logo

Alleged TeamPCP Hackers Charged in Australia Over Major Supply Chain Attacks

ID: de6c44ea-cf61-52b4-87c9-f68b2807096b

STIX ID: report--de6c44ea-cf61-52b4-87c9-f68b2807096b

Feed Name: The Hacker News

Threat Score
85/100

Date Published: 2026-08-27

Date Updated: 2026-08-27

Author: [email protected] (The Hacker News)

...
...

The report describes TeamPCP's March 2026 supply-chain compromise that poisoned open-source tools (Trivy, Checkmarx KICS, LiteLLM and others) across GitHub Actions, Docker Hub, npm, PyPI and OpenVSX to steal publishing tokens, CI/CD credentials and exfiltrate data; authorities charged two Australian men in August 2026. Security firms and the FBI estimate widespread exposure (AFP: potentially >1,000 organizations, ~500,000 credentials stolen, ~300 GB exfiltrated; other vendors report even larger reconstructed exposures), trace the group's infrastructure back to earlier activity, and recommend rotating credentials, pinning workflow SHAs, and searching for repo artifacts created by the worm.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.