HomeSecuritySupply Chain Attack: TeamPCP Targets Developer Tools

Supply Chain Attack: TeamPCP Targets Developer Tools

Software supply chain attacks are emerging as one of the biggest cybersecurity challenges, and a new campaign shows just how dangerous this tactic can become. According to a warning from the FBI, a cybercriminal group being monitored by the name of TeamPCP has launched coordinated attacks against popular software development and security, aiming to steal critical credentials and gain access to corporate cloud infrastructure.

TeamPCP

Unlike traditional cyberattacks that directly target an organization, TeamPCP chooses to attack the tools that thousands of developers. In this way, a single compromised update can simultaneously affect hundreds or even thousands of businesses, turning the attack into a large-scale problem.

Developer trust becomes the weak point

The success of this particular campaign is based on the trust that development teams show in well-known software tools and libraries.

See also: SharkLoader: New malware disguises itself as Cisco and Google updates

The attackers managed to insert malicious code into legitimate packages, which are distributed as regular updates. Thus, developers install the new versions without realizing that along with the improvements, malware is also installed.

According to the FBI , popular tools such as Trivy , KICS , LiteLLM , and the Telnyx Python SDK were targeted . This is software widely used in continuous integration and continuous development (CI/CD) environments, which multiplies the impact of a successful breach.

Credential theft and access to cloud infrastructure

Once the modified package is installed on a system, it silently begins collecting valuable information.

Attackers are looking for tokens, SSH keys, API keys, environment variables, and access credentials to Kubernetes services. They are also attempting to obtain credentials for major cloud platforms such as Amazon Web Services (AWS), Microsoft Azure, and Google Cloud.

The importance of this data is enormous. A single valid cloud token can provide access to databases, virtual servers, storage systems , and critical business applications, allowing attackers to move silently within an organization's network.

Supply Chain Attack: TeamPCP Targets Developer Tools

From cyber espionage to blackmail

TeamPCP's activity is not limited to information theft. The FBI notes that the group has also moved into the blackmail, posting victims' names on dedicated data leak websites and threatening to release the stolen information if its financial demands are not met.

See also: NetNut / Popa: Google disrupts residential proxy network

This tactic significantly increases the pressure on businesses, as even if they remove the malware, the stolen credentials may continue to circulate online or be sold to other criminal groups months later.

For this reason, experts emphasize that such a breach does not end with the restoration of systems, but requires continuous monitoring and renewal of all access credentials.

The tools behind the attack

TeamPCP uses a set of specialized malicious tools, each of which serves a different purpose.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

CanisterWorm , and other credentials related to cloud computing services.

At the same time, SANDCLOCK searches for AWS credentials, Kubernetes ServiceAccount tokens, environment variables, and even data from cryptocurrency wallets, significantly expanding the range of information that can be collected.

Of particular interest is Mini Shai-Hulud, a self-replicating worm that spreads in the npm and PyPI, creating new infection chains without human intervention.

Researchers have also identified a variant called Miasma, which follows a similar tactic, modifying configuration files and continuing to steal credentials as it spreads.

Supply Chain Attack: TeamPCP Targets Developer Tools

FBI recommendations to organizations and development teams

The federal agency is urging any organization that suspects a potential breach to immediately collect evidence, such as logs from CI/CD pipelines, network logs, information about affected packages, and any extortion messages, in order to facilitate the investigation of incidents.

See also: ToddyCat: New Umbrij malware targets corporate Gmail accounts

At the same time, it recommends using verified commit hashes in GitHub Actions workflows instead of mutable tags, as well as immediately refreshing all cloud credentials, SSH keys, and secrets that may have been exposed.

Administrators are also urged to check corporate GitHub accounts for repositories with names such as tpcp-docs or docs-tpcp​​, as these have been linked to the activity of this particular worm.

Additionally, it is recommended to implement the principle of least privilege on CI/CD service accounts, to require strong MFA for access to repositories, to delay the installation of new packages until they are considered trustworthy by the community, and to maintain offline and immutable backups. Experts point out that as long as organizations depend on open software ecosystems, supply chain security will be one of the most important factors in protecting against cyber threats in the coming years.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS