logo

The Worm That Keeps on Digging: TeamPCP Hits @antv in Latest Wave

ID: 27c25b3e-554b-53d9-9a64-d50078a453e3

STIX ID: report--27c25b3e-554b-53d9-9a64-d50078a453e3

Feed Name: Wiz Blog

Threat Score
85/100

Date Published: 2026-05-19

Date Updated: 2026-05-19

Author: Rami McCarthy

...
...

Wiz Research details a coordinated software supply-chain campaign (attributed to "TeamPCP" with moderate confidence) that compromised numerous npm packages, GitHub Actions, and a VSCode extension to deploy credential-stealing malware, exfiltrate developer secrets via attacker-created GitHub repositories, and maintain persistence with a Python backdoor that polls GitHub for signed commands.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.