supply-chain
TeamPCP Supply Chain Campaign: Activity Through 2026-05-24, (Mon, May 25th)
High
Summary
TeamPCP, a threat actor, launched a sophisticated supply chain campaign involving the malicious publication of compromised code extensions and SDKs across multiple platforms, including GitHub, npm, and PyPI. This campaign targeted organizations like GitHub, OpenAI, Microsoft, and Grafana Labs, leveraging trojanized extensions and SDKs to steal credentials and exfiltrate data. The incident highlights the risks associated with relying solely on publisher verification badges and underscores the need for robust security practices within CI/CD pipelines.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data