Skip to content
Threat Digest
Explainers Data Breaches Vulnerabilities & CVEs Ransomware & Malware
Nation-State Threats Security Tools Compliance & Policy Cloud Security Threat Intelligence

#teampcp

Illustration of a stylized worm or sandworm tunneling through code packages.
Vulnerabilities & CVEs

170+ Packages Wormed: TeamPCP's Mini Shai-Hulud Campaign Explained

A sophisticated, self-propagating worm has silently infected over 170 open-source packages, marking a disturbing new escalation in supply chain attacks. This isn't just a breach; it's a breach of trust, and the implications are staggering.

6 min read 1 day, 21 hours ago
Illustration of a digital lock being broken with code flowing out.
Data Breaches

GitHub Breach: TeamPCP Lists 4,000 Repositories For Sale

GitHub's internal source code is reportedly up for grabs on the dark web, and the company's scrambling to figure out what happened. This latest incident highlights the ever-present danger lurking in the supply chain.

6 min read 3 days, 7 hours ago
Abstract representation of code flowing through a compromised network, with a padlock symbol indicating a security breach.
Vulnerabilities & CVEs

TeamPCP Hits Checkmarx Again: The Supply Chain Trust Game

Just weeks after a supply chain attack that snaked through Bitwarden, TeamPCP is back, this time hijacking Checkmarx's own Jenkins plugin. It’s deja vu, and not the fun kind.

5 min read 1 week, 4 days ago
🎯
Threat Intelligence

Malware Hijacks: Cleaners Become Criminals

It’s an ironic twist: a new malware campaign is actively removing signs of rival hackers, only to replace them with its own malware and pilfer sensitive credentials from cloud environments.

6 min read 1 week, 6 days ago
Malicious Bitwarden CLI npm package code stealing developer credentials in supply chain attack
Data Breaches

[2026] Bitwarden CLI npm Compromised in Supply Chain Attack

Two hours. That's all it took for attackers to slip malicious code into Bitwarden's CLI npm package, turning a trusted password tool against developers. Credentials flew out—npm tokens, SSH keys, cloud secrets—and self-propagated to other projects.

5 min read 4 weeks, 1 day ago
Cisco logo cracked open with code spilling out amid supply chain attack icons
Threat Intelligence

Cisco's Source Code Raided: TeamPCP's Trivy Breach Exposes 300+ Repos and Gov Clients

Hackers turned Trivy into a key for Cisco's dev kingdom, swiping source code from banks, governments, and AI projects. As deadlines pass without dumps, is the TeamPCP campaign cracking?

4 min read 1 month, 1 week ago
Illustration of hackers breaching European Commission AWS cloud with stolen API key
Cloud Security

EU Cloud Hack: Stolen AWS Key Exposes 30 Entities' Secrets

Hackers waltzed into the European Commission's AWS cloud with a pilfered API key, swiping data from 30 EU outfits. CERT-EU calls it TeamPCP's work—supply-chain slop at its finest.

5 min read 1 month, 2 weeks ago
TeamPCP supply chain campaign timeline with Databricks, ransomware tracks, and AstraZeneca icons
Cloud Security

TeamPCP's Supply Chain Onslaught Hits Databricks, Splits Ransomware Into Two Deadly Tracks

Databricks is scrambling to verify a potential TeamPCP breach, while the group unleashes dual ransomware tracks and dumps AstraZeneca data for free. This isn't just another hack—it's a monetization masterclass.

5 min read 1 month, 2 weeks ago
🦠
Ransomware & Malware

CanisterWorm: Cybercrooks Hijack Iran Tensions for Cloud Data Heists

A worm called CanisterWorm just lit up Iranian cloud setups, wiping data based on time zones and language. Behind it? TeamPCP, who own 97% of their hits on Azure and AWS misconfigs.

4 min read 1 month, 2 weeks ago
Digital illustration of locked cloud icons cracking open with flying credential keys
Data Breaches

TeamPCP's Credential Blitz: AWS and Azure Fall in Hours, Not Days

Your cloud bill explodes overnight — crypto rigs humming on your dime. That's TeamPCP breaches in action, turning pilfered credentials into instant chaos for businesses everywhere.

5 min read 1 month, 2 weeks ago
Diagram of TeamPCP supply chain attack infiltrating CI/CD pipelines via PyPI and GitHub
Nation-State Threats

TeamPCP's Ruthless Hijack of Security Scanners: 500K Machines, 300GB Stolen

Attackers slipped infostealers into GitHub Actions and PyPI, turning vulnerability scanners against their users. Over 500,000 machines lost cloud tokens, SSH keys, and Kubernetes secrets in this escalating nightmare.

5 min read 1 month, 2 weeks ago
TeamPCP hackers exploiting PyPI packages for ransomware with Lapsus$ and Vect logos
Vulnerabilities & CVEs

TeamPCP's Stolen Secrets Pipeline: Fueling Ransomware Rampage

Your next PyPI download could hand hackers your cloud keys. TeamPCP's blending supply chain hacks with extortion gangs, turning dev tools into ransomware launchpads.

5 min read 1 month, 2 weeks ago

Categories

Explainers Data Breaches Vulnerabilities & CVEs Ransomware & Malware Nation-State Threats Security Tools Compliance & Policy Cloud Security
Threat Digest

Threat intelligence. Zero noise.

More

  • RSS Feed
  • Sitemap
  • About
  • Editorial Process
  • Advertise

Legal

  • Privacy
  • Terms
  • Work With Us

Our Network

The AI Catchup AI & Machine Learning Threat Digest Cybersecurity Legal AI Beat Legal Tech Fintech Rundown Finance & Banking DevTools Feed Developer Tools Open Source Beat Open Source Fintech Dose Crypto & DeFi Chip Beat Semiconductors AdTech Beat Ad Technology Supply Chain Beat Logistics

© 2026 Threat Digest. All rights reserved.

🏠Home 🔍Search 🔖Saved 📂Categories
Privacy & cookies

We use a privacy-respecting analytics tool to count page views — no personal profiles, no ad tracking, no third-party cookies. Accept to help us understand which stories matter to readers.

Details