logo

TeamPCP Explores Ways to Exploit Stolen Supply Chain Secrets

ID: 321bc832-8fda-51b9-a64e-f38f2d8cb978

STIX ID: report--321bc832-8fda-51b9-a64e-f38f2d8cb978

Feed Name: Infosecurity Magazine (News)

Threat Score
85/100

Date Published: 2026-03-31

Date Updated: 2026-04-22

...
...

Researchers observed TeamPCP conducting supply-chain attacks by publishing typosquatted and backdoored PyPI packages and injecting credential-stealing malware into CI/CD pipelines and libraries (including Trivy, LiteLLM, Checkmarx KICS, and Telnyx). The group validated, encrypted, and exfiltrated cloud credentials, SSH keys, and other developer secrets to attacker-controlled domains and is reported to be collaborating with extortion and ransomware actors (Lapsus$, Vect), raising risk of large-scale follow-on ransomware campaigns.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.