IC Technology & Cyber — 2026-07-06

FBI Warns TeamPCP Compromised Developer Tools in Large-Scale Supply Chain Campaign Targeting Cloud Credentials

BLUFAdditional compromised packages will very likely surface within 60 days, as TeamPCP's self-replicating worms have seeded infections far beyond the four tools named in the FBI alert.

The FBI issued a FLASH alert on July 2 attributing a large-scale software supply chain campaign to a group it calls TeamPCP, which compromised widely used developer and security tools including Trivy, KICS, LiteLLM, and the Telnyx Python SDK to plant credential-stealing malware in CI/CD pipelines 1. The alert identifies four malware families: CanisterWorm and SANDCLOCK, which harvest AWS, GCP, and Azure credentials along with Kubernetes ServiceAccount tokens and SSH keys, and Mini Shai-Hulud and its Miasma variant, self-replicating worms that spread autonomously across npm and PyPI registries while poisoning configuration files 12. The FBI ties the campaign to exploitation of stale npm maintainer recovery-email domains and flags two GitHub repositories, tpcp-docs and docs-tpcp, created by the worm using stolen credentials 23. The indicator set, drawn from Palo Alto Unit 42 research, lists six IP addresses, 27 file hashes, and four CVEs, and the FBI states TeamPCP has published victim names on a leak site and threatened data disclosure as part of an extortion effort 13.

Analysis
Additional compromised packages or registries will very likely surface within the next 60 days as researchers continue mapping TeamPCP's footprint across npm and PyPI. Analytic confidence is high, resting on the worm's demonstrated self-replicating spread mechanism and the volume of indicators Unit 42 has already tied to the group's infrastructure. Organizations that treat this as a closed incident after patching the four named tools will miss downstream infections seeded through the same stale-recovery-email takeover technique. Stolen credentials remain exploitable indefinitely, so exposure will continue accumulating even after initial remediation.
4 sources
  1. FLASH-20260702-01: Indicators of Compromise Associated with TeamPCP - FBI/IC3
  2. FBI: TeamPCP Compromised Dev Tools to Steal Cloud Credentials - Security Affairs
  3. FBI Warns TeamPCP Hackers Compromise Developer Tools in Large-Scale Supply Chain Attacks - Cyber Security News
  4. FBI Says TeamPCP Uses Trojanized Updates to Steal Cloud Tokens, SSH Keys, and Kubernetes Secrets - GBHackers

View in full brief →

UNCLASSIFIED // OPEN SOURCE