TeamPCP Threat Actor Report
ID: 99ff042d-1bf3-5b86-8889-076b5867e429
STIX ID: report--99ff042d-1bf3-5b86-8889-076b5867e429
Feed Name: ThreatMon
TeamPCP is a financially motivated cybercrime group that emerged in late 2025 and evolved from exploiting exposed cloud infrastructure to executing large-scale software supply-chain compromises in 2026. The campaign compromised trusted developer and security tools (including Trivy, Checkmarx KICS, LiteLLM gateway, Telnyx SDK) and delivery ecosystems (GitHub Actions, Docker Hub, npm, PyPI, OpenVSX), resulting in over 1,000 affected SaaS environments, approximately 500,000 compromised credentials, and more than 300 GB of exfiltrated data; the group used a chained compromise model to cascade access and has ties to multiple ransomware operations including a partnership with Vect and its own CipherForce brand.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
