FBI Warns of TeamPCP Supply Chain Attack
ID: ecbe90ff-2ffc-508e-951d-266a72d20bb0
STIX ID: report--ecbe90ff-2ffc-508e-951d-266a72d20bb0
Feed Name: securityonline.info
The FBI issued an urgent FLASH alert warning that TeamPCP conducted a large-scale 2026 software supply chain campaign by injecting malicious code into popular developer and security packages (e.g., Trivy, KICS, LiteLLM, Telnyx SDK), deploying credential-stealing malware (CanisterWorm, SANDCLOCK) and self-replicating worms across npm and PyPI to harvest cloud tokens, SSH keys, Kubernetes secrets and establish persistent access; the report includes exploited CVEs, attribution to TeamPCP, and immediate mitigation guidance such as pinning workflows, rotating credentials, enforcing MFA, auditing maintainer accounts, and delaying acceptance of new packages.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
