supply-chain Shai-Hulud hackers: two men charged over TeamPCP’s global supply chain crime spree that hit OpenAI, and thousands more Two men from Western Australia have been charged in connection with TeamPCP, a cybercriminal group responsible for a global supply-chain hacking campaign that targeted over 1000 organizations, including OpenAI and the European Commission. The group used a self-propagating worm, Shai-Hulud, to steal data and credentials… Graham Cluley · 2d ago High AUsupply chainopen sourcemalware
threat-intel TeamPCP : deux suspects arrêtés en Australie TeamPCP, a sophisticated cybercrime group, emerged in late 2025 and escalated to supply chain attacks in early 2026. Two suspects were arrested in Australia in August 2026, linked to a global operation involving data th… ZATAZ · 3d ago High AUsupply chainransomwarevulnerability
threat-intel Australia charges two men for TeamPCP supply-chain hacking spree Two men in Perth, Australia, have been charged in connection with their alleged involvement in the TeamPCP cybercrime syndicate, which has been linked to a massive supply-chain hacking campaign targeting over 1,000 organ… The Record · 3d ago High AUsupply-chaincybercrimehacking
threat-intel Australia Arrests 2 Alleged TeamPCP Hackers Australian authorities have arrested two men linked to the TeamPCP cybercrime group, a notorious organization responsible for stealing over 500,000 corporate credentials and causing significant financial damage. The grou… SecurityWeek · 3d ago High AUsupply-chaincredential-theftcybercrime
threat-intel Alleged TeamPCP Hackers Charged in Australia Over Major Supply Chain Attacks Australian authorities have charged two men linked to the cybercrime group TeamPCP, allegedly responsible for a widespread supply chain attack targeting over 1,000 organizations globally. The group exploited compromised… The Hacker News · 3d ago High AUsupply chaincredential theftopen source
threat-intel Two Alleged ‘TeamPCP’ Hackers Arrested in Australia Two men, believed to be members of the Australian cybercrime group TeamPCP, have been arrested in Western Australia. TeamPCP is a prolific group responsible for a long-running series of software supply chain attacks, emb… Krebs on Security · 3d ago High AUSOsupply-chaincybercrimeopen-source
threat-intel In Other News: Zombie Card Attack, T-Mobile Cut Cable to Stop Hackers, GitHub Denies AI Caused Bug This week’s cybersecurity news highlights a range of active threats and vulnerabilities. A severe code injection flaw in Ray-Project Ray is being actively exploited by a Mirai-based botnet, while T-Mobile took drastic ac… SecurityWeek · Aug 21, 2026 High CVE-2025-62593JACAvulnerabilityddosransomware
supply-chain Trivy, Not LiteLLM Behind the 2,500 Org Compromise A sophisticated supply chain attack, initially linked to the LiteLLM malware, has impacted over 2,500 organizations, primarily through a compromise of the Trivy scanner. The attack, orchestrated by TeamPCP, exploited vul… SecurityWeek · Aug 14, 2026 High GEBRFRsupply-chainvulnerabilitycredential-theft
supply-chain Over 2,500 Organizations Impacted by LiteLLM Supply Chain Attack Over 2,500 organizations and 434,000 CI/CD pipelines were impacted by a supply chain attack involving the LiteLLM AI library. The attack stemmed from a compromised version of Aqua Security’s Trivy vulnerability scanner,… SecurityWeek · Aug 12, 2026 High supply chainaicredentials
supply-chain Malicious LiteLLM Releases Tied to Trivy Hack May Have Exposed 2,100+ Organizations A supply-chain attack linked to Aqua Security's Trivy scanner has resulted in the release of two malicious LiteLLM packages containing credential-stealing code. CloudSEK identified over 2,500 organizations potentially ex… The Hacker News · Aug 12, 2026 High CVE-2026-33634USEUsupply chaincredential theftpypi
threat-intel TeamPCP Linked To Redis Attacks Dating Back To 2020 And Later Supply Chain Campaign The threat actor known as TeamPCP has been active since 2020, engaging in a series of campaigns targeting internet-facing infrastructure and expanding into sophisticated supply chain attacks. Their tactics have evolved s… The Hacker News · Aug 7, 2026 High IRsupply-chainkubernetesreact
threat-intel When AppSec Scanners Become a Supply Chain Attack Vector Security scanners used in the software supply chain can be exploited to introduce vulnerabilities and compromise downstream systems. Researchers at ZeroPath discovered that attackers can craft malicious code repositories… Dark Reading · Jul 29, 2026 High supply-chainvulnerabilitysecurity
supply-chain The npm Threat Landscape: Attack Surface and Mitigations (Updated July 15) The npm ecosystem experienced a critical inflection point in September 2025 with the emergence of the Shai-Hulud worm, marking a shift from nuisance attacks to a high-consequence threat landscape. Since then, Unit 42 has… Palo Alto Unit 42 · Jul 15, 2026 High NLsupply chainnpmgithub
threat-intel The serpent’s tongue: Luring the Python out of its den This report from Cisco Talos details a growing threat landscape surrounding Python packages, focusing on supply chain attacks leveraging malicious packages installed through package managers like PyPI. The report highlig… Cisco Talos · Jul 14, 2026 High supply chainpythonmalware
threat-intel In Other News: DHS Database Hacked, Adobe Boosts Patch Cadence, Canada Disrupts Ransomware Ops Multiple cybersecurity incidents and threats are unfolding, including a ransomware affiliate pleading guilty in the US, a subscription-based remote access trojan (QuimaRAT) being actively sold on the dark web, and a Cana… SecurityWeek · Jul 10, 2026 High ARCAUSransomwaredata breachremote access trojan
supply-chain GitHub dismissed security reports on flaws now exploited by supply-chain worm, researchers say A supply-chain worm, dubbed Shai-Hulud, is exploiting design flaws in GitHub to infect hundreds of software packages and developer accounts worldwide. The vulnerabilities, initially flagged by Deep Specter Research, were… The Record · Jun 16, 2026 High GBFRsupply chainvulnerabilitygithub
supply-chain Early Warning Signs of Supply-Chain Attacks Live in the Dark Web This BleepingComputer article highlights the increasing threat of supply-chain attacks, which target the tools and vendors organizations rely on. The article details how early warning signs of these attacks often appear… BleepingComputer · Jun 12, 2026 High GEsupply chaingithubcredentials
supply-chain Miasma Supply Chain Worm Burrows Into 73 Microsoft Repositories A sophisticated supply chain attack, orchestrated by the Miasma worm (a variant of Shai-Hulud), targeted 73 Microsoft GitHub repositories, primarily within the Azure organization. The attack, initially discovered through… Dark Reading · Jun 9, 2026 High supply chaingithubazure
supply-chain Over 100 NPM, PyPI Packages Hit in New Shai-Hulud Supply Chain Attacks A new wave of Shai-Hulud supply chain attacks has impacted over 471 NPM and PyPI packages, utilizing variants named Miasma and Hades. The attacks, originating from TeamPCP, involve credential harvesting and self-replicat… SecurityWeek · Jun 9, 2026 High supply chainnpmpypi
supply-chain TeamPCP Supply Chain Campaign: Activity Through 2026-06-07, (Mon, Jun 8th) This report details the ongoing TeamPCP supply chain campaign, which has recently seen increased activity and expanded impact. CISA has formally acknowledged and addressed the campaign, adding vulnerabilities to its Know… SANS Internet Storm Center · Jun 8, 2026 High CVE-2026-45321CVE-2026-48027CVE-2026-8398USsupply chainnpmgithub