Close Menu
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice

Subscribe to Updates

Get the latest creative news from FooBar about art, design and business.

What's Hot

KDDI Breach Affects Six Japanese ISPs, Exposes 14.2 Email Credentials

June 25, 2026

The Top 10 Attack Surface Exposures in 2026

June 25, 2026

Operation Endgame Takes Down StealC and Amadey Infostealers

June 25, 2026
Facebook X (Twitter) Instagram
Thursday, June 25
Facebook X (Twitter) Instagram Pinterest Vimeo
Cyberwire Daily
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice
Cyberwire Daily
Home»News»TeamPCP Explores Ways to Exploit Stolen Supply Chain Secrets
News

TeamPCP Explores Ways to Exploit Stolen Supply Chain Secrets

Team-CWDBy Team-CWDMarch 31, 2026No Comments3 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
Share
Facebook Twitter LinkedIn Pinterest Email


Researchers have observed a “dangerous convergence” between supply chain attackers and extortion gangs like Lapsus$ as TeamPCP looks to exploit stolen credentials.

In a new report published on March 30, security researchers at Wiz, now part of Google Cloud, said they found evidence that TeamPCP was exploring ways to monetize the secrets harvested during these campaigns, such as cloud credentials, SSH keys, Kubernetes configuration files and other coding process secrets.

The threat group had been observed validating, encrypting and exfiltrating theses secrets to attacker-controlled domains.

“While the speed at which they were used suggests that it was the work of the same threat actors responsible for the supply chain operations, we are not able to rule out the secrets being shared with other groups and used by them,” the Wiz researchers wrote.

TeamPCP: Alleged Ties to Ransomware Groups

In a message shared with Infosecurity, Wiz confirmed that TeamPCP was “explicitly collaborating with the notorious extortion group Lapsus$ to perpetuate the chaos.”

Lapsus$ is an extortion-focused hacking group known for high-profile breaches via social engineering and credential theft, with suspected tactical overlaps – but no confirmed organizational ties – to Scattered Spider and ShinyHunters.

Ben Read, a lead researcher at Wiz, told Infosecurity: “We are seeing a dangerous convergence between supply chain attackers and high-profile extortion groups like Lapsus$. By moving horizontally across the ecosystem – hitting tools like liteLLM that are present in over a third of cloud environments – they are creating a ‘snowball effect.’ This isn’t an isolated incident; it’s a systemic campaign that requires security teams to take action and will likely continue to expand.”

Meanwhile, Socket, one of the earliest firms to report the TeamPCP software supply chain attacks, shared posts attributed to the Vect ransomware group on BreachForums announcing a partnership with TeamPCP as part of its research into the group.

“Vect Ransomware Group is now partnering with TeamPCP, the operators behind the latest Trivy / LiteLLM supply chain compromises. Together, we are ready to deploy ransomware across all affected companies that got hit by these attacks, and we won’t stop there. We will pull off even bigger supply chain operations. We will chain these compromises into devastating follow-on ransomware campaigns,” the message read.

Vect is an emerging Russian-speaking ransomware-as-a-service (RaaS) group, operating as a structured affiliate model where core developers build the ransomware and affiliates carry out attacks, earning up to 80–88% of the profits.

TeamPCP Behind Wave of Malicious PyPI Packages

The cyber threat group known as TeamPCP recently rose to notoriety by uploading malicious packages to Python Package Index (PyPI), the official online repository where developers share and download Python software packages. The group typically uses typosquatting to trick developers into downloading them.

In one campaign, the group targeted Trivy, a widely used open-source vulnerability scanner owned by Aqua Security, by injecting credential-stealing malware into official releases and GitHub Actions.

TeamPCP subsequently injected the same malware into Checkmarx’s KICS scanner through GitHub Actions and OpenVSX extensions.

Later, researchers discovered TeamPCP targeted LiteLLM AI Gateway, a popular Python library for AI model integration.

A fourth TeamPCP campaign affected the Telnyx Python package on PyPI and led, once again, to the delivery of credential-stealing malware.



Source

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous Article⚡ Weekly Recap: CI/CD Backdoor, FBI Buys Location Data, WhatsApp Ditches Numbers & More
Next Article Why Modern Security Demands a New Data Strategy
Team-CWD
  • Website

Related Posts

News

KDDI Breach Affects Six Japanese ISPs, Exposes 14.2 Email Credentials

June 25, 2026
News

The Top 10 Attack Surface Exposures in 2026

June 25, 2026
News

Operation Endgame Takes Down StealC and Amadey Infostealers

June 25, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest News

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202522 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views

Why SOC Burnout Can Be Avoided: Practical Steps

November 14, 20259 Views

Cyber M&A Roundup: Cyber Giants Strengthen AI Security Offerings

December 1, 20258 Views
Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Most Popular

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202522 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views
Our Picks

The WhatsApp screen-sharing scam you didn’t see coming

November 6, 2025

‘What happens online stays online’ and other cyberbullying myths, debunked

September 11, 2025

Is it time for internet services to adopt identity verification?

January 14, 2026

Subscribe to Updates

Get the latest news from cyberwiredaily.com

Facebook X (Twitter) Instagram Pinterest
  • Home
  • Contact
  • Privacy Policy
  • Terms of Use
  • California Consumer Privacy Act (CCPA)
© 2026 All rights reserved.

Type above and press Enter to search. Press Esc to cancel.