Skip to main content
← All Articles

Tag

#TeamPCP

42 articles

Advertisement

MEDIUM
Supply Chain

TeamPCP Hackers Arrested in Australia Over Supply Chain Attacks

Australian Federal Police arrest two men linked to TeamPCP, a cybercrime syndicate behind major software supply chain attacks and data extortion.

Runtime Rebel Intel
3 min read · Sep 1, 2026
CRITICAL
Supply Chain

TeamPCP Supply Chain Attack: Trivy Compromise Impacts 2,500 Orgs

A supply chain attack attributed to TeamPCP compromised over 2,500 organizations, primarily through Aqua Security's Trivy scanner, not LiteLLM.

Runtime Rebel Intel
5 min read · Aug 15, 2026
Malicious LiteLLM PyPI Releases Steal Cloud Credentials via TeamPCP
CRITICAL
Supply Chain

Malicious LiteLLM PyPI Releases Steal Cloud Credentials via TeamPCP

Malicious LiteLLM PyPI releases 1.82.7 and 1.82.8 exfiltrated cloud keys, SSH keys, and tokens from 2,100+ organizations in the TeamPCP supply chain campaign.

Runtime Rebel Intel
4 min read · Aug 12, 2026
npm Supply Chain Attacks: Shai-Hulud, Miasma, and CI/CD Compromises
HIGH
Supply Chain

npm Supply Chain Attacks: Shai-Hulud, Miasma, and CI/CD Compromises

The npm ecosystem faces escalating supply chain attacks like Shai-Hulud and Miasma RAT, leading to credential theft and widespread package compromise.

Runtime Rebel Intel
5 min read · Aug 8, 2026
TeamPCP's Evolving Threat: Redis, Cloud Native & Supply Chain Attacks
HIGH
Threat Intel

TeamPCP's Evolving Threat: Redis, Cloud Native & Supply Chain Attacks

TeamPCP, active since 2020, now targets Redis, Docker, Kubernetes, and supply chains, deploying wipers and backdoors.

Runtime Rebel Intel
4 min read · Aug 7, 2026
HIGH
Threat Intel

TeamPCP Campaign Update: Mini Shai-Hulud Framework Gains Adoption

Analysis of the TeamPCP supply chain campaign, the open-sourcing of the Mini Shai-Hulud framework, and its adoption by diverse threat actor groups in 2026.

Runtime Rebel Intel
4 min read · Jun 8, 2026

Advertisement

Shai-Hulud Campaign: TeamPCP Targets Open-Source Supply Chain
HIGH
Supply Chain

Shai-Hulud Campaign: TeamPCP Targets Open-Source Supply Chain

Analysis of the Shai-Hulud campaign by TeamPCP, detailing their open-source supply chain attacks, TTPs, and critical mitigation strategies.

Runtime Rebel Intel
5 min read · May 26, 2026
HIGH
Supply Chain

TeamPCP Supply Chain Attack Targets Microsoft SDKs and GitHub

TeamPCP expands its supply chain campaign to trojanize official Microsoft Python SDKs and infiltrate GitHub, requiring immediate dependency audits.

Runtime Rebel Intel
3 min read · May 25, 2026
GitHub Data Breach: Analysis of TeamPCP Internal Repository Theft
HIGH
Data Breach

GitHub Data Breach: Analysis of TeamPCP Internal Repository Theft

GitHub confirms the theft of 4,000 internal repositories by threat actor TeamPCP. Learn the technical implications and defense strategies for security teams.

Runtime Rebel Intel
3 min read · May 21, 2026
HIGH
Data Breach

GitHub Internal Repo Breach Claimed by TeamPCP – Code at Risk

GitHub investigates TeamPCP's claim of breaching internal repositories, potentially exposing 4,000 private codebases. Defenders must secure supply chains.

Runtime Rebel Intel
5 min read · May 20, 2026
GitHub Investigates Claimed TeamPCP Breach of 4,000 Internal Repos
HIGH
Data Breach

GitHub Investigates Claimed TeamPCP Breach of 4,000 Internal Repos

GitHub is investigating a potential breach of 4,000 internal repositories claimed by TeamPCP, highlighting the risk of source code leaks for enterprises.

Runtime Rebel Intel
4 min read · May 20, 2026
HIGH
Supply Chain

TeamPCP Jenkins Plugin Compromise and Mini Shai-Hulud Worm Analysis

TeamPCP escalates its supply chain campaign with a confirmed Jenkins plugin compromise and a self-spreading worm targeting the npm and PyPI ecosystems.

