Related Threat Clusters
-
Bitwarden CLI Compromised in Supply Chain Attack via npm
A malicious version of the Bitwarden CLI password manager was distributed via npm, affecting version 2026.4.0 for a brief window on April 22, 2026. The attack exploited a compromised GitHub Action in Bitwarden's CI/CD…
18 articles · Updated April 24, 2026 -
Checkmarx Jenkins Plugin Compromised by TeamPCP Malware Attack
Checkmarx reported a malicious version of its Jenkins AST plugin was uploaded to the Jenkins Marketplace on May 9, 2026. This backdoored plugin, which affects security scans in Jenkins CI pipelines, poses a significant…
15 articles · Updated May 11, 2026 -
LiteLLM Python Package Compromised in Major Supply Chain Attack by TeamPCP
On March 24, 2026, two malicious versions of the LiteLLM Python package (1.82.7 and 1.82.8) were published on PyPI, containing credential-stealing malware. The attack, attributed to the TeamPCP threat group, exploited…
53 articles · Updated March 24, 2026 -
Mercor Cyberattack Linked to LiteLLM Supply Chain Compromise
AI recruiting startup Mercor confirmed it was impacted by a supply chain attack linked to the LiteLLM project, which has affected thousands of organizations. The breach was attributed to the hacking group TeamPCP, with…
30 articles · Updated April 1, 2026 -
Checkmarx Data Leak Linked to Supply-Chain Attack by TeamPCP
Checkmarx, a software security firm, is investigating a significant data leak after its GitHub repository was compromised in a supply-chain attack on March 23, 2026. The attack, attributed to the TeamPCP cybercrime…
12 articles · Updated April 27, 2026 -
Vect and TeamPCP Form Alliance for Ransomware Operations
In late March 2026, the Vect ransomware group partnered with TeamPCP, a credential theft specialist, to enhance their cybercriminal operations. This collaboration aims to leverage TeamPCP's extensive credential…
8 articles · Updated July 2, 2026 -
GitHub Breach: 3,800 Internal Repositories Compromised via Malicious VS Code Extension
On May 20, 2026, GitHub confirmed a significant security breach involving a poisoned Visual Studio Code (VS Code) extension that compromised an employee's device. The attack, attributed to the TeamPCP hacking group,…
149 articles · Updated May 20, 2026 -
38% of GitHub Actions Workflows Vulnerable to Script Injection
Analysis shows that 38% of organizations using GitHub Actions workflows are exposed to script injection and unsafe trigger configurations. This vulnerability poses a significant risk in software supply chains, as GitHub…
2 articles · Updated June 4, 2026
Recent Intelligence Reports
- Vect and TeamPCP partner for ransomware campaigns — Sophos · July 2, 2026
- Case For Github Actions Security — securitylabs.datadoghq.com · June 4, 2026
- GitHub Confirms Breach of Internal Repositories Via Malicious VS Code Extension — Infosecurity-Magazine · May 20, 2026
- TeamPCP Compromised Checkmarx Jenkins AST Plugin Following KICS Supply Chain Attack — Cybersecuritynews · May 12, 2026
- Checkmarx Jenkins AST Plugin Compromised in KICS Supply Chain Attack — Gbhackers · May 12, 2026
- Ongoing Security Updates — checkmarx.com · May 11, 2026
- TeamPCP Compromises Checkmarx Jenkins AST Plugin Weeks After KICS Supply Chain Attack — Thehackernews · May 11, 2026
- Checkmarx tackles another TeamPCP intrusion as Jenkins plugin sabotaged — Theregister · May 11, 2026