TeamPCP Supply Chain Attacks Feed VECT Ransomware With Stolen CI/CD Credentials
ID: d1c49c38-e35c-5d45-8101-821ac0ca4eca
STIX ID: report--d1c49c38-e35c-5d45-8101-821ac0ca4eca
Feed Name: GBHackers
TeamPCP conducted large-scale supply‑chain compromises of developer tools and CI workflows—injecting malicious workflow code and a persistent Python loader into packages like Trivy, Checkmarx KICS, LiteLLM, and the Telnyx Python SDK—to harvest CI/CD and cloud credentials at scale (reported ~500,000 credentials from 10,000+ pipelines). Those credentials formed an inventory used by VECT ransomware operators to select and successfully deploy ransomware; the report includes exploited CVE-2026-33634, affected product versions (e.g., LiteLLM v1.82.8, Telnyx 4.87.1/4.87.2), forensic IOCs (litellm_init.pth, docs-tpcp repos), the VECT encryption flaw, and immediate remediation steps such as rotating pre‑April 2026 credentials and auditing pipeline activity.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
