logo

Blast Radius of TeamPCP Attacks Expands Amid Hacker Infighting

ID: 5015b573-02b0-5a38-bf9b-a48914902465

STIX ID: report--5015b573-02b0-5a38-bf9b-a48914902465

Feed Name: Dark Reading

Threat Score
88/100

Date Published: 2026-04-03

Date Updated: 2026-04-22

Author: Rob Wright

...
...

TeamPCP conducted high-impact supply-chain attacks by distributing compromised versions of open-source tools (notably Trivy and a Telnyx PyPI package) that harvested credentials and secrets; those credentials were used to access AWS and other cloud resources, enabling rapid reconnaissance and data exfiltration. Third-party criminal groups (ShinyHunters, Lapsus$) have surfaced stolen data for extortion, and TeamPCP’s announced alliance with the Vect ransomware gang raises the risk of widespread ransomware deployment; recommended immediate actions include revoking and rotating exposed secrets, invalidating tokens, and hunting for malicious CI/CD and cloud activity.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.