TeamPCP Hackers Focus on AI Developers, Planting Malicious Code to Disrupt Projects
ID: 35453ade-a356-5af3-9dd9-c12ded093659
STIX ID: report--35453ade-a356-5af3-9dd9-c12ded093659
Feed Name: GBHackers
Threat Score
The FBI warns that TeamPCP executed a large supply-chain compromise by first stealing GitHub authentication keys from the open-source Trivy scanner and then using those credentials to inject malicious code into the LiteLLM AI gateway, distributing infected updates to an estimated tens of millions of developers; the group used AI tools to automate malware/script generation and appears to monetize access by selling to ransomware operators or extorting victims.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
