The FBI issued a FLASH alert on July 2, 2026, warning that the criminal group TeamPCP is compromising developer tools to execute large-scale software supply chain attacks.
Key Points
- TeamPCP injected malicious code into widely used tools including Trivy, KICS, LiteLLM, and the Telnyx Python SDK.
- The group deployed four malware families—CanisterWorm, SANDCLOCK, Mini Shai-Hulud, and Miasma—to harvest cloud tokens, SSH keys, and Kubernetes secrets.
- Attackers gained control of npm accounts by registering expired recovery email domains linked to package maintainers.
- The campaign is associated with four specific CVEs: CVE-2026-33634, CVE-2026-48027, CVE-2026-45321, and CVE-2025-55182.
- Recommended mitigations include pinning GitHub Actions to commit SHAs, enforcing phishing-resistant MFA, and rotating all CI/CD secrets.