FILTERING BY: CLEAR FILTER

LiteLLM and PyTorch Lightning Supply Chain Attack

Threat actor TeamPCP executed a targeted supply chain attack by compromising PyPI maintainer credentials to inject malicious code into LiteLLM (v1.82.7, 1.82.8) and PyTorch Lightning (v2.6.2, 2.6.3). The attackers utilized .pth file manipulation to achieve silent code execution during Python interpreter initialization, bypassing traditional import-based detection. The campaign exfiltrated 153GB of data—including AWS, GCP, Azure tokens, SSH keys, and CI/CD secrets—from approximately 2,500 organizations. The attack window lasted three hours before PyPI quarantine, highlighting a systemic shift toward targeting AI infrastructure and leveraging "slopsquatting" to exploit LLM-generated package hallucinations.

Multi-Vector Supply Chain Campaign: Mastra AI, GitHub Actions, and Arch Linux AUR Compromise

A sophisticated supply chain campaign, attributed to the suspected threat actor TeamPCP, has simultaneously targeted the Mastra AI framework via npm, GitHub Actions CI/CD workflows, and the Arch Linux User Repository (AUR). The attack utilized dormant contributor account takeovers to poison the @mastra npm scope using the easy-day-js dependency and hijacked GitHub Action version tags to exfiltrate CI/CD credentials. Additionally, over 1,500 AUR packages were compromised with eBPF-based rootkit malware. This coordinated infrastructure, linked by the "Mini Shai-Hulud" worm, facilitates widespread code execution, credential theft, and persistent rootkit deployment across development, DevOps, and end-user Linux environments.

The Vect and TeamPCP Alliance: Industrialized Supply Chain and Cloud-Native Ransomware Orchestration

The convergence of the Vect Ransomware-as-a-Service (RaaS) operation and the TeamPCP threat actor marks a strategic shift toward a vertically integrated cybercrime model. Vect provides high-volume initial access and credential harvesting, while TeamPCP specializes in ransomware orchestration and the development of cloud-native worms. This alliance targets the software development lifecycle through industrialized supply chain compromises of CI/CD pipelines and developer tools. By leveraging stolen OAuth tokens and API keys, the actors facilitate lateral movement across AWS, Azure, and GCP environments. The campaign focuses on cloud-native extortion, utilizing exfiltration of S3 buckets and database snapshots to maximize leverage against enterprise targets.

Npm, Microsoft, and AI Coding Agents: Shai Hulud and Miasma Worm Supply Chain Campaigns

Between May and June 2026, threat actor TeamPCP executed a multi-stage supply chain attack transitioning from the Shai Hulud cluster to the Miasma Worm. Shai Hulud utilized dependency confusion and SLSA provenance spoofing to compromise CI/CD pipelines and exfiltrate AWS Redshift data. The subsequent Miasma Worm evolved into an "environment-triggered" threat, hijacking AI agent configuration files (e.g., .claude/settings.json, .cursor/rules/setup.mdc) to achieve zero-click execution upon workspace opening. This campaign compromised 176 npm packages and 37 PyPI wheels, culminating in a June 5 breach of Microsoft that disabled 73 GitHub repositories and disrupted Azure Functions deployment actions globally.


LINK COPIED TO CLIPBOARD