logo

Australian Police Charge Two Over TeamPCP Credential Theft

ID: 08881fb7-7447-5f2f-a848-2d1f0b3a6b01

STIX ID: report--08881fb7-7447-5f2f-a848-2d1f0b3a6b01

Feed Name: Security Affairs

Threat Score
90/100

Date Published: 2026-08-27

Date Updated: 2026-08-28

Author: Pierluigi Paganini

...
...

Australian authorities charged two men allegedly linked to TeamPCP after a coordinated supply-chain operation secretly injected credential-stealing and worm malware into popular open-source packages (PyPI, npm), potentially compromising 1,000+ organizations, exfiltrating ~300 GB of data and stealing over 500,000 credentials; affected tools include Trivy, KICS, LiteLLM and the Telnyx Python SDK, and notable malware families are CanisterWorm, SANDCLOCK, Mini Shai-Hulud and Miasma, with IOCs such as GitHub repos named tpcp-docs and docs-tpcp.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.