Package registry attacks shift risk from code to identity.
Article excerpt
Highlighted: the sentence this signal was extracted from
Package registry attacks shift risk from code to identity. West Pharmaceutical Services, a Pennsylvania manufacturer with over 10,000 employees and $3 billion in annual revenue, reported on May 4, 2026, that a ransomware attack disrupted global shipping, receiving, and manufacturing operations. The company disclosed that critical systems were encrypted and data exfiltrated, forcing a shutdown of on-premise infrastructure. While core enterprise systems have been restored and critical processes restarted at some sites, the timeline for complete restoration remains undefined. The incident represents a direct operational impact: production facilities idled, supply chains disrupted, and a quantifiable exposure window measured in days or weeks rather than hours. The compromise arrived as software supply chain infrastructure became the breach vector itself. RubyGems suspended new account registrations after hundreds of malicious packages were uploaded in what Mend.io's senior product manager characterized as a major attack. TeamPCP, a persistent threat actor, compromised npm and PyPI packages from TanStack, Mistral AI, Guardrails AI, and others using a malware variant called Mini Shai-Hulud. The attack injected obfuscated JavaScript files into legitimate packages, harvesting credentials from cloud providers, cryptocurrency wallets, AI tools, and CI/CD systems including GitHub...
Keep reading with a free account
The rest of this article, and every signal for West Pharmaceutical Services, is in your free account.
