Related Threat Clusters
-
Massive Data Breach at US Social Security Administration and Cyberattacks on European Infrastructure
In 2026, significant cybersecurity incidents have emerged, including a data breach at the US Social Security Administration (SSA) linked to the Department of Government Efficiency (DOGE) led by Elon Musk. Reports…
2 articles · Updated July 7, 2026 -
TeamPCP Compromises Microsoft DurableTask and GitHub Actions in Supply Chain Attack
The TeamPCP threat group has expanded its supply chain attack campaign, compromising the Microsoft DurableTask Python client with versions v1.4.1, v1.4.2, and v1.4.3 found to contain a credential-stealing worm. This…
11 articles · Updated May 20, 2026 -
LiteLLM Python Package Compromised in Major Supply Chain Attack by TeamPCP
On March 24, 2026, two malicious versions of the LiteLLM Python package (1.82.7 and 1.82.8) were published on PyPI, containing credential-stealing malware. The attack, attributed to the TeamPCP threat group, exploited…
53 articles · Updated March 24, 2026 -
Checkmarx Data Leak Linked to Supply-Chain Attack by TeamPCP
Checkmarx, a software security firm, is investigating a significant data leak after its GitHub repository was compromised in a supply-chain attack on March 23, 2026. The attack, attributed to the TeamPCP cybercrime…
12 articles · Updated April 27, 2026 -
TeamPCP Hackers Arrested for Major Supply Chain Attacks
On August 26, 2026, Australian Federal Police arrested two men, Ruben Thomson and Louis Gaebler, linked to the TeamPCP hacking group. This group is notorious for sophisticated supply chain attacks that compromised over…
26 articles · Updated August 27, 2026 -
Vect 2.0 Ransomware Functions as Data Wiper, Not Encryptor
The Vect 2.0 ransomware, emerging from a partnership with the TeamPCP group, has been found to irreversibly destroy files larger than 128 KB instead of encrypting them for ransom. This critical flaw, identified by Check…
21 articles · Updated April 28, 2026 -
1K+ Cloud Environments Compromised in Trivy Supply Chain Attack
A supply chain attack targeting the Trivy open source scanner has infected over 1,000 cloud environments with secret-stealing malware. The attack, which occurred last week, has been attributed to a group called TeamPCP,…
3 articles · Updated March 24, 2026 -
Vect and TeamPCP Form Alliance for Ransomware Operations
In late March 2026, the Vect ransomware group partnered with TeamPCP, a credential theft specialist, to enhance their cybercriminal operations. This collaboration aims to leverage TeamPCP's extensive credential…
8 articles · Updated July 2, 2026 -
PCPJack Malware Targets TeamPCP Victims for Credential Theft
The newly discovered PCPJack malware framework is actively targeting cloud environments to steal credentials while removing remnants of the TeamPCP cybercrime group. This worm exploits exposed services such as Docker,…
11 articles · Updated May 7, 2026 -
LiteLLM Supply Chain Attack Triggers Surge in Demand for On-Premises AI Solutions
On March 24, 2026, the LiteLLM supply chain attack compromised 36% of cloud environments, affecting enterprises across financial services, healthcare, and defense sectors. The attack was executed by the threat actor…
2 articles · Updated April 3, 2026
Recent Intelligence Reports
- Two alleged TeamPCP members arrested and charged after months of software supply — Cyberscoop · August 27, 2026
- Cloud Security — securis360.com · August 26, 2026
- Hacked, leaked, and held for ransom: The worst breaches of 2026 so far — Techcrunch · July 7, 2026
- Warning Over “Industrialized” Cyber — Infosecurity-Magazine · July 3, 2026
- Vect and TeamPCP partner for ransomware campaigns — Sophos · July 2, 2026
- Vect and TeamPCP partner for ransomware campaigns — News.Sophos · July 2, 2026
- GitHub breached via poisoned VS Code extension, 3,800 repos stolen — Thenextweb · May 20, 2026
- GitHub confirms breach after hackers put stolen source code up for sale — Cybernews · May 20, 2026