TeamPCP supply-chain credential-exploitation campaign
Campaign
Summary
Hide ▲
Show ▼
TeamPCP was reported on March 30-31, 2026 to be monetizing secrets from supply-chain intrusions, including cloud credentials, SSH keys, and Kubernetes configuration files, by validating, encrypting, and exfiltrating them to attacker-controlled domains. Wiz also said the group was collaborating with Lapsus$, suggesting a broader extortion ecosystem. In a later update, Checkmarx said TeamPCP compromised its Jenkins AST plugin by publishing a rogue version to repo.jenkins-ci.org on May 9, 2026, outside the release pipeline. Checkmarx advised users to use version 2.0.13-829.vc72453fa_1c16 or older, rotate secrets, and look for lateral movement or persistence.
Related Happenings
AsyncAPI repositories and npm publishing workflow hit by network compromise
Incident
H score27
First: 15.07.2026 12:16
Last: 15.07.2026 12:16
Sources 1
About this happening:
The AsyncAPI npm publishing pipeline was compromised in a July 14 supply-chain attack that used the project’s normal GitHub Actions release path to publish trojani...
AsyncAPI repositories and npm publishing workflow hit by network compromise
IncidentAbout this happening: The AsyncAPI npm publishing pipeline was compromised in a July 14 supply-chain attack that used the project’s normal GitHub Actions release path to publish trojani...
GitHub fake-repository infostealer campaign
Campaign
H score41
First: 14.07.2026 22:15
Last: 14.07.2026 22:15
Sources 1
About this happening:
A GitHub impersonation campaign is distributing infostealer malware through 292 fake repositories, expanding the risk to users searching for trusted software downloads...
GitHub fake-repository infostealer campaign
CampaignAbout this happening: A GitHub impersonation campaign is distributing infostealer malware through 292 fake repositories, expanding the risk to users searching for trusted software downloads...
WP-SHELLSTORM webshell access brokerage campaign
Campaign
H score71
First: 10.07.2026 14:30
Last: 10.07.2026 14:30
Sources 1
About this happening:
The WP-SHELLSTORM campaign exposed its own infrastructure, revealing a webshell access brokerage that targeted WordPress and Joomla sites at scale and backdoored *...
WP-SHELLSTORM webshell access brokerage campaign
CampaignAbout this happening: The WP-SHELLSTORM campaign exposed its own infrastructure, revealing a webshell access brokerage that targeted WordPress and Joomla sites at scale and backdoored *...
Injective Labs SDK project GitHub repository hit by network compromise
Incident
H score21
First: 09.07.2026 23:10
Last: 09.07.2026 23:10
Sources 1
About this happening:
The Injective Labs SDK project suffered a GitHub repository compromise that let attackers publish a malicious @injectivelabs/sdk-ts v1.20.21 package, putting developer...
Injective Labs SDK project GitHub repository hit by network compromise
IncidentAbout this happening: The Injective Labs SDK project suffered a GitHub repository compromise that let attackers publish a malicious @injectivelabs/sdk-ts v1.20.21 package, putting developer...
Single organization's private GitHub repository cloned after confirmed access
Data Leak
H score12
First: 09.07.2026 21:38
Last: 09.07.2026 21:38
Sources 1
About this happening:
Confirmed access to a private GitHub repository belonging to one organization marks a concrete data exposure and raises the risk of source-code or internal-content...
Single organization's private GitHub repository cloned after confirmed access
Data LeakAbout this happening: Confirmed access to a private GitHub repository belonging to one organization marks a concrete data exposure and raises the risk of source-code or internal-content...
Timeline
-
12.05.2026 01:03 2 articles · 2mo ago
TeamPCP compromises Checkmarx Jenkins AST plugin
Campaign Scope UpdateTeamPCP compromised the Checkmarx Jenkins AST plugin by publishing a rogue version to repo.jenkins-ci.org on May 9, 2026, outside the official release pipeline. The malicious upload was tied to access to Checkmarx GitHub repositories and was used to deliver credential-stealing malware and malicious code to the affected organization.
Show sources
- Official CheckMarx Jenkins package compromised with infostealer — www.bleepingcomputer.com — 12.05.2026 01:03
- GitHub Internal Repositories Breached via Malicious Nx Console VS Code Extension — thehackernews.com — 21.05.2026 07:27
-
30.03.2026 03:00 1 articles · 3mo ago
Wiz reports TeamPCP monetizing stolen supply-chain secrets
Initial DisclosureTeamPCP is reported to be exploring ways to monetize secrets harvested during supply-chain campaigns, including cloud credentials, SSH keys, Kubernetes configuration files, and other coding process secrets, while validating, encrypting, and exfiltrating those secrets to attacker-controlled domains; Wiz also said TeamPCP was explicitly collaborating with Lapsus$.
Show sources
- TeamPCP Explores Ways to Exploit Stolen Supply Chain Secrets — www.infosecurity-magazine.com — 31.03.2026 15:15