supply-chain
TeamPCP Supply Chain Campaign: Activity Through 2026-05-24, (Mon, May 25th)
High
Summary
TeamPCP, a threat actor, launched a sophisticated supply chain campaign involving the trojanization of multiple software packages, impacting GitHub, Microsoft, OpenAI, Grafana Labs, and Mistral AI. The campaign utilized stolen credentials and verified publisher badges to infiltrate systems and exfiltrate data. This represents a novel multi-stage operation and highlights the risks associated with relying solely on publisher verification at install time.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data