed, equivalent to 340 GB uncompressed, from the europa.eu web hosting service. Data published by ShinyHunters on March 28 included 51,992 files (2.22 GB) of outbound email communications. Forty-two internal Commission clients and 29+ other EU entities were potentially affected.

The initial access was not a traditional cloud attack. CERT-EU confirmed with high confidence that it passed through the supply chain compromise of Trivy, an open-source container security scanner, publicly attributed to the threat actor TeamPCP. The EC case is not isolated. It documents a systemic pattern emerging in 2025-2026: install-time malware on npm packages that steals cloud credentials before the application runs, turning developer workstations and CI/CD runners into gateways for institutional breaches.

Key Takeaways

  • The European Commission breach (91.7 GB compressed, 340 GB uncompressed) originates from the Trivy supply chain compromise, with 42 internal clients and 29+ EU entities affected
  • The Shai-Hulud campaign compromised 639 package versions across 323 packages in the @antv ecosystem, exploiting npm's preinstall hook to steal credentials before execution
  • UNC6426 demonstrated lethal speed: from stolen GitHub token to AWS administrator permissions in under 72 hours
  • Coordinated attacks on April 21-23, 2026 hit npm, PyPI, and Docker Hub with shared C2 infrastructure between Checkmarx KICS and Bitwarden CLI
  • The Qualys-proposed framework — that the developer is the new perimeter — is corroborated by multiple independent campaigns, but remains an evolving analytical model
"91.7 GB compressed (340 GB uncompressed) exfiltrated from AWS; 42 internal clients and 29+ EU entities potentially affected"

The Mechanism: Credentials Stolen Before Execution

Traditional defenses focus on running code. Install-time malware bypasses this assumption. npm preinstall hooks execute during installation, not after. Even if the user cancels the installation, the hook has already run.

Qualys Threat Research articulates the framework: "The central argument is that once install-time malware exposes credentials capable of accessing cloud resources, a software supply chain incident can become a cloud identity incident". The transition requires no cloud vulnerability: it exploits legitimate credentials in standard locations.

Credentials reside in predictable files — ~/.aws/credentials, .npmrc, .netrc, GITHUB_TOKEN, KUBECONFIG, VAULT_TOKEN — and are harvested during installation itself. As Qualys notes: "A developer workstation or continuous integration and continuous delivery (CI/CD) runner is not just a coding machine. It is a nexus of credentials". Subsequent API calls use valid credentials, evading detection based on behavioral anomalies.

The Five Campaigns Corroborating the Pattern

Five documented campaigns between 2025 and 2026 trace the evolution of the pattern. They are not all linked: attribution varies, targets differ, but they share the fundamental mechanism — install-time credential harvesting enabling cloud breach.

Shai-Hulud (September 2025 – May 2026): The original campaign compromised popular npm packages including @ctrl/tinycolor. By May 2026, Mini Shai-Hulud shifted the attack to the preinstall hook, compromising 639 versions across 323 packages in the @antv ecosystem. The package echarts-for-react, with 1.1 million weekly downloads, was among those hit. Trend Micro analyzed Shai-Hulud 2.0: targets AWS, GCP, Azure, npm tokens, GitHub authentication; GitHub Actions workflows for C&C; parallel backdooring of up to 100 packages simultaneously.

The evasion mechanism is refined. The Bun runtime evades detection. A background process with unref() completes npm install in normal time. Qualys underscores: "The practical lesson is that a user does not need to run the application for the cloud exposure to begin" — specifically for Shai-Hulud's preinstall hook.

TeamPCP / Trivy (March 2026): The compromise of the Trivy scanner, Checkmarx KICS, LiteLLM, and Telnyx used stolen GitHub PATs to force-push malicious commits. The team bypassed secret masking by reading runner process memory. From here, the path led to the EC breach.

Checkmarx KICS and Bitwarden CLI (April 21-23, 2026): Coordinated attacks within 48 hours on npm, PyPI, and Docker Hub. The two packages shared the C2 domain audit.checkmarx.cx. KICS counted 5 million cumulative pulls on Docker Hub. Bitwarden CLI, with 70,000+ normal weekly downloads, had the malicious version 2026.4.0 live for approximately 90 minutes. Sophos detected similar payloads with the Bun runtime. No evidence links this to TeamPCP.

UNC6426 (August 2025): The case documented in the Google Cloud Threat Horizons Report H1 2026 shows lethal speed. From nx npm supply chain compromise to AWS admin access in under 72 hours: stolen GitHub token → Nord Stream for CI secrets → GitHub Actions-CloudFormation role → deploy stack with CAPABILITY_NAMED_IAM → AdministratorAccess policy. The role was excessively permissive, but the attack exploited legitimate credentials.

OpenSearch/ElasticSearch Typosquatting (May 28, 2026): 14 npm packages stole secrets, then used stolen publish tokens to infect additional packages of legitimate maintainers.

The EC Breach: Where the Pattern Meets Institutional Impact

The European Commission incident is the most severe documented cloud breach among those analyzed. CERT-EU confirmed the supply chain origin with high confidence: "We assess with high confidence that initial access was obtained through the Trivy supply-chain compromise, which was publicly attributed to a threat actor known as TeamPCP".

The timeline is precise. On March 19, 2026, the threat actor obtained the AWS secret. Exfiltration followed immediately. The data appeared online nine days later. The scope — 42 internal clients, 29+ EU entities — reflects the centrality of the europa.eu service.

CERT-EU did not document full lateral movement, but flagged that the secret possessed management rights over additional accounts. This limit is relevant: we do not know whether the actor exploited this capability beyond the documented exfiltration.

What Changes

The framework proposed by Qualys — that the developer is the new perimeter — is not isolated marketing. It is corroborated by multiple independent campaigns, government advisories, and vendor reports. It remains, however, an evolving analytical model, not a settled truth.

The implications are threefold. First: the moment of risk shifts upstream, from execution to installation. Second: the attack surface includes package managers, registries, and lifecycle hooks, not just application code. Third: the speed of escalation — 72 hours in UNC6426, 90 minutes of exposure for Bitwarden CLI — compresses detection windows.

Not all campaigns are solvable the same way. Some patches are in progress as of the sources. Attribution is not uniform: TeamPCP is confirmed for Trivy/EC, but Checkmarx/Bitwarden remain unlinked with certainty.

Open Unknowns

The analysis leaves unanswered questions. Who orchestrated Checkmarx/Bitwarden? Sophos rules out links to TeamPCP but offers no alternative attribution. How far did lateral movement extend in the EC? CERT-EU found no evidence, but management rights existed. How many downstream maintainers of Shai-Hulud were compromised beyond the documented packages?

These unknowns do not weaken the pattern. They make it more dangerous: a replicable attack model, with unattributed variants, that exploits trust in development toolchains to compromise institutional cloud infrastructure.

The Qualys source has a commercial interest in promoting TotalCloud/TruRisk. The technical evidence of the campaigns is independent of the product, but the conceptual framework should be read with this awareness.

Sources: Qualys Threat Research; CERT-EU; Trend Micro; Sophos; The Hacker News / Google Cloud Threat Horizons Report H1 2026. This article is based primarily on Qualys analysis, corroborated by government and vendor reports. Some campaigns lack confirmed attribution.

Information has been verified against cited sources and updated as of publication.

Sources


Sources and references
  1. blog.qualys.com
  2. cert.europa.eu
  3. trendmicro.com
  4. sophos.com
  5. thehackernews.com