logo

Weaponizing the Protectors: TeamPCP’s Multi-Stage Supply Chain Attack on Security Infrastructure

ID: 3284f7d1-b718-563c-810a-dfacaa7d6839

STIX ID: report--3284f7d1-b718-563c-810a-dfacaa7d6839

Feed Name: Palo Alto Networks Unit 42

Threat Score
92/100

Date Published: 2026-03-31

Date Updated: 2026-04-28

Author: Unit 42

...
...

Between February and March 2026, threat actor TeamPCP executed a large-scale supply chain campaign that poisoned CI/CD and package repositories (GitHub Actions, npm, PyPI) for widely used tools — including Aqua Security Trivy, Checkmarx KICS, BerriAI LiteLLM, and the Telnyx Python SDK — to deploy an infostealer and a self-replicating CanisterWorm with wiper capabilities; the operation harvested cloud tokens, SSH keys, Kubernetes secrets, and reportedly exfiltrated hundreds of gigabytes and credentials from hundreds of thousands of machines, while the report provides IoCs, detection queries, and recommended CI/CD and cloud hardening steps.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.