logo

The TeamPCP supply chain attack evolves

ID: 0309fa44-bbee-59d4-8771-04f653a3f0db

STIX ID: report--0309fa44-bbee-59d4-8771-04f653a3f0db

Feed Name: ReversingLabs Blog

Threat Score
90/100

Date Published: 2026-03-27

Date Updated: 2026-04-30

Author: Paul Roberts

...
...

Executive summary: Researchers report an active TeamPCP supply-chain campaign that compromised developer tooling and PyPI packages (including LiteLLM and telnyx) by abusing GitHub Actions, stolen credentials, and compromised accounts; malicious payloads (infostealers and backdoors) were published to repositories and package registries to harvest cloud secrets, tokens, and wallet data, with observed C2 infrastructure (e.g., models.litellm.cloud, checkmarx.zone, and IP 83.142.209.203) and evidence of runner execution and persistence.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.