logo

Tracking TeamPCP: Investigating Post-Compromise Attacks Seen in the Wild

ID: 8883f761-466e-5422-b55c-f7f11a4b161f

STIX ID: report--8883f761-466e-5422-b55c-f7f11a4b161f

Feed Name: Wiz Blog

Threat Score
85/100

Date Published: 2026-03-30

Date Updated: 2026-05-01

...
...

Wiz CIRT and Research describe an active supply‑chain campaign by "TeamPCP" that deployed credential‑stealing malware in multiple open‑source projects (Trivy, KICS, LiteLLM, Telnyx), then rapidly validated stolen secrets and used them for AWS discovery, GitHub repository exfiltration, container execution, and bulk data theft; the report provides observed TTPs, IPs/user‑agents and detection/remediation guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.