<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>RuntimeRebel — #TeamPCP</title><description>Cybersecurity articles tagged #TeamPCP on RuntimeRebel.</description><link>https://runtimerebel.com</link><item><title>TeamPCP Hackers Arrested in Australia Over Supply Chain Attacks</title><link>https://runtimerebel.com/blog/teampcp-hackers-arrested-in-australia-over-supply-chain-attacks</link><guid isPermaLink="true">https://runtimerebel.com/blog/teampcp-hackers-arrested-in-australia-over-supply-chain-attacks</guid><description>Australian Federal Police arrest two men linked to TeamPCP, a cybercrime syndicate behind major software supply chain attacks and data extortion.</description><pubDate>Tue, 01 Sep 2026 02:41:36 GMT</pubDate><category>TeamPCP</category><category>Supply Chain Attack</category><category>Shai Hulud</category><category>GitHub</category><category>LiteLLM</category></item><item><title>TeamPCP Supply Chain Attack: Trivy Compromise Impacts 2,500 Orgs</title><link>https://runtimerebel.com/blog/teampcp-supply-chain-attack-trivy-compromise-impacts-2500-orgs</link><guid isPermaLink="true">https://runtimerebel.com/blog/teampcp-supply-chain-attack-trivy-compromise-impacts-2500-orgs</guid><description>A supply chain attack attributed to TeamPCP compromised over 2,500 organizations, primarily through Aqua Security&apos;s Trivy scanner, not LiteLLM.</description><pubDate>Sat, 15 Aug 2026 00:42:24 GMT</pubDate><category>TeamPCP</category><category>Trivy</category><category>LiteLLM</category><category>Supply Chain Attack</category><category>Shai Hulud</category></item><item><title>Malicious LiteLLM PyPI Releases Steal Cloud Credentials via TeamPCP</title><link>https://runtimerebel.com/blog/malicious-litellm-pypi-releases-steal-cloud-credentials-via-teampcp</link><guid isPermaLink="true">https://runtimerebel.com/blog/malicious-litellm-pypi-releases-steal-cloud-credentials-via-teampcp</guid><description>Malicious LiteLLM PyPI releases 1.82.7 and 1.82.8 exfiltrated cloud keys, SSH keys, and tokens from 2,100+ organizations in the TeamPCP supply chain campaign.</description><pubDate>Wed, 12 Aug 2026 09:02:31 GMT</pubDate><category>LiteLLM</category><category>PyPI</category><category>Supply Chain Attack</category><category>TeamPCP</category><category>Credential Theft</category></item><item><title>npm Supply Chain Attacks: Shai-Hulud, Miasma, and CI/CD Compromises</title><link>https://runtimerebel.com/blog/npm-supply-chain-attacks-shai-hulud-miasma-and-ci-cd-compromises</link><guid isPermaLink="true">https://runtimerebel.com/blog/npm-supply-chain-attacks-shai-hulud-miasma-and-ci-cd-compromises</guid><description>The npm ecosystem faces escalating supply chain attacks like Shai-Hulud and Miasma RAT, leading to credential theft and widespread package compromise.</description><pubDate>Sat, 08 Aug 2026 16:26:28 GMT</pubDate><category>NPM</category><category>Supply Chain Attack</category><category>Shai Hulud</category><category>TeamPCP</category><category>CI CD Security</category></item><item><title>TeamPCP&apos;s Evolving Threat: Redis, Cloud Native &amp; Supply Chain Attacks</title><link>https://runtimerebel.com/blog/teampcp-s-evolving-threat-redis-cloud-native-supply-chain-attacks</link><guid isPermaLink="true">https://runtimerebel.com/blog/teampcp-s-evolving-threat-redis-cloud-native-supply-chain-attacks</guid><description>TeamPCP, active since 2020, now targets Redis, Docker, Kubernetes, and supply chains, deploying wipers and backdoors.</description><pubDate>Fri, 07 Aug 2026 08:47:09 GMT</pubDate><category>TeamPCP</category><category>Cloud Native</category><category>Supply Chain Attack</category><category>Kubernetes</category><category>Wiper</category></item><item><title>TeamPCP Campaign Update: Mini Shai-Hulud Framework Gains Adoption</title><link>https://runtimerebel.com/blog/teampcp-campaign-update-mini-shai-hulud-framework-gains-adoption</link><guid isPermaLink="true">https://runtimerebel.com/blog/teampcp-campaign-update-mini-shai-hulud-framework-gains-adoption</guid><description>Analysis of the TeamPCP supply chain campaign, the open-sourcing of the Mini Shai-Hulud framework, and its adoption by diverse threat actor groups in 2026.