TeamPCP Targets Software Build Systems In Credential-Theft Campaign
ID: 38e3bc7a-4a73-565f-ab0d-e6c7539d746e
STIX ID: report--38e3bc7a-4a73-565f-ab0d-e6c7539d746e
Feed Name: Cyber Press
**TeamPCP supply-chain campaign (Mar–Apr 2026):** A financially motivated threat group conducted multi-channel supply-chain compromises of developer tooling and package ecosystems — poisoning Docker Hub images, VS Code extensions, GitHub Actions workflows, and PyPI packages — to deliver JavaScript and Python credential-stealing malware that harvested GitHub tokens, AWS keys, CI tokens and other secrets, exploited signed releases and CI permissions to persist and propagate, and used encrypted exfiltration and fallback C2 in commit messages to maintain access.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
