news.mlab.sh
Back to the feed
supply-chain

TeamPCP Supply Chain Campaign: Activity Through 2026-05-24, (Mon, May 25th)

High
Summary

TeamPCP, a threat actor, launched a sophisticated supply chain campaign involving the trojanization of multiple software packages, impacting GitHub, Microsoft, OpenAI, Grafana Labs, and Mistral AI. The campaign utilized stolen credentials and verified publisher badges to infiltrate systems and exfiltrate data. This represents a novel multi-stage operation and highlights the risks associated with relying solely on publisher verification at install time.

Read the full article at SANS Internet Storm Center

Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data

Report an error
Confirmed errors are fixed and listed on /corrections.