</description><pubDate>Mon, 08 Jun 2026 17:14:51 GMT</pubDate><category>TeamPCP</category><category>Mini Shai Hulud</category><category>Supply Chain Attack</category><category>Vulnerability Scanner</category><category>Threat Intelligence</category></item><item><title>Shai-Hulud Campaign: TeamPCP Targets Open-Source Supply Chain</title><link>https://runtimerebel.com/blog/shai-hulud-campaign-teampcp-targets-open-source-supply-chain</link><guid isPermaLink="true">https://runtimerebel.com/blog/shai-hulud-campaign-teampcp-targets-open-source-supply-chain</guid><description>Analysis of the Shai-Hulud campaign by TeamPCP, detailing their open-source supply chain attacks, TTPs, and critical mitigation strategies.</description><pubDate>Tue, 26 May 2026 20:47:57 GMT</pubDate><category>TeamPCP</category><category>Shai Hulud</category><category>Supply Chain Attack</category><category>Open Source Security</category><category>NPM</category><category>PyPI</category><category>Malicious Packages</category></item><item><title>TeamPCP Supply Chain Attack Targets Microsoft SDKs and GitHub</title><link>https://runtimerebel.com/blog/teampcp-supply-chain-attack-targets-microsoft-sdks-and-github</link><guid isPermaLink="true">https://runtimerebel.com/blog/teampcp-supply-chain-attack-targets-microsoft-sdks-and-github</guid><description>TeamPCP expands its supply chain campaign to trojanize official Microsoft Python SDKs and infiltrate GitHub, requiring immediate dependency audits.</description><pubDate>Mon, 25 May 2026 16:52:00 GMT</pubDate><category>TeamPCP</category><category>Supply Chain Attack</category><category>Python SDK</category><category>GitHub</category><category>PyPI</category><category>NPM</category></item><item><title>GitHub Data Breach: Analysis of TeamPCP Internal Repository Theft</title><link>https://runtimerebel.com/blog/github-data-breach-analysis-of-teampcp-internal-repository-theft</link><guid isPermaLink="true">https://runtimerebel.com/blog/github-data-breach-analysis-of-teampcp-internal-repository-theft</guid><description>GitHub confirms the theft of 4,000 internal repositories by threat actor TeamPCP. Learn the technical implications and defense strategies for security teams.</description><pubDate>Thu, 21 May 2026 09:16:24 GMT</pubDate><category>GitHub</category><category>TeamPCP</category><category>Source Code Theft</category><category>Internal Repositories</category><category>Data Exfiltration</category></item><item><title>GitHub Internal Repo Breach Claimed by TeamPCP – Code at Risk</title><link>https://runtimerebel.com/blog/github-internal-repo-breach-claimed-by-teampcp-code-at-risk</link><guid isPermaLink="true">https://runtimerebel.com/blog/github-internal-repo-breach-claimed-by-teampcp-code-at-risk</guid><description>GitHub investigates TeamPCP&apos;s claim of breaching internal repositories, potentially exposing 4,000 private codebases. Defenders must secure supply chains.</description><pubDate>Wed, 20 May 2026 05:27:49 GMT</pubDate><category>GitHub</category><category>TeamPCP</category><category>Data Breach</category><category>Supply Chain</category><category>Source Code</category></item><item><title>GitHub Investigates Claimed TeamPCP Breach of 4,000 Internal Repos</title><link>https://runtimerebel.com/blog/github-investigates-claimed-teampcp-breach-of-4000-internal-repos</link><guid isPermaLink="true">https://runtimerebel.com/blog/github-investigates-claimed-teampcp-breach-of-4000-internal-repos</guid><description>GitHub is investigating a potential breach of 4,000 internal repositories claimed by TeamPCP, highlighting the risk of source code leaks for enterprises.