Skip to main content
← All Articles

Tag

#TeamPCP

42 articles

Advertisement

TeamPCP Supply Chain Attack: From Credential Theft to Payroll Fraud
HIGH
Supply Chain

TeamPCP Supply Chain Attack: From Credential Theft to Payroll Fraud

TeamPCP leverages supply chain attacks to compromise trusted software, facilitating large-scale credential harvesting, logistics theft, and payroll fraud.

Runtime Rebel Intel
4 min read · Apr 15, 2026
HIGH
Supply Chain

TeamPCP Supply Chain Campaign: Cisco Source Code Stolen, UNC6780 Activity

Analysis of the TeamPCP supply chain campaign, including the theft of Cisco source code and over 1,000 compromised SaaS environments tracked by Google GTIG as UNC6780.

Runtime Rebel Intel
4 min read · Apr 9, 2026
HIGH
Supply Chain

TeamPCP Supply Chain: CERT-EU Confirms Cloud Breach, 1000+ SaaS Environments Affected

CERT-EU confirms European Commission cloud breach via TeamPCP supply chain campaign. Mandiant identifies over 1,000 compromised SaaS environments.

Runtime Rebel Intel
5 min read · Apr 3, 2026
TeamPCP Supply Chain Attacks Escalate Amidst Hacker Infighting
HIGH
Threat Intel

TeamPCP Supply Chain Attacks Escalate Amidst Hacker Infighting

Runtime Rebel details how TeamPCP's supply chain attacks are leading to breaches, with ShinyHunters and Lapsus$ adding to the chaos.

Runtime Rebel Intel
4 min read · Apr 3, 2026
HIGH
Threat Intel

TeamPCP Breach of European Commission Affects 30 EU Entities

CERT-EU attributes a major cloud security breach at the European Commission to threat group TeamPCP, impacting data across 30 European Union organizations.

Runtime Rebel Intel
4 min read · Apr 3, 2026
HIGH
Supply Chain

TeamPCP Supply Chain Campaign: First Victim, Cloud Enumeration, Ransomware

Detailed analysis of TeamPCP supply chain campaign, covering the first confirmed victim, post-compromise cloud enumeration tactics, and dual ransomware operations.

Runtime Rebel Intel
4 min read · Apr 1, 2026

Advertisement

HIGH
Supply Chain

TeamPCP Supply Chain Campaign: Databricks and AstraZeneca Impact

TeamPCP's supply chain campaign weaponizes security scanners for dual ransomware operations, impacting Databricks and AstraZeneca in a major breach.

Runtime Rebel Intel
4 min read · Mar 30, 2026
HIGH
Supply Chain

TeamPCP Supply Chain Campaign: Weaponized Scanners and PyPI Compromise

Analysis of the TeamPCP campaign transition to monetization following the Telnyx PyPI compromise and Vect ransomware partnership affecting security tools.

Runtime Rebel Intel
4 min read · Mar 28, 2026
HIGH
Supply Chain

Backdoored Telnyx PyPI Package Uses Steganography to Deliver Malware

Security researchers discovered malicious versions of the Telnyx PyPI package delivering infostealers via steganography hidden in WAV audio files.

Runtime Rebel Intel
3 min read · Mar 28, 2026
Telnyx PyPI Package Compromised by TeamPCP via Steganography
HIGH
Supply Chain

Telnyx PyPI Package Compromised by TeamPCP via Steganography

TeamPCP threat actors distributed malicious Telnyx Python package versions 4.87.1 and 4.87.2 on PyPI to harvest credentials using hidden WAV files.

Runtime Rebel Intel
4 min read · Mar 27, 2026
HIGH
Supply Chain

TeamPCP Supply Chain Attack: Telnyx PyPI Compromise and Vect Ransomware

TeamPCP campaign escalates with Telnyx PyPI compromise and Vect Ransomware mass affiliate program. Critical update for software developers and SOC teams.

Runtime Rebel Intel
4 min read · Mar 27, 2026
HIGH
Supply Chain

TeamPCP Supply Chain: Checkmarx Wider Scope & LiteLLM PyPI Compromise

An update on the TeamPCP supply chain campaign details wider Checkmarx impact, LiteLLM PyPI compromise, and a CISA KEV entry.

Runtime Rebel Intel
5 min read · Mar 26, 2026
HIGH
Supply Chain

TeamPCP Supply Chain Attacks Target Docker Hub, PyPI, and VS Code

TeamPCP expands supply chain attack tactics from GitHub Actions to Docker Hub, PyPI, and VS Code extensions, collaborating with the Lapsus$ hacking group.

Runtime Rebel Intel
4 min read · Mar 25, 2026
Checkmarx KICS & VS Code Plugin Targeted in Supply Chain Attack
HIGH
Supply Chain

Checkmarx KICS & VS Code Plugin Targeted in Supply Chain Attack

TeamPCP exploited Checkmarx KICS, VS Code plugins, and LiteLLM in a supply chain attack targeting code scanners and AI libraries, indicating expanding threats.

Runtime Rebel Intel
5 min read · Mar 25, 2026
HIGH
Supply Chain

LiteLLM PyPI Supply Chain Attack: TeamPCP Steals Credentials

TeamPCP compromised the LiteLLM PyPI package, backdooring it to steal credentials and auth tokens from hundreds of thousands of devices.

Runtime Rebel Intel
5 min read · Mar 25, 2026
TeamPCP Backdoors LiteLLM 1.82.7–1.82.8 via CI/CD Compromise
HIGH
Supply Chain

TeamPCP Backdoors LiteLLM 1.82.7–1.82.8 via CI/CD Compromise

TeamPCP threat actors compromised LiteLLM versions 1.82.7 and 1.82.8, deploying credential harvesters and Kubernetes lateral movement tools via CI/CD.

Runtime Rebel Intel
3 min read · Mar 24, 2026
MEDIUM
Threat Intel

TeamPCP Targets Kubernetes Clusters with Iran-Specific Wiper Malware

TeamPCP is targeting misconfigured Kubernetes clusters to deploy a data-wiping script that specifically triggers on Iranian system configurations and locales.

Runtime Rebel Intel
3 min read · Mar 23, 2026
HIGH
Supply Chain

Trivy Supply Chain Attack: TeamPCP Pushes Infostealer via GitHub

Threat actor TeamPCP compromised the Trivy-action repository to distribute infostealer malware through GitHub Actions, targeting CI/CD pipelines and secrets.

Runtime Rebel Intel
3 min read · Mar 21, 2026