Related Threat Clusters
-
TeamPCP's CanisterWorm Targets Iranian Systems with Destructive Kubernetes Wiper
TeamPCP has launched a new cyber campaign deploying a destructive payload that targets Kubernetes clusters configured for Iran. This wiper malware, part of the ongoing CanisterWorm campaign, uses the same…
4 articles · Updated March 23, 2026 -
TeamPCP Compromises Microsoft DurableTask and GitHub Actions in Supply Chain Attack
The TeamPCP threat group has expanded its supply chain attack campaign, compromising the Microsoft DurableTask Python client with versions v1.4.1, v1.4.2, and v1.4.3 found to contain a credential-stealing worm. This…
11 articles · Updated May 20, 2026 -
LiteLLM Supply Chain Attack Exposes Critical Credentials
On March 24, 2026, two versions of the LiteLLM Python package (1.82.7 and 1.82.8) were compromised on PyPI, embedding credential-stealing payloads. The attack, linked to the TeamPCP threat actor, exploited a…
3 articles · Updated June 12, 2026 -
Bitwarden CLI Compromised in Supply Chain Attack via npm
A malicious version of the Bitwarden CLI password manager was distributed via npm, affecting version 2026.4.0 for a brief window on April 22, 2026. The attack exploited a compromised GitHub Action in Bitwarden's CI/CD…
18 articles · Updated April 24, 2026 -
Checkmarx Jenkins Plugin Compromised by TeamPCP Malware Attack
Checkmarx reported a malicious version of its Jenkins AST plugin was uploaded to the Jenkins Marketplace on May 9, 2026. This backdoored plugin, which affects security scans in Jenkins CI pipelines, poses a significant…
15 articles · Updated May 11, 2026 -
LiteLLM Python Package Compromised in Major Supply Chain Attack by TeamPCP
On March 24, 2026, two malicious versions of the LiteLLM Python package (1.82.7 and 1.82.8) were published on PyPI, containing credential-stealing malware. The attack, attributed to the TeamPCP threat group, exploited…
53 articles · Updated March 24, 2026 -
AI Supply Chain Attacks and Model Poisoning Threats
In July 2026, researchers demonstrated that open-weight AI models can be easily poisoned, allowing attackers to implant backdoors for under $100. Katie Paxton-Fear successfully manipulated a model to execute remote code…
8 articles · Updated July 17, 2026 -
Megalodon Campaign Infects Over 5,500 GitHub Repositories with Malware
On May 18, 2026, an automated cyber campaign named Megalodon pushed 5,718 malicious commits to 5,561 GitHub repositories within six hours. The attackers used forged identities and dummy accounts to inject malicious…
7 articles · Updated May 26, 2026 -
Mini Shai-Hulud Supply Chain Attack Targets SAP npm Packages
A new supply chain attack, dubbed 'Mini Shai-Hulud', has compromised multiple npm packages related to SAP's Cloud Application Programming Model (CAP). This attack involves injecting malicious preinstall scripts into…
751 articles · Updated April 29, 2026 -
TeamPCP Hackers Arrested for Major Supply Chain Attacks
On August 26, 2026, Australian Federal Police arrested two men, Ruben Thomson and Louis Gaebler, linked to the TeamPCP hacking group. This group is notorious for sophisticated supply chain attacks that compromised over…
25 articles · Updated August 27, 2026
Recent Intelligence Reports
- Two TeamPCP members arrested in Australia — News.Risky.Biz · August 28, 2026
- Australian cops cuff alleged TeamPCP masterminds — Theregister · August 28, 2026
- Tracker — www.globenewswire.com · August 27, 2026
- Two Australians Charged Over TeamPCP Supply-Chain Attacks That Hit 1,000+ Organizations — Cybersecuritynews · August 27, 2026
- Version Control DFIR: a Cheatsheet to GitHub, GitLab, Bitbucket, and Azure DevOps — Wiz · August 27, 2026
- LiteLLM Hack Exposes Secrets From 2,488 Companies Across 118,829 CI Runner Dumps — Gbhackers · August 13, 2026
- Open-source software’s archenemy TeamPCP goes back further than anyone thought — Cyberscoop · August 5, 2026
- AI supply chain attacks — hivesecurity.gitlab.io · July 17, 2026