The FBI issued a FLASH warning that TeamPCP is carrying out large-scale software supply chain compromises by trojanizing trusted developer and security tools, including Trivy, KICS, LiteLLM, and the Telnyx Python SDK. The campaign is designed to infiltrate CI/CD pipelines, cloud infrastructure, and security workflows, then steal high-value secrets such as cloud access tokens, API keys, SSH keys, and Kubernetes secrets. Reporting tied to the alert describes TeamPCP as a financially motivated group whose operations show persistence and scale more commonly associated with advanced threat actors.
Authorities and researchers said the activity is linked to malware families including CanisterWorm, SANDCLOCK, Mini Shai-Hulud, and Miasma, which were used to establish persistence, exfiltrate credentials, and spread access into downstream victim environments. The FBI said the group has also engaged in extortion, published victim names on a leak site, and collaborated with other threat actors, raising the risk that stolen credentials will be reused long after the initial compromise. Defenders were urged to rotate exposed secrets, pin GitHub Actions to verified commit SHAs, hunt for worm-created repositories, harden CI/CD environments, and review published indicators such as domains, IP addresses, hashes, and related CVEs.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
Sophos confirmed at least one VECT ransomware deployment that used credentials sourced from TeamPCP's software supply-chain compromises. The report tied TeamPCP's credential-theft activity to VECT's victim selection and ransomware operations.
VMRay researchers traced a phishing and business-email-compromise-style campaign targeting the maritime shipping sector back to April 2026. The activity used RedLine and Formbook-linked infrastructure, fraudulent lookalike domains, and fake supplier personas to target organizations including Kangrim Heavy Industries.
TeamPCP carried out a campaign that trojanized legitimate developer and security packages, including Trivy, KICS, LiteLLM, and the Telnyx Python SDK, to steal credentials and gain downstream access. The activity targeted CI/CD pipelines, cloud infrastructure, and security workflows, and was associated with malware families including CanisterWorm, SANDCLOCK, Mini Shai-Hulud, and Miasma.
On 2026-07-02, the FBI issued a FLASH advisory warning that TeamPCP was conducting large-scale software supply chain compromises. The notice described credential theft, persistence, extortion activity, leak-site publication of victim names, and provided indicators and mitigation guidance.
In the 48 hours after the Telnyx PyPI disclosure on 2026-03-27, no new package compromises were confirmed for the first time since operations began on March 19. The update assessed that TeamPCP was likely shifting from rapid supply-chain expansion to monetizing previously harvested credentials, while noting no additional named victims were disclosed.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
7 references tracked. Mallory keeps watching after this page renders.
blog.alphahunt.io
Open sourcecybersecuritynews.com
Open sourcecybersecuritynews.com
Open sourcecommunity.gurucul.com
Open sourcesecuritysenses.com
Open sourceisc.sans.edu
Open sourceic3.gov
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.