</description><pubDate>Wed, 20 May 2026 05:27:11 GMT</pubDate><category>GitHub</category><category>TeamPCP</category><category>Source Code Leak</category><category>Data Breach</category><category>Cybercrime</category></item><item><title>TeamPCP Jenkins Plugin Compromise and Mini Shai-Hulud Worm Analysis</title><link>https://runtimerebel.com/blog/teampcp-jenkins-plugin-compromise-and-mini-shai-hulud-worm-analysis</link><guid isPermaLink="true">https://runtimerebel.com/blog/teampcp-jenkins-plugin-compromise-and-mini-shai-hulud-worm-analysis</guid><description>TeamPCP escalates its supply chain campaign with a confirmed Jenkins plugin compromise and a self-spreading worm targeting the npm and PyPI ecosystems.</description><pubDate>Mon, 18 May 2026 20:38:04 GMT</pubDate><category>TeamPCP</category><category>Jenkins</category><category>NPM</category><category>PyPI</category><category>Mini Shai Hulud</category><category>Supply Chain Attack</category></item><item><title>TeamPCP Threatens Sale of Mistral AI Source Code Repositories</title><link>https://runtimerebel.com/blog/teampcp-threatens-sale-of-mistral-ai-source-code-repositories</link><guid isPermaLink="true">https://runtimerebel.com/blog/teampcp-threatens-sale-of-mistral-ai-source-code-repositories</guid><description>TeamPCP hackers claim to have exfiltrated 22GB of source code from Mistral AI. This report analyzes the breach impact and API key security risks.</description><pubDate>Fri, 15 May 2026 00:52:30 GMT</pubDate><category>TeamPCP</category><category>Mistral AI</category><category>Data Breach</category><category>Source Code Theft</category><category>API Security</category></item><item><title>Mini Shai-Hulud Worm Compromises TanStack and Mistral AI Packages</title><link>https://runtimerebel.com/blog/mini-shai-hulud-worm-compromises-tanstack-and-mistral-ai-packages</link><guid isPermaLink="true">https://runtimerebel.com/blog/mini-shai-hulud-worm-compromises-tanstack-and-mistral-ai-packages</guid><description>TeamPCP actor compromises major npm and PyPI packages including TanStack and Mistral AI via the Mini Shai-Hulud worm, deploying profiling malware.</description><pubDate>Tue, 12 May 2026 09:04:37 GMT</pubDate><category>TeamPCP</category><category>Mini Shai Hulud</category><category>NPM</category><category>PyPI</category><category>Supply Chain Attack</category></item><item><title>Checkmarx Jenkins AST Plugin Compromised in TeamPCP Attack</title><link>https://runtimerebel.com/blog/checkmarx-jenkins-ast-plugin-compromised-in-teampcp-attack</link><guid isPermaLink="true">https://runtimerebel.com/blog/checkmarx-jenkins-ast-plugin-compromised-in-teampcp-attack</guid><description>TeamPCP compromised the Checkmarx Jenkins AST plugin on the Jenkins Marketplace. Defenders must revert to version 2.0.13 to secure CI/CD pipelines.</description><pubDate>Mon, 11 May 2026 20:39:30 GMT</pubDate><category>Checkmarx</category><category>Jenkins</category><category>TeamPCP</category><category>Supply Chain Attack</category><category>CI CD Security</category></item><item><title>AI-Augmented Zero-Day Exploitation and Autonomous Malware Orchestration</title><link>https://runtimerebel.com/blog/ai-augmented-zero-day-exploitation-and-autonomous-malware-orchestration</link><guid isPermaLink="true">https://runtimerebel.com/blog/ai-augmented-zero-day-exploitation-and-autonomous-malware-orchestration</guid><description>GTIG report reveals how threat actors leverage generative AI for zero-day discovery, autonomous Android malware orchestration, and AI supply chain attacks.