Palo Alto Networks Unit 42 reported that TeamPCP has conducted a multi-stage supply chain campaign aimed at security infrastructure providers, describing a pattern in which the actor compromises organizations that sit inside customer build, deployment, and protection workflows. The activity highlights the risk of attacking trusted security tooling and cloud-connected platforms to gain access to downstream environments, internal architecture, and sensitive operational data.
A later dark web listing tied a campaign called CanisterWorm to the same actor set, with a seller using the name xpl0itrs claiming to offer data allegedly stolen from RapidFort, a container hardening and software supply chain security vendor, for $40,000. The unverified listing advertised 569GB of data across 140,061 files from 48 S3 buckets, including hardening pipelines, vulnerability database pipelines, scanner backends, DevOps infrastructure, billing exports, plaintext cloud credentials, Kubernetes kubeconfig files, and private keys; if authentic, the exposure could create follow-on intrusion opportunities because RapidFort reportedly operates within customer CI/CD environments and may hold cross-account access into customer cloud estates.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
6 events from the most recent confirmed update back to the earliest known activity.
A threat actor using the name xpl0itrs advertised the alleged sale of data purportedly stolen from RapidFort for $40,000. The listing claimed 569GB of data from 48 S3 buckets and associated the intrusion with the CanisterWorm campaign linked to TeamPCP.
The Cloud Security Alliance reference says credentials stolen during TeamPCP's March 2026 supply-chain activity were later used to breach Cisco's development environment. The intrusion allegedly led to the exfiltration of more than 300 internal repositories, including code for Cisco AI Assistant and Cisco AI Defense.
The CSIRT.SK reference links TeamPCP to a destructive campaign using CanisterWorm logic to wipe Iranian Kubernetes clusters. It describes this as part of the group's broader infrastructure attacks against exposed Docker API, Kubernetes, Redis, and Ray environments.
On 2026-04-22, attackers tampered with Checkmarx KICS Docker images and maliciously published @bitwarden/cli@2026.4.0 to npm. Both payloads reportedly exfiltrated harvested credentials to an attacker-controlled domain impersonating Checkmarx.
Unit 42 reported on a campaign by TeamPCP involving multi-stage supply chain attacks targeting security infrastructure. The reference describes the operation as weaponizing trusted security tooling and infrastructure providers.
Telnyx published a security notice stating that malicious versions of the Telnyx Python SDK were identified on PyPI in March 2026. This adds Telnyx as an affected package ecosystem victim in the broader supply-chain intrusion story.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
7 references tracked. Mallory keeps watching after this page renders.
darkwebinformer.com
Open sourcelabs.cloudsecurityalliance.org
Open sourcecsirt.sk
Open sourcesemgrep.dev
Open sourcepartner.gurucul.com
Open sourceunit42.paloaltonetworks.com
Open sourcetelnyx.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.