TeamPCP Hackers Charged in Australia Over Major Supply Chain Attacks
The Australian Federal Police (AFP) has charged two Western Australian men with a combined total of 14 offences for their alleged roles…
The Australian Federal Police (AFP) has charged two Western Australian men with a combined total of 14 offences for their alleged roles…
Two malicious LiteLLM releases on PyPI, versions 1.82.7 and 1.82.8, were live for about 40 minutes on March 24, 2026, carrying credential-stealing…
A new analysis by Oligo Security has uncovered that the threat actor known as TeamPCP has been active in the cybercrime scene…
TeamPCP is a cybercrime group alleged to have compromised open-source projects like Trivy, Checkmarx KICS, and LiteLLM in March 2026. The group…
Kamikaze is a wiper malware used by TeamPCP to wipe all nodes in a Kubernetes cluster. It is deployed via a DaemonSet…
CanisterWorm is a backdoor deployed by TeamPCP on Kubernetes nodes located outside Iran. It is part of the group's evolving malware arsenal,…
kube.py is a Python script used by TeamPCP after breaching Kubernetes environments. Early versions focused on propagation and persistence, while newer variants…
[TeamPCP](https://attack.mitre.org/groups/G1056) is a financially-motivated, cloud-native threat group that has been active since at least September 2025. Initially focused on ransomware and cryptocurrency…