</description><pubDate>Mon, 11 May 2026 13:13:41 GMT</pubDate><category>PROMPTSPY</category><category>AI Security</category><category>Zero-Day</category><category>TeamPCP</category><category>APT45</category></item><item><title>PCPJack Malware: Stealing Cloud Secrets via Parquet File Discovery</title><link>https://runtimerebel.com/blog/pcpjack-malware-stealing-cloud-secrets-via-parquet-file-discovery</link><guid isPermaLink="true">https://runtimerebel.com/blog/pcpjack-malware-stealing-cloud-secrets-via-parquet-file-discovery</guid><description>PCPJack malware replaces TeamPCP, utilizing Apache Parquet files for stealthy cloud secret theft across multiple service providers and environments.</description><pubDate>Fri, 08 May 2026 08:39:33 GMT</pubDate><category>PCPJack</category><category>TeamPCP</category><category>Cloud Security</category><category>Credential Theft</category><category>Apache Parquet</category></item><item><title>PCPJack Worm: Analyzing the Malware Displacement in Cloud Environments</title><link>https://runtimerebel.com/blog/pcpjack-worm-analyzing-the-malware-displacement-in-cloud-environments</link><guid isPermaLink="true">https://runtimerebel.com/blog/pcpjack-worm-analyzing-the-malware-displacement-in-cloud-environments</guid><description>PCPJack is a new Golang-based worm targeting AWS, Docker, and Kubernetes. Learn how it removes TeamPCP and steals credentials to compromise cloud infrastructure.</description><pubDate>Fri, 08 May 2026 08:38:51 GMT</pubDate><category>PCPJack</category><category>TeamPCP</category><category>Cloud Security</category><category>Docker</category><category>Kubernetes</category><category>Credential Theft</category></item><item><title>PCPJack Worm Steals Cloud Credentials, Cleans TeamPCP Access</title><link>https://runtimerebel.com/blog/pcpjack-worm-steals-cloud-credentials-cleans-teampcp-access</link><guid isPermaLink="true">https://runtimerebel.com/blog/pcpjack-worm-steals-cloud-credentials-cleans-teampcp-access</guid><description>New PCPJack worm actively targets exposed cloud infrastructure, stealing credentials and removing existing TeamPCP infections. Understand its TTPs and mitigation.</description><pubDate>Thu, 07 May 2026 20:32:45 GMT</pubDate><category>PCPJack</category><category>TeamPCP</category><category>Credential Theft</category><category>Cloud Security</category><category>Worm</category><category>Malware</category></item><item><title>PCPJack Credential Stealer: Cloud System Exploitation &amp; Spread</title><link>https://runtimerebel.com/blog/pcpjack-credential-stealer-cloud-system-exploitation-spread</link><guid isPermaLink="true">https://runtimerebel.com/blog/pcpjack-credential-stealer-cloud-system-exploitation-spread</guid><description>PCPJack, a new credential stealer, leverages 5 unspecified CVEs to achieve worm-like spread across cloud, container, developer, and financial service environments…</description><pubDate>Thu, 07 May 2026 20:32:23 GMT</pubDate><category>PCPJack</category><category>Credential Stealer</category><category>Cloud Security</category><category>Worm</category><category>TeamPCP</category></item><item><title>TeamPCP Targets SAP npm Packages: Mini Shai-Hulud Supply Chain Attack</title><link>https://runtimerebel.com/blog/teampcp-targets-sap-npm-packages-mini-shai-hulud-supply-chain-attack</link><guid isPermaLink="true">https://runtimerebel.com/blog/teampcp-targets-sap-npm-packages-mini-shai-hulud-supply-chain-attack</guid><description>TeamPCP broadens supply chain attacks, compromising npm packages in SAP&apos;s cloud development ecosystem with the &apos;Mini Shai-Hulud&apos; malicious code injection.</description><pubDate>Fri, 01 May 2026 00:54:59 GMT</pubDate><category>TeamPCP</category><category>SAP</category><category>NPM</category><category>Supply Chain Attack</category><category>Mini Shai Hulud</category><category>Cloud Security</category></item><item><title>Official SAP npm Packages Compromised in TeamPCP Supply Chain Attack</title><link>https://runtimerebel.com/blog/official-sap-npm-packages-compromised-in-teampcp-supply-chain-attack</link><guid isPermaLink="true">https://runtimerebel.com/blog/official-sap-npm-packages-compromised-in-teampcp-supply-chain-attack</guid><description>Attackers compromised official SAP npm packages to exfiltrate developer credentials and tokens. Learn how to detect and remediate this supply chain threat.