Supply Chain Confidence: What Every Organisation Needs to Know
ID: c34780c3-7c13-542c-8f79-d2a9c2ff4084
STIX ID: report--c34780c3-7c13-542c-8f79-d2a9c2ff4084
Feed Name: Ransomware ISAC Blog
Date Published: 2026-04-03
Date Updated: 2026-07-28
Author: [email protected] (Ransom-ISAC Research Team)
# Executive summary Between late February and March 2026 TeamPCP executed a large, multi-stage software supply chain campaign compromising CI/CD tooling and popular packages (Trivy, Checkmarx KICS, LiteLLM, Telnyx, numerous npm packages) to steal credentials from thousands of pipelines, deploy credential-stealers and RATs, exfiltrate terabytes of sensitive data, and partner with ransomware groups for mass extortion; the report details timelines, common tactics (mutable references, long-lived tokens, trusted security tools), IOCs, and prioritized mitigation steps such as SHA-pinning, short-lived tokens/OIDC, secret scanning, package firewalls, and rebuild-and-rotate remediation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
