Supply Chain Confidence: What Every Organisation Needs to Know
ID: 7f9efbe9-e4a7-5953-8494-b45ecb45cc1b
STIX ID: report--7f9efbe9-e4a7-5953-8494-b45ecb45cc1b
Feed Name: Ransomware ISAC Blog
Date Published: 2026-04-03
Date Updated: 2026-08-21
Author: [email protected] (Ransom-ISAC Research Team)
**Executive summary:** This Ransom-ISAC report details a high-impact, coordinated software supply chain campaign by a threat actor calling itself TeamPCP that abused mutable references and long-lived credentials to compromise tools and packages (Trivy, Checkmarx KICS, LiteLLM, Telnyx, dozens of npm packages), steal credentials at scale, establish persistent presence on developer and production systems, and partner with ransomware groups (CipherForce, Vect) to monetise access and exfiltrated data; the document contains a condensed timeline, IOCs, detection guidance, and prioritized remedial actions (SHA-pinning, token expiry, secrets management, package firewalls, runner hardening).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