</description><pubDate>Thu, 30 Apr 2026 00:50:55 GMT</pubDate><category>SAP</category><category>NPM</category><category>TeamPCP</category><category>Credential Theft</category><category>Malicious Packages</category></item><item><title>TeamPCP Supply Chain: Checkmarx KICS, Bitwarden CLI, xinference PyPI Attacks</title><link>https://runtimerebel.com/blog/teampcp-supply-chain-checkmarx-kics-bitwarden-cli-xinference-pypi-attacks</link><guid isPermaLink="true">https://runtimerebel.com/blog/teampcp-supply-chain-checkmarx-kics-bitwarden-cli-xinference-pypi-attacks</guid><description>TeamPCP resumes supply chain attacks with new compromises targeting Checkmarx KICS, Bitwarden CLI, and xinference PyPI. UNC6780 credential theft campaign continues.</description><pubDate>Mon, 27 Apr 2026 16:42:13 GMT</pubDate><category>TeamPCP</category><category>UNC6780</category><category>SANDCLOCK</category><category>Supply Chain Attack</category><category>Checkmarx KICS</category><category>Bitwarden CLI</category><category>Xinference PyPI</category><category>NPM</category><category>PyPI</category><category>Credential Theft</category><category>CVE-2026-33634</category></item><item><title>Bitwarden NPM Supply Chain Attack: Analyzing the TeamPCP Campaign</title><link>https://runtimerebel.com/blog/bitwarden-npm-supply-chain-attack-analyzing-the-teampcp-campaign</link><guid isPermaLink="true">https://runtimerebel.com/blog/bitwarden-npm-supply-chain-attack-analyzing-the-teampcp-campaign</guid><description>A malicious npm package impersonating Bitwarden was discovered exfiltrating sensitive data via the Shai-Hulud worm in a recent supply chain attack.</description><pubDate>Fri, 24 Apr 2026 08:49:11 GMT</pubDate><category>NPM</category><category>Bitwarden</category><category>TeamPCP</category><category>Shai Hulud</category><category>Supply Chain Security</category></item><item><title>TeamPCP Supply Chain Attack: From Credential Theft to Payroll Fraud</title><link>https://runtimerebel.com/blog/teampcp-supply-chain-attack-from-credential-theft-to-payroll-fraud</link><guid isPermaLink="true">https://runtimerebel.com/blog/teampcp-supply-chain-attack-from-credential-theft-to-payroll-fraud</guid><description>TeamPCP leverages supply chain attacks to compromise trusted software, facilitating large-scale credential harvesting, logistics theft, and payroll fraud.</description><pubDate>Wed, 15 Apr 2026 16:30:57 GMT</pubDate><category>TeamPCP</category><category>Supply Chain Attack</category><category>Credential Harvesting</category><category>Payroll Fraud</category><category>Financial Crime</category></item><item><title>TeamPCP Supply Chain Campaign: Cisco Source Code Stolen, UNC6780 Activity</title><link>https://runtimerebel.com/blog/teampcp-supply-chain-campaign-cisco-source-code-stolen-unc6780-activity</link><guid isPermaLink="true">https://runtimerebel.com/blog/teampcp-supply-chain-campaign-cisco-source-code-stolen-unc6780-activity</guid><description>Analysis of the TeamPCP supply chain campaign, including the theft of Cisco source code and over 1,000 compromised SaaS environments tracked by Google GTIG as UNC6780.