VECT and TeamPCP Reverse Ransomware Kill Chain With Supply Chain Credential Theft
ID: a920e0d0-4813-5e10-b4c6-ed4aec268043
STIX ID: report--a920e0d0-4813-5e10-b4c6-ed4aec268043
Feed Name: cybersecurityNews.com
**Executive summary:** The report describes a large-scale supply-chain campaign where TeamPCP tampered with widely used open-source packages (notably LiteLLM v1.82.8, Trivy GitHub Action v0.76/x and v0.77/x, Checkmarx KICS, and Telnyx SDK 4.87.x) to harvest developer and CI/CD credentials and provide a ready-made victim pool for the VECT ransomware operation; FBI IC3 FLASH-20260702-001 plus vendor analyses (Vectra AI, Sophos, Check Point Research) confirm active exploitation, list technical indicators (e.g., litellm_init.pth, hidden repo docs-tpcp), and recommend credential rotation, log audits, and searching installation directories for the malicious payload.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
