logo

TeamPCP Supply Chain Campaign: Update 005 - First Confirmed Victim Disclosure, Post-Compromise Cloud Enumeration Documented, and Axios Attribution Narrows, (Wed, Apr 1st)

ID: 49455d28-c383-5efc-8734-7c69f4e5a95d

STIX ID: report--49455d28-c383-5efc-8734-7c69f4e5a95d

Feed Name: SANS ISC Diary

Threat Score
90/100

Date Published: 2026-04-01

Date Updated: 2026-04-19

...
...

This update consolidates developments in the TeamPCP supply-chain campaign: Mercor AI publicly confirmed a LiteLLM-driven breach with significant data exfiltration, Wiz published detailed post-compromise AWS/Azure enumeration behaviors, the axios npm incident was attributed to DPRK-linked UNC1069 (while the token provenance remains unclear), LiteLLM releases resumed after a Mandiant forensic audit, ownCloud disclosed build-infrastructure impact, and the overall supply-chain pause and remediation deadlines are tracked.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.