</description><pubDate>Thu, 09 Apr 2026 00:37:07 GMT</pubDate><category>TeamPCP</category><category>UNC6780</category><category>Supply Chain Attack</category><category>Cisco</category><category>Source Code Theft</category><category>Trivy</category><category>ShinyHunters</category><category>SaaS Compromise</category></item><item><title>TeamPCP Supply Chain: CERT-EU Confirms Cloud Breach, 1000+ SaaS Environments Affected</title><link>https://runtimerebel.com/blog/teampcp-supply-chain-cert-eu-confirms-cloud-breach-1000-saas-environments-affected</link><guid isPermaLink="true">https://runtimerebel.com/blog/teampcp-supply-chain-cert-eu-confirms-cloud-breach-1000-saas-environments-affected</guid><description>CERT-EU confirms European Commission cloud breach via TeamPCP supply chain campaign. Mandiant identifies over 1,000 compromised SaaS environments.</description><pubDate>Fri, 03 Apr 2026 16:19:26 GMT</pubDate><category>TeamPCP</category><category>Supply Chain Attack</category><category>Cloud Security</category><category>SaaS</category><category>European Commission</category><category>DPRK</category></item><item><title>TeamPCP Supply Chain Attacks Escalate Amidst Hacker Infighting</title><link>https://runtimerebel.com/blog/teampcp-supply-chain-attacks-escalate-amidst-hacker-infighting</link><guid isPermaLink="true">https://runtimerebel.com/blog/teampcp-supply-chain-attacks-escalate-amidst-hacker-infighting</guid><description>Runtime Rebel details how TeamPCP&apos;s supply chain attacks are leading to breaches, with ShinyHunters and Lapsus$ adding to the chaos.</description><pubDate>Fri, 03 Apr 2026 16:18:40 GMT</pubDate><category>TeamPCP</category><category>ShinyHunters</category><category>Lapsus</category><category>Supply Chain Attack</category><category>Breach</category><category>Threat Actor</category></item><item><title>TeamPCP Breach of European Commission Affects 30 EU Entities</title><link>https://runtimerebel.com/blog/teampcp-breach-of-european-commission-affects-30-eu-entities</link><guid isPermaLink="true">https://runtimerebel.com/blog/teampcp-breach-of-european-commission-affects-30-eu-entities</guid><description>CERT-EU attributes a major cloud security breach at the European Commission to threat group TeamPCP, impacting data across 30 European Union organizations.</description><pubDate>Fri, 03 Apr 2026 08:25:00 GMT</pubDate><category>TeamPCP</category><category>European Commission</category><category>CERT EU</category><category>Cloud Security</category><category>Data Breach</category></item><item><title>TeamPCP Supply Chain Campaign: First Victim, Cloud Enumeration, Ransomware</title><link>https://runtimerebel.com/blog/teampcp-supply-chain-campaign-first-victim-cloud-enumeration-ransomware</link><guid isPermaLink="true">https://runtimerebel.com/blog/teampcp-supply-chain-campaign-first-victim-cloud-enumeration-ransomware</guid><description>Detailed analysis of TeamPCP supply chain campaign, covering the first confirmed victim, post-compromise cloud enumeration tactics, and dual ransomware operations.</description><pubDate>Wed, 01 Apr 2026 16:28:28 GMT</pubDate><category>TeamPCP</category><category>Supply Chain Attack</category><category>Cloud Security</category><category>Ransomware</category><category>AstraZeneca</category><category>Databricks</category><category>Data Breach</category></item><item><title>TeamPCP Supply Chain Campaign: Databricks and AstraZeneca Impact</title><link>https://runtimerebel.com/blog/teampcp-supply-chain-campaign-databricks-and-astrazeneca-impact</link><guid isPermaLink="true">https://runtimerebel.com/blog/teampcp-supply-chain-campaign-databricks-and-astrazeneca-impact</guid><description>TeamPCP&apos;s supply chain campaign weaponizes security scanners for dual ransomware operations, impacting Databricks and AstraZeneca in a major breach.</description><pubDate>Mon, 30 Mar 2026 16:29:39 GMT</pubDate><category>TeamPCP</category><category>Databricks</category><category>AstraZeneca</category><category>Supply Chain Attack</category><category>Dual Ransomware</category></item><item><title>TeamPCP Supply Chain Campaign: Weaponized Scanners and PyPI Compromise</title><link>https://runtimerebel.com/blog/teampcp-supply-chain-campaign-weaponized-scanners-and-pypi-compromise</link><guid isPermaLink="true">https://runtimerebel.com/blog/teampcp-supply-chain-campaign-weaponized-scanners-and-pypi-compromise</guid><description>Analysis of the TeamPCP campaign transition to monetization following the Telnyx PyPI compromise and Vect ransomware partnership affecting security tools.