TeamPCP — Breach Tracker
OSINT + Third-Party Intel Last updated: Apr 2026
Threat Actor Supply Chain Campaign
TeamPCP

A live tracker documenting the coordinated supply chain attack campaign attributed to TeamPCP — covering confirmed infection vectors, alleged victim organisations, and downstream credential exposure sourced from OSINT and third-party threat intelligence.

Alleged Victims
57
organisations named
Attack Vectors
4
independently confirmed
Countries Affected
19
across all victim claims
Campaign Start
Mar 2026
earliest confirmed incident
01

Campaign Background

Over the course of roughly two weeks, the threat group known as TeamPCP carried out a systematic series of supply chain intrusions against widely-adopted open source developer tooling. The campaign has been tracked from its earliest confirmed incident through each subsequent escalation.

All four documented attack vectors deployed malware purpose-built to exfiltrate cloud provider credentials, SSH keys, Kubernetes configs, and CI/CD secrets. Stolen material was encrypted before exfiltration to attacker-controlled infrastructure, then rapidly validated and used to pivot through victim environments. Operational consistency across all intrusions points to a single coordinated actor — though credential sharing or resale to third parties cannot be ruled out.

All victim data below derives from TeamPCP's own disclosures or corroborating open-source intelligence. No organisation listed here has necessarily confirmed a security incident. Status labels reflect current assessment only.
02

Confirmed Attack Vectors

4 confirmed
19 Mar 2025
Trivy
Aqua Security
Credential-harvesting malware injected into Aqua Security's open source vulnerability scanner. Distributed via the compiled binary, GitHub Actions workflow, and container images.
23 Mar 2025
KICS
Checkmarx
The same malware family appeared in Checkmarx's infrastructure-as-code scanner, distributed via the GitHub Action and through the OpenVSX extension marketplace.
24 Mar 2025
LiteLLM
PyPI
Malicious versions of the popular LLM proxy library pushed to PyPI. Payloads engineered to harvest developer environment credentials at install time.
27 Mar 2025
Telnyx SDK
PyPI
Backdoored releases of the Telnyx Python SDK published to PyPI. Malicious payload functionally identical to prior attacks, using the same exfiltration infrastructure.
03

Alleged Victim Organisations

57 organisations · 19 countries

Named as direct victims in TeamPCP disclosures. No listing should be treated as a confirmed breach unless explicitly marked. Click a country to expand entries.

🇦🇺 Australia
3 entries
OrganisationDomainStatusNote
Alex Solutionsalexsolutions.comClaimedNo public confirmation.
Microbamicroba.comClaimedGut microbiome diagnostics. No public confirmation.
Symbio (MNF Group)symbio.globalClaimedTelecom infrastructure. Rebranded from mnf-group.
🇦🇹 Austria
1 entry
OrganisationDomainStatusNote
FIOR Digital (21bitcoin)21bitcoin.comClaimedBitcoin financial services. No public confirmation.
🇧🇷 Brazil
2 entries
OrganisationDomainStatusNote
Aarinaarin.com.brClaimedFintech / payments infrastructure.
Brasil Paralelobrasilparalelo.com.brClaimedMedia platform. No public confirmation.
🇨🇦 Canada
3 entries
OrganisationDomainStatusNote
Lululemonlululemon.comClaimedPublicly listed athletic apparel company.
PocketHealthpockethealth.comClaimedMedical imaging platform.
R2 Capitalr2capital.caClaimedNo public confirmation.
🇨🇱 Chile
2 entries
OrganisationDomainStatusNote
CMPCcmpc.comClaimedMajor pulp and paper manufacturer.
PreUPDVpreupdv.clClaimedEducation platform.
🇨🇴 Colombia
1 entry
OrganisationDomainStatusNote
Farmaonlinefarmaonline.comClaimedOnline pharmacy.
🇩🇰 Denmark
1 entry
OrganisationDomainStatusNote
Norlys Energy Tradingnorlysenergytrading.comClaimedEnergy trading arm of Norlys.
🇫🇷 France
4 entries
OrganisationDomainStatusNote
Norautonorauto.comClaimedAuto repair chain.
OKwindokwind.comClaimedRenewable energy.
Orange Open Sourceopensource.orange.comClaimedOpen source division of telecom giant Orange.
Tealeteale.ioClaimedHealthcare SaaS.
🇩🇪 Germany
4 entries
OrganisationDomainStatusNote
GotPhotogotphoto.comClaimedPhotography platform.
Nooxitnooxit.comClaimedNo public confirmation.
OG1Oog1o.comClaimedNo public confirmation.
understand.aiunderstand.aiClaimedAI data annotation (acquired by Daimler).
🇮🇱 Israel
1 entry
OrganisationDomainStatusNote
Illusive Networksillusivenetworks.comClaimedCybersecurity (deception tech).
🇲🇽 Mexico
1 entry
OrganisationDomainStatusNote
Auronixauronix.comClaimedBusiness messaging platform.
🇳🇱 Netherlands
4 entries
OrganisationDomainStatusNote
Assertive Yieldassertiveyield.comClaimedAd monetisation platform.
Axualaxual.comClaimedKafka-based streaming platform.
Finomfinom.coClaimedBusiness finance platform.
Radventureradventure.comClaimedNo public confirmation.
🇳🇴 Norway
2 entries
OrganisationDomainStatusNote
Statkraftstatkraft.seClaimedEurope's largest renewable energy producer.
TOMRAtomra.comClaimedResource collection / reverse vending systems (listed OSE).
🇵🇱 Poland
1 entry
OrganisationDomainStatusNote
eobuwieeobuwie.com.plClaimedMajor online footwear retailer.
🇿🇦 South Africa
1 entry
OrganisationDomainStatusNote
CrazyBetcrazybet.comClaimedOnline sports betting.
🇪🇸 Spain
2 entries
OrganisationDomainStatusNote
APIQualityapiquality.ioClaimedAPI governance platform.
Cloudappicloudappi.netClaimedSoftware development firm.
🇸🇪 Sweden
2 entries
OrganisationDomainStatusNote
Handelshögskolan (HHS)hhs.seClaimedStockholm School of Economics.
Toptracertoptracer.comClaimedGolf technology (Callaway subsidiary).
🇬🇧 United Kingdom
1 entry
OrganisationDomainStatusNote
Holland & Barretthollandandbarrett.comClaimedMajor health & wellness retailer.
🇺🇸 United States
19 entries
OrganisationDomainStatusNote
Azra AIazra-ai.comClaimedOncology AI.
Ciscocisco.com✓ ConfirmedConfirmed by BleepingComputer (31 Mar 2026). 300+ GitHub repos cloned, AWS keys stolen via Trivy supply chain credentials.
Corelightcorelight.comClaimedNetwork detection & response.
CoverSelfcoverself.comClaimedInsurance SaaS.
Cynerio (→ Axonius)axonius.comClaimedHealthcare IoT security, acquired by Axonius.
Databricksdatabricks.com✗ DeniedInvestigated and found nothing in internal systems. Official statement via @DatabricksSec.
DeepHealthdeephealth.comClaimedAI radiology platform.
Excel Impactexcelimpact.comClaimedNo public confirmation.
Life.Churchlife.churchClaimedLarge multi-site church organisation.
LotLinxlotlinx.comClaimedAutomotive inventory AI.
Metafarmetafar.ioClaimedNo public confirmation.
OpsVanguardopsvanguard.comClaimedNo public confirmation.
Ping Identitypingidentity.com◐ PartialCorporate address found in exfiltrated credential dump.
Pluralsightpluralsight.comClaimedTech learning platform.
Rivianrivian.comClaimedPublicly listed EV manufacturer.
Saviyntsaviynt.comClaimedIdentity security SaaS.
Strykerstryker.comClaimedPublicly listed medical devices company.
TeamWorksteamworks.comClaimedAthlete management platform.
Turion Spaceturionspace.comClaimedSpace debris removal startup.
Varo Moneyvaromoney.comClaimedNeobank / consumer fintech.
Vermillvermill.ioClaimedNo public confirmation.
04

