The Worm That Keeps on Digging: TeamPCP Hits @antv in Latest Wave
ID: 27c25b3e-554b-53d9-9a64-d50078a453e3
STIX ID: report--27c25b3e-554b-53d9-9a64-d50078a453e3
Feed Name: Wiz Blog
Threat Score
Wiz Research details a coordinated software supply-chain campaign (attributed to "TeamPCP" with moderate confidence) that compromised numerous npm packages, GitHub Actions, and a VSCode extension to deploy credential-stealing malware, exfiltrate developer secrets via attacker-created GitHub repositories, and maintain persistence with a Python backdoor that polls GitHub for signed commands.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
