logo

FBI Warns TeamPCP Hackers Compromise Developer Tools in Large-Scale Supply Chain Attacks

ID: 785e65a7-c6ab-54f1-ac9d-595e20bc11a7

STIX ID: report--785e65a7-c6ab-54f1-ac9d-595e20bc11a7

Feed Name: cybersecurityNews.com

Threat Score
88/100

Date Published: 2026-07-03

Date Updated: 2026-07-03

Author: Tushar Subhra Dutta

...
...

TeamPCP has been conducting large-scale software supply chain attacks by trojanizing widely used developer and security tools (including Trivy, KICS, LiteLLM, and the Telnyx Python SDK) to steal cloud tokens, SSH keys, Kubernetes secrets, and deploy persistent backdoors and extortion, with FBI guidance and numerous IoCs (IPs, domains, file hashes) and CVEs provided in the report.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.