Related Threat Clusters
-
Massive Data Breach at US Social Security Administration and Cyberattacks on European Infrastructure
In 2026, significant cybersecurity incidents have emerged, including a data breach at the US Social Security Administration (SSA) linked to the Department of Government Efficiency (DOGE) led by Elon Musk. Reports…
2 articles · Updated July 7, 2026 -
2026 Cyberattacks Target Critical Infrastructure and Data Breaches
In 2026, cyberattacks have escalated from data theft to targeting critical infrastructure, affecting government systems, educational platforms, and medical technology companies. The U.S. Department of Government…
2 articles · Updated June 7, 2026 -
TeamPCP Compromises Microsoft DurableTask and GitHub Actions in Supply Chain Attack
The TeamPCP threat group has expanded its supply chain attack campaign, compromising the Microsoft DurableTask Python client with versions v1.4.1, v1.4.2, and v1.4.3 found to contain a credential-stealing worm. This…
11 articles · Updated May 20, 2026 -
Supply Chain Attack Targets Checkmarx KICS Tool via Docker and VSCode Extensions
Hackers have compromised Docker images and VSCode extensions for the Checkmarx KICS analysis tool, which is used to identify security vulnerabilities in source code. The attack involved a trojanized KICS Docker image…
2 articles · Updated April 23, 2026 -
Bitwarden CLI Compromised in Supply Chain Attack via npm
A malicious version of the Bitwarden CLI password manager was distributed via npm, affecting version 2026.4.0 for a brief window on April 22, 2026. The attack exploited a compromised GitHub Action in Bitwarden's CI/CD…
18 articles · Updated April 24, 2026 -
Checkmarx Jenkins Plugin Compromised by TeamPCP Malware Attack
Checkmarx reported a malicious version of its Jenkins AST plugin was uploaded to the Jenkins Marketplace on May 9, 2026. This backdoored plugin, which affects security scans in Jenkins CI pipelines, poses a significant…
15 articles · Updated May 11, 2026 -
LiteLLM Python Package Compromised in Major Supply Chain Attack by TeamPCP
On March 24, 2026, two malicious versions of the LiteLLM Python package (1.82.7 and 1.82.8) were published on PyPI, containing credential-stealing malware. The attack, attributed to the TeamPCP threat group, exploited…
53 articles · Updated March 24, 2026 -
Checkmarx Data Leak Linked to Supply-Chain Attack by TeamPCP
Checkmarx, a software security firm, is investigating a significant data leak after its GitHub repository was compromised in a supply-chain attack on March 23, 2026. The attack, attributed to the TeamPCP cybercrime…
12 articles · Updated April 27, 2026 -
Vect 2.0 Ransomware Functions as Data Wiper, Not Encryptor
The Vect 2.0 ransomware, emerging from a partnership with the TeamPCP group, has been found to irreversibly destroy files larger than 128 KB instead of encrypting them for ransom. This critical flaw, identified by Check…
21 articles · Updated April 28, 2026 -
Vect and TeamPCP Form Alliance for Ransomware Operations
In late March 2026, the Vect ransomware group partnered with TeamPCP, a credential theft specialist, to enhance their cybercriminal operations. This collaboration aims to leverage TeamPCP's extensive credential…
8 articles · Updated July 2, 2026
Recent Intelligence Reports
- Link — edge.prnewswire.com · July 8, 2026
- Hacked, leaked, and held for ransom: The worst breaches of 2026 so far — Techcrunch · July 7, 2026
- Vect and TeamPCP partner for ransomware campaigns — Sophos · July 2, 2026
- Vect and TeamPCP partner for ransomware campaigns — News.Sophos · July 2, 2026
- How software development’s speed obsession enabled TeamPCP’s chaos crusade — Cyberscoop · June 18, 2026
- 2026 Cyberattacks Shift from Data Theft to Real-World Disruption — Kucoin · June 7, 2026
- The worst hacks and breaches of 2026 (so far) — Techcrunch · June 3, 2026
- GitHub breached via poisoned VS Code extension, 3,800 repos stolen — Thenextweb · May 20, 2026