logo

VECT and TeamPCP Reverse Ransomware Kill Chain With Supply Chain Credential Theft

ID: a920e0d0-4813-5e10-b4c6-ed4aec268043

STIX ID: report--a920e0d0-4813-5e10-b4c6-ed4aec268043

Feed Name: cybersecurityNews.com

Threat Score
88/100

Date Published: 2026-07-07

Date Updated: 2026-07-07

Author: Tushar Subhra Dutta

...
...

**Executive summary:** The report describes a large-scale supply-chain campaign where TeamPCP tampered with widely used open-source packages (notably LiteLLM v1.82.8, Trivy GitHub Action v0.76/x and v0.77/x, Checkmarx KICS, and Telnyx SDK 4.87.x) to harvest developer and CI/CD credentials and provide a ready-made victim pool for the VECT ransomware operation; FBI IC3 FLASH-20260702-001 plus vendor analyses (Vectra AI, Sophos, Check Point Research) confirm active exploitation, list technical indicators (e.g., litellm_init.pth, hidden repo docs-tpcp), and recommend credential rotation, log audits, and searching installation directories for the malicious payload.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.