</description><pubDate>Sat, 28 Mar 2026 16:14:20 GMT</pubDate><category>TeamPCP</category><category>PyPI</category><category>Vect Ransomware</category><category>Telnyx</category><category>Supply Chain Attack</category></item><item><title>Backdoored Telnyx PyPI Package Uses Steganography to Deliver Malware</title><link>https://runtimerebel.com/blog/backdoored-telnyx-pypi-package-uses-steganography-to-deliver-malware</link><guid isPermaLink="true">https://runtimerebel.com/blog/backdoored-telnyx-pypi-package-uses-steganography-to-deliver-malware</guid><description>Security researchers discovered malicious versions of the Telnyx PyPI package delivering infostealers via steganography hidden in WAV audio files.</description><pubDate>Sat, 28 Mar 2026 00:36:31 GMT</pubDate><category>PyPI</category><category>Telnyx</category><category>Steganography</category><category>Infostealer</category><category>TeamPCP</category><category>Python Security</category></item><item><title>Telnyx PyPI Package Compromised by TeamPCP via Steganography</title><link>https://runtimerebel.com/blog/telnyx-pypi-package-compromised-by-teampcp-via-steganography</link><guid isPermaLink="true">https://runtimerebel.com/blog/telnyx-pypi-package-compromised-by-teampcp-via-steganography</guid><description>TeamPCP threat actors distributed malicious Telnyx Python package versions 4.87.1 and 4.87.2 on PyPI to harvest credentials using hidden WAV files.</description><pubDate>Fri, 27 Mar 2026 20:15:00 GMT</pubDate><category>Telnyx</category><category>PyPI</category><category>TeamPCP</category><category>Python</category><category>Steganography</category><category>Credential Theft</category></item><item><title>TeamPCP Supply Chain Attack: Telnyx PyPI Compromise and Vect Ransomware</title><link>https://runtimerebel.com/blog/teampcp-supply-chain-attack-telnyx-pypi-compromise-and-vect-ransomware</link><guid isPermaLink="true">https://runtimerebel.com/blog/teampcp-supply-chain-attack-telnyx-pypi-compromise-and-vect-ransomware</guid><description>TeamPCP campaign escalates with Telnyx PyPI compromise and Vect Ransomware mass affiliate program. Critical update for software developers and SOC teams.</description><pubDate>Fri, 27 Mar 2026 16:27:06 GMT</pubDate><category>TeamPCP</category><category>Telnyx</category><category>PyPI</category><category>Vect Ransomware</category><category>Supply Chain Security</category></item><item><title>TeamPCP Supply Chain: Checkmarx Wider Scope &amp; LiteLLM PyPI Compromise</title><link>https://runtimerebel.com/blog/teampcp-supply-chain-checkmarx-wider-scope-litellm-pypi-compromise</link><guid isPermaLink="true">https://runtimerebel.com/blog/teampcp-supply-chain-checkmarx-wider-scope-litellm-pypi-compromise</guid><description>An update on the TeamPCP supply chain campaign details wider Checkmarx impact, LiteLLM PyPI compromise, and a CISA KEV entry.</description><pubDate>Thu, 26 Mar 2026 20:16:14 GMT</pubDate><category>TeamPCP</category><category>Supply Chain Attack</category><category>Checkmarx</category><category>LiteLLM</category><category>PyPI</category><category>CISA KEV</category></item><item><title>TeamPCP Supply Chain Attacks Target Docker Hub, PyPI, and VS Code</title><link>https://runtimerebel.com/blog/teampcp-supply-chain-attacks-target-docker-hub-pypi-and-vs-code</link><guid isPermaLink="true">https://runtimerebel.com/blog/teampcp-supply-chain-attacks-target-docker-hub-pypi-and-vs-code</guid><description>TeamPCP expands supply chain attack tactics from GitHub Actions to Docker Hub, PyPI, and VS Code extensions, collaborating with the Lapsus$ hacking group.