logo

TeamPCP Breaches Cloud, SaaS Instances With Stolen Credentials

ID: b4a8eebb-70a2-525c-9d57-07d75bec3e86

STIX ID: report--b4a8eebb-70a2-525c-9d57-07d75bec3e86

Feed Name: Dark Reading

Threat Score
85/100

Date Published: 2026-03-31

Date Updated: 2026-04-22

Author: Rob Wright

...
...

TeamPCP has been performing supply-chain attacks by poisoning multiple open-source projects (Trivy, KICS, LiteLLM, Telnyx) to distribute infostealer malware, harvest credentials and secrets, then quickly validate and weaponize those credentials to access AWS, Azure, GitHub and other SaaS environments for enumeration, data exfiltration, and container abuse; affected organizations are advised to rotate/revoke secrets, enable audit logging, and hunt for anomalous activity.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.