Runtime Rebel Intel
3 min read · May 18, 2026
HIGH
Data Breach

TeamPCP Threatens Sale of Mistral AI Source Code Repositories

TeamPCP hackers claim to have exfiltrated 22GB of source code from Mistral AI. This report analyzes the breach impact and API key security risks.

Runtime Rebel Intel
4 min read · May 15, 2026
Mini Shai-Hulud Worm Compromises TanStack and Mistral AI Packages
HIGH
Supply Chain

Mini Shai-Hulud Worm Compromises TanStack and Mistral AI Packages

TeamPCP actor compromises major npm and PyPI packages including TanStack and Mistral AI via the Mini Shai-Hulud worm, deploying profiling malware.

Runtime Rebel Intel
4 min read · May 12, 2026
Checkmarx Jenkins AST Plugin Compromised in TeamPCP Attack
HIGH
Supply Chain

Checkmarx Jenkins AST Plugin Compromised in TeamPCP Attack

TeamPCP compromised the Checkmarx Jenkins AST plugin on the Jenkins Marketplace. Defenders must revert to version 2.0.13 to secure CI/CD pipelines.

Runtime Rebel Intel
3 min read · May 11, 2026
HIGH
Threat Intel

AI-Augmented Zero-Day Exploitation and Autonomous Malware Orchestration

GTIG report reveals how threat actors leverage generative AI for zero-day discovery, autonomous Android malware orchestration, and AI supply chain attacks.

Runtime Rebel Intel
4 min read · May 11, 2026
PCPJack Malware: Stealing Cloud Secrets via Parquet File Discovery
HIGH
Cloud Security

PCPJack Malware: Stealing Cloud Secrets via Parquet File Discovery

PCPJack malware replaces TeamPCP, utilizing Apache Parquet files for stealthy cloud secret theft across multiple service providers and environments.

Runtime Rebel Intel
3 min read · May 8, 2026
HIGH
Malware

PCPJack Worm: Analyzing the Malware Displacement in Cloud Environments

PCPJack is a new Golang-based worm targeting AWS, Docker, and Kubernetes. Learn how it removes TeamPCP and steals credentials to compromise cloud infrastructure.

Runtime Rebel Intel
4 min read · May 8, 2026
HIGH
Malware

PCPJack Worm Steals Cloud Credentials, Cleans TeamPCP Access

New PCPJack worm actively targets exposed cloud infrastructure, stealing credentials and removing existing TeamPCP infections. Understand its TTPs and mitigation.

Runtime Rebel Intel
4 min read · May 7, 2026
PCPJack Credential Stealer: Cloud System Exploitation & Spread
HIGH
Malware

PCPJack Credential Stealer: Cloud System Exploitation & Spread

PCPJack, a new credential stealer, leverages 5 unspecified CVEs to achieve worm-like spread across cloud, container, developer, and financial service environments…

Runtime Rebel Intel
5 min read · May 7, 2026
TeamPCP Targets SAP npm Packages: Mini Shai-Hulud Supply Chain Attack
HIGH
Supply Chain

TeamPCP Targets SAP npm Packages: Mini Shai-Hulud Supply Chain Attack

TeamPCP broadens supply chain attacks, compromising npm packages in SAP's cloud development ecosystem with the 'Mini Shai-Hulud' malicious code injection.

Runtime Rebel Intel
4 min read · May 1, 2026
HIGH
Supply Chain

Official SAP npm Packages Compromised in TeamPCP Supply Chain Attack

Attackers compromised official SAP npm packages to exfiltrate developer credentials and tokens. Learn how to detect and remediate this supply chain threat.

Runtime Rebel Intel
4 min read · Apr 30, 2026
HIGH
Supply Chain

TeamPCP Supply Chain: Checkmarx KICS, Bitwarden CLI, xinference PyPI Attacks

TeamPCP resumes supply chain attacks with new compromises targeting Checkmarx KICS, Bitwarden CLI, and xinference PyPI. UNC6780 credential theft campaign continues.

Runtime Rebel Intel
5 min read · Apr 27, 2026
HIGH
Supply Chain

Bitwarden NPM Supply Chain Attack: Analyzing the TeamPCP Campaign

A malicious npm package impersonating Bitwarden was discovered exfiltrating sensitive data via the Shai-Hulud worm in a recent supply chain attack.

Runtime Rebel Intel
4 min read · Apr 24, 2026