</description><pubDate>Wed, 25 Mar 2026 12:24:38 GMT</pubDate><category>TeamPCP</category><category>Lapsus</category><category>Supply Chain Attack</category><category>Docker Hub</category><category>GitHub Actions</category><category>VS Code</category></item><item><title>Checkmarx KICS &amp; VS Code Plugin Targeted in Supply Chain Attack</title><link>https://runtimerebel.com/blog/checkmarx-kics-vs-code-plugin-targeted-in-supply-chain-attack</link><guid isPermaLink="true">https://runtimerebel.com/blog/checkmarx-kics-vs-code-plugin-targeted-in-supply-chain-attack</guid><description>TeamPCP exploited Checkmarx KICS, VS Code plugins, and LiteLLM in a supply chain attack targeting code scanners and AI libraries, indicating expanding threats.</description><pubDate>Wed, 25 Mar 2026 00:37:08 GMT</pubDate><category>TeamPCP</category><category>Checkmarx KICS</category><category>VS Code</category><category>LiteLLM</category><category>Supply Chain Attack</category></item><item><title>LiteLLM PyPI Supply Chain Attack: TeamPCP Steals Credentials</title><link>https://runtimerebel.com/blog/litellm-pypi-supply-chain-attack-teampcp-steals-credentials</link><guid isPermaLink="true">https://runtimerebel.com/blog/litellm-pypi-supply-chain-attack-teampcp-steals-credentials</guid><description>TeamPCP compromised the LiteLLM PyPI package, backdooring it to steal credentials and auth tokens from hundreds of thousands of devices.</description><pubDate>Wed, 25 Mar 2026 00:36:46 GMT</pubDate><category>LiteLLM</category><category>PyPI</category><category>TeamPCP</category><category>Supply Chain Attack</category><category>Credential Theft</category><category>Python Package</category></item><item><title>TeamPCP Backdoors LiteLLM 1.82.7–1.82.8 via CI/CD Compromise</title><link>https://runtimerebel.com/blog/teampcp-backdoors-litellm-1-82-7-1-82-8-via-ci-cd-compromise</link><guid isPermaLink="true">https://runtimerebel.com/blog/teampcp-backdoors-litellm-1-82-7-1-82-8-via-ci-cd-compromise</guid><description>TeamPCP threat actors compromised LiteLLM versions 1.82.7 and 1.82.8, deploying credential harvesters and Kubernetes lateral movement tools via CI/CD.</description><pubDate>Tue, 24 Mar 2026 20:18:30 GMT</pubDate><category>LiteLLM</category><category>TeamPCP</category><category>Supply Chain Attack</category><category>Python Security</category><category>Kubernetes</category></item><item><title>TeamPCP Targets Kubernetes Clusters with Iran-Specific Wiper Malware</title><link>https://runtimerebel.com/blog/teampcp-targets-kubernetes-clusters-with-iran-specific-wiper-malware</link><guid isPermaLink="true">https://runtimerebel.com/blog/teampcp-targets-kubernetes-clusters-with-iran-specific-wiper-malware</guid><description>TeamPCP is targeting misconfigured Kubernetes clusters to deploy a data-wiping script that specifically triggers on Iranian system configurations and locales.</description><pubDate>Mon, 23 Mar 2026 20:17:25 GMT</pubDate><category>TeamPCP</category><category>Kubernetes</category><category>Wiper Malware</category><category>Cloud Security</category><category>Iran</category></item><item><title>Trivy Supply Chain Attack: TeamPCP Pushes Infostealer via GitHub</title><link>https://runtimerebel.com/blog/trivy-supply-chain-attack-teampcp-pushes-infostealer-via-github</link><guid isPermaLink="true">https://runtimerebel.com/blog/trivy-supply-chain-attack-teampcp-pushes-infostealer-via-github</guid><description>Threat actor TeamPCP compromised the Trivy-action repository to distribute infostealer malware through GitHub Actions, targeting CI/CD pipelines and secrets.</description><pubDate>Sat, 21 Mar 2026 20:08:15 GMT</pubDate><category>Trivy Scanner</category><category>GitHub Actions</category><category>TeamPCP</category><category>Infostealer</category><category>CI CD Security</category></item></channel></rss>