AUTO-UPDATED

FBI: TeamPCP Compromised Dev Tools to Steal Cloud Credentials

The FBI issued a FLASH alert on July 2, 2026, warning that the criminal group TeamPCP is compromising developer tools to execute large-scale software supply chain attacks.

Key Points

  • TeamPCP injected malicious code into widely used tools including Trivy, KICS, LiteLLM, and the Telnyx Python SDK.
  • The group deployed four malware families—CanisterWorm, SANDCLOCK, Mini Shai-Hulud, and Miasma—to harvest cloud tokens, SSH keys, and Kubernetes secrets.
  • Attackers gained control of npm accounts by registering expired recovery email domains linked to package maintainers.
  • The campaign is associated with four specific CVEs: CVE-2026-33634, CVE-2026-48027, CVE-2026-45321, and CVE-2025-55182.
  • Recommended mitigations include pinning GitHub Actions to commit SHAs, enforcing phishing-resistant MFA, and rotating all CI/CD secrets.

Why it Matters

This campaign demonstrates how attackers can bypass traditional security by poisoning the trusted tools and pipelines that organizations rely on for software development. Because the stolen credentials may be shared with other criminal groups, impacted organizations must treat all exposed data as a persistent, long-term security risk.
Securityaffairs.com Published by Pierluigi Paganini
Read original