logo

TeamPCP Threat Actor Report

ID: 99ff042d-1bf3-5b86-8889-076b5867e429

STIX ID: report--99ff042d-1bf3-5b86-8889-076b5867e429

Feed Name: ThreatMon

Threat Score
90/100

Date Published: 2026-07-28

Date Updated: 2026-07-28

Author: admin

...
...

TeamPCP is a financially motivated cybercrime group that emerged in late 2025 and evolved from exploiting exposed cloud infrastructure to executing large-scale software supply-chain compromises in 2026. The campaign compromised trusted developer and security tools (including Trivy, Checkmarx KICS, LiteLLM gateway, Telnyx SDK) and delivery ecosystems (GitHub Actions, Docker Hub, npm, PyPI, OpenVSX), resulting in over 1,000 affected SaaS environments, approximately 500,000 compromised credentials, and more than 300 GB of exfiltrated data; the group used a chained compromise model to cascade access and has ties to multiple ransomware operations including a partnership with Vect and its own CipherForce brand.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.