Downstream Credential Exposure

21 organisations

Corporate-domain addresses found in the exfiltrated credential dump. These organisations were not necessarily direct targets — exposure is a downstream consequence of staff running affected tooling. Entries marked ★ also appear in the direct victim list.

Corporate domains only — personal addresses excluded
OrganisationDomainCountryStatus
Appliedapplied.co🇬🇧 UK◐ Credential Exposure
Atosatos.net🇫🇷 France◐ Credential Exposure
BMWbmw.de🇩🇪 Germany◐ Credential Exposure
CAIS Groupcaisgroup.com🇺🇸 US◐ Credential Exposure
CloudOfficercloudofficer.ca🇨🇦 Canada◐ Credential Exposure
Deloittedeloitte.com / .co.uk🇺🇸🇬🇧 US / UK◐ Credential Exposure
Ernst & Young (EY)gds.ey.com🌐 Global◐ Credential Exposure
Evinova / AstraZenecaevinova.com🇸🇪 Sweden✓ Confirmed
Funky Penguinfunkypenguin.co.nz🇳🇿 NZ◐ Credential Exposure
GlobalHitssglobalhitss.com🇨🇴 Colombia◐ Credential Exposure
Hiperhiper.com.br🇧🇷 Brazil◐ Credential Exposure
Impinjimpinj.com🇺🇸 US◐ Credential Exposure
Komatsuglobal.komatsu🇯🇵 Japan◐ Credential Exposure
LSEGlseg.com🇬🇧 UK◐ Credential Exposure
Mapfremapfre.com🇪🇸 Spain◐ Credential Exposure
MSG Groupmsg.group🇩🇪 Germany◐ Credential Exposure
MTN Groupmtn.com🇿🇦 South Africa◐ Credential Exposure
NielsenIQnielseniq.com🇺🇸 US◐ Credential Exposure
Ping Identity ★pingidentity.com🇺🇸 US◐ Credential Exposure
Samsungsamsung.com🇰🇷 South Korea◐ Credential Exposure
WeCodewecode.dk🇩🇰 Denmark◐ Credential Exposure
05

Disclaimer

!
Important Notice

All information on this page is compiled from open-source intelligence (OSINT), threat actor communications, and third-party security reporting. Claims are not independently verified unless explicitly stated. Organisations listed as alleged victims have not necessarily confirmed any security incident, and their inclusion does not constitute an assertion of breach.

This page exists solely for informational and research purposes. Nothing here constitutes legal advice, confirmed attribution, or an official statement of compromise. If your organisation is listed and you have information to share, correct, or dispute, reach out via X or Telegram.