Topic: teampcp threat actor

  • Malware hidden in backdoored Telnyx PyPI package

    Malware hidden in backdoored Telnyx PyPI package

    A malicious version of the Telnyx SDK Python package was uploaded to PyPI on March 27, 2026, by the threat actor TeamPCP, who backdoored the legitimate code. The attack originated from stolen credentials obtained in a prior breach of the LiteLLM project, which were used to compromise the Telnyx P...

    Read More »
  • Red Hat npm packages hit by new Mini Shai-Hulud malware wave

    Red Hat npm packages hit by new Mini Shai-Hulud malware wave

    On June 1, 2026, over 30 npm packages tied to Red Hat Cloud Services were compromised in a supply chain attack after a Red Hat employee's GitHub account was breached, with attackers deploying malware that steals credentials from developers' build environments. The malware, a new variant of TeamPC...

    Read More »
  • Microsoft hit again by credential-stealing malware in software packages

    Microsoft hit again by credential-stealing malware in software packages

    Microsoft's compromised open source packages on GitHub contained credential-stealing malware that activated when opened in AI coding agents, with 73 malicious packages blocked by GitHub's automated systems. GitHub's response only stated the packages violated terms of service, while Microsoft did ...

    Read More »