Skip to content
Tracker

Tracker

www.globenewswire.com August 27, 2026

A post arrest full technical profile of the group that compromised Trivy, Checkmarx KICS, LiteLLM and the Telnyx SDK. Tradecraft, infrastructure, indicators and MITRE ATT&CK mapping.

Most supply chain attacks find a weak dependency. TeamPCP compromised the tools that check the dependencies, then used the credentials it stole from each victim to reach the . This profile documents how. It covers the group’s evolution from opportunistic cloud exploitation into industrialised supply chain compromise, the specific tradecraft behind each wave, the infrastructure it built to survive takedowns, and a full MITRE ATT&CK mapping.

Key Report Highlights: