logo

Supply Chain Confidence: What Every Organisation Needs to Know

ID: c34780c3-7c13-542c-8f79-d2a9c2ff4084

STIX ID: report--c34780c3-7c13-542c-8f79-d2a9c2ff4084

Feed Name: Ransomware ISAC Blog

Threat Score
92/100

Date Published: 2026-04-03

Date Updated: 2026-07-28

Author: [email protected] (Ransom-ISAC Research Team)

...
...

# Executive summary Between late February and March 2026 TeamPCP executed a large, multi-stage software supply chain campaign compromising CI/CD tooling and popular packages (Trivy, Checkmarx KICS, LiteLLM, Telnyx, numerous npm packages) to steal credentials from thousands of pipelines, deploy credential-stealers and RATs, exfiltrate terabytes of sensitive data, and partner with ransomware groups for mass extortion; the report details timelines, common tactics (mutable references, long-lived tokens, trusted security tools), IOCs, and prioritized mitigation steps such as SHA-pinning, short-lived tokens/OIDC, secret scanning, package firewalls, and rebuild-and-rotate remediation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.