logo

Your Supply Chain Breach Is Someone Else's Payday

ID: 093158dd-0c7e-5765-a15f-6c0936d2298b

STIX ID: report--093158dd-0c7e-5765-a15f-6c0936d2298b

Feed Name: Recorded Future Blog

Threat Score
90/100

Date Published: 2026-04-15

Date Updated: 2026-04-29

...
...

TeamPCP used stolen developer credentials to push credential-harvesting malware into widely used software (including the LiteLLM Python package and Checkmarx GitHub Actions), exfiltrating API keys, cloud credentials, and secrets and causing cascading supply-chain compromises across five ecosystems; the campaign enables extortion, payroll redirection, logistics fraud, and other large-scale impacts, and the report recommends immediate credential rotation, pipeline audits, dependency pinning, and continuous AI-driven integrity and identity monitoring.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.