Related Threat Clusters
-
LiteLLM Python Package Compromised in Major Supply Chain Attack by TeamPCP
On March 24, 2026, two malicious versions of the LiteLLM Python package (1.82.7 and 1.82.8) were published on PyPI, containing credential-stealing malware. The attack, attributed to the TeamPCP threat group, exploited…
53 articles · Updated March 24, 2026 -
Mercor Cyberattack Linked to LiteLLM Supply Chain Compromise
AI recruiting startup Mercor confirmed it was impacted by a supply chain attack linked to the LiteLLM project, which has affected thousands of organizations. The breach was attributed to the hacking group TeamPCP, with…
30 articles · Updated April 1, 2026 -
TeamPCP Supply Chain Attack Compromises Databricks Platform
Databricks is investigating a potential security compromise linked to the TeamPCP supply chain attack. This incident follows a notification from International Cyber Digest, which indicated that Databricks was alerted…
4 articles · Updated March 30, 2026 -
Emerging Cyber Threats: CRPx0 Ransomware and TeamPCP Supply Chain Attacks
CRPx0 is a rapidly growing ransomware operation linked to the cybercriminal 'MrAnon00', active since July 2025, targeting small healthcare and dental organizations. The operation employs social engineering tactics to…
3 articles · Updated August 27, 2026 -
European Commission Cyberattack Compromises AWS Cloud Infrastructure
The European Commission confirmed a cyberattack on March 24, 2026, affecting its cloud infrastructure on the Europa.eu platform. Hackers claimed to have stolen over 350GB of data, including sensitive information related…
45 articles · Updated March 27, 2026 -
TeamPCP Supply Chain Attacks Pause as Ransomware Focus Intensifies
TeamPCP, a cybercriminal group, has halted its supply chain attacks for the first time since March 19, 2026. No new compromises have been reported in the last three days, following the malicious release of Telnyx's SDK…
2 articles · Updated March 30, 2026
Recent Intelligence Reports
- KELA research leads to alleged TeamPCP Members Arrested — Markets.Businessinsider · August 27, 2026
- TeamPCP Supply Chain Campaign: Update 006 - CERT-EU Confirms European Commission Cloud Breach, Sportradar Details Emerge, and Mandiant Quantifies Campaign at 1,000+ SaaS Environments, (Fri, Apr 3rd) — Isc.Sans.Edu · April 3, 2026
- TeamPCP Supply Chain Campaign: Update 005 - First Confirmed Victim Disclosure, Post-Compromise Cloud Enumeration Documented, and Axios Attribution Narrows, (Wed, Apr 1st) — Isc.Sans.Edu · April 1, 2026
- TeamPCP Supply Chain Campaign: Update 004 - Databricks Investigating Alleged Compromise, TeamPCP Runs Dual Ransomware Operations, and AstraZeneca Data Released, (Mon, Mar 30th) — Isc.Sans.Edu · March 30, 2026
- TeamPCP Supply Chain Campaign: Update 003 - Operational Tempo Shift as Campaign Enters Monetization Phase With No New Compromises in 48 Hours, (Sat, Mar 28th) — Isc.Sans.Edu · March 28, 2026
- TeamPCP Supply Chain Campaign: Update 002 - Telnyx PyPI Compromise, Vect Ransomware Mass Affiliate Program, and First Named Victim Claim, (Fri, Mar 27th) — Isc.Sans.Edu · March 27, 2026