logo

TeamPCP Supply Chain Attacks Feed VECT Ransomware With Stolen CI/CD Credentials

ID: d1c49c38-e35c-5d45-8101-821ac0ca4eca

STIX ID: report--d1c49c38-e35c-5d45-8101-821ac0ca4eca

Feed Name: GBHackers

Threat Score
90/100

Date Published: 2026-07-07

Date Updated: 2026-07-21

Author: Mayura Kathir

...
...

TeamPCP conducted large-scale supply‑chain compromises of developer tools and CI workflows—injecting malicious workflow code and a persistent Python loader into packages like Trivy, Checkmarx KICS, LiteLLM, and the Telnyx Python SDK—to harvest CI/CD and cloud credentials at scale (reported ~500,000 credentials from 10,000+ pipelines). Those credentials formed an inventory used by VECT ransomware operators to select and successfully deploy ransomware; the report includes exploited CVE-2026-33634, affected product versions (e.g., LiteLLM v1.82.8, Telnyx 4.87.1/4.87.2), forensic IOCs (litellm_init.pth, docs-tpcp repos), the VECT encryption flaw, and immediate remediation steps such as rotating pre‑April 2026 credentials and auditing pipeline activity.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.