Blast Radius of TeamPCP Attacks Expands Amid Hacker Infighting
ID: 5015b573-02b0-5a38-bf9b-a48914902465
STIX ID: report--5015b573-02b0-5a38-bf9b-a48914902465
Feed Name: Dark Reading
TeamPCP conducted high-impact supply-chain attacks by distributing compromised versions of open-source tools (notably Trivy and a Telnyx PyPI package) that harvested credentials and secrets; those credentials were used to access AWS and other cloud resources, enabling rapid reconnaissance and data exfiltration. Third-party criminal groups (ShinyHunters, Lapsus$) have surfaced stolen data for extortion, and TeamPCP’s announced alliance with the Vect ransomware gang raises the risk of widespread ransomware deployment; recommended immediate actions include revoking and rotating exposed secrets, invalidating tokens, and hunting for malicious CI/CD and cloud activity.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
