Related Threat Clusters
-
LiteLLM Supply Chain Attack Exposes Critical Credentials
On March 24, 2026, two versions of the LiteLLM Python package (1.82.7 and 1.82.8) were compromised on PyPI, embedding credential-stealing payloads. The attack, linked to the TeamPCP threat actor, exploited a…
3 articles · Updated June 12, 2026 -
Bitwarden CLI Compromised in Supply Chain Attack via npm
A malicious version of the Bitwarden CLI password manager was distributed via npm, affecting version 2026.4.0 for a brief window on April 22, 2026. The attack exploited a compromised GitHub Action in Bitwarden's CI/CD…
18 articles · Updated April 24, 2026 -
Checkmarx Jenkins Plugin Compromised by TeamPCP Malware Attack
Checkmarx reported a malicious version of its Jenkins AST plugin was uploaded to the Jenkins Marketplace on May 9, 2026. This backdoored plugin, which affects security scans in Jenkins CI pipelines, poses a significant…
15 articles · Updated May 11, 2026 -
Critical Vulnerability in Claude Code GitHub Actions Exposes Repositories to Attacks
A critical supply chain vulnerability in Claude Code’s GitHub Actions, identified by security researcher Ryota K from GMO Flat Security, allows attackers to compromise any repository using Anthropic’s CI/CD workflow.…
18 articles · Updated June 2, 2026 -
GlassWorm Malware Campaign Targets OpenVSX with 73 Malicious Extensions
A resurgence of the GlassWorm malware campaign has been identified, targeting the OpenVSX ecosystem with 73 'sleeper' extensions that become malicious after updates. Six of these extensions have already been activated…
8 articles · Updated April 27, 2026 -
LiteLLM Python Package Compromised in Major Supply Chain Attack by TeamPCP
On March 24, 2026, two malicious versions of the LiteLLM Python package (1.82.7 and 1.82.8) were published on PyPI, containing credential-stealing malware. The attack, attributed to the TeamPCP threat group, exploited…
53 articles · Updated March 24, 2026 -
Glassworm Botnet Targeting Developers Disrupted by CrowdStrike and Google
The Glassworm botnet, which has targeted software developers since early 2025, was taken down in a coordinated operation by CrowdStrike, Google, and the Shadowserver Foundation on May 26, 2026. This botnet utilized…
30 articles · Updated May 27, 2026 -
Mini Shai-Hulud Supply Chain Attack Targets SAP npm Packages
A new supply chain attack, dubbed 'Mini Shai-Hulud', has compromised multiple npm packages related to SAP's Cloud Application Programming Model (CAP). This attack involves injecting malicious preinstall scripts into…
753 articles · Updated April 29, 2026 -
1K+ Cloud Environments Compromised in Trivy Supply Chain Attack
A supply chain attack targeting the Trivy open source scanner has infected over 1,000 cloud environments with secret-stealing malware. The attack, which occurred last week, has been attributed to a group called TeamPCP,…
3 articles · Updated March 24, 2026 -
Vect and TeamPCP Form Alliance for Ransomware Operations
In late March 2026, the Vect ransomware group partnered with TeamPCP, a credential theft specialist, to enhance their cybercriminal operations. This collaboration aims to leverage TeamPCP's extensive credential…
8 articles · Updated July 2, 2026
Recent Intelligence Reports
- KELA research leads to alleged TeamPCP Members Arrested — Markets.Businessinsider · August 27, 2026
- Link — edge.prnewswire.com · July 8, 2026
- Snyk researcher Stephen Thoemmes — snyk.io · July 2, 2026
- Vect and TeamPCP partner for ransomware campaigns — Sophos · July 2, 2026
- Vect and TeamPCP partner for ransomware campaigns — News.Sophos · July 2, 2026
- AI Coding Agents Skip Package Verification, and Attackers Are Exploiting It — Techtimes · July 1, 2026
- LiteLLM supply-chain incident — www.trendmicro.com · June 12, 2026
- Glassworm First Self Propagating Worm Using Invisible Code Hits Openvsx Marketplace — www.koi.ai · May 27, 2026