TeamPCP Supply Chain Campaign Update: Critical Threats & Mitigation

TeamPCP Supply Chain Campaign Update: Critical Threats & Mitigation

TeamPCP Supply Chain Campaign Update: Critical Threats & Mitigation

Key Developments in the TeamPCP Threat Landscape

The TeamPCP supply chain campaign continues to evolve with alarming speed. This update highlights three critical developments: a new PyPI SDK compromise, a ransomware affiliate partnership, and the first named victim breach. Cybersecurity teams must act swiftly to mitigate these risks.

Telnyx Python SDK Compromised via WAV Steganography

On March 27, 2026, TeamPCP exploited stolen PyPI credentials to publish malicious versions of the telnyx SDK (4.87.1 and 4.87.2). These versions embedded payloads using WAV audio file steganography, leveraging Telnyx’s telecom API purpose to hide malicious code. Key indicators include:

  • Windows: Persistent msbuild.exe in Startup folders
  • Linux/macOS: Credential harvesters mirroring LiteLLM patterns
  • Exfiltration: tpcp.tar.gz data transfers to known domains

Action: Audit Python environments for versions 4.87.1/4.87.2. Rotate credentials immediately if found. The last safe version is 4.87.0.

TeamPCP & Vect Ransomware: A 300,000-Affiliate Mobilization

TeamPCP has partnered with Vect ransomware-as-a-service and BreachForums to distribute affiliate keys to 300,000 users. This marks a shift from credential theft to industrialized ransomware deployment. Analysts warn this could become the largest ransomware affiliate campaign ever recorded.

Implications: Organizations exposed to TeamPCP’s Trivy, Checkmarx, or LiteLLM compromises must assume credentials are now widely distributed. Monitor for Vect ransomware indicators immediately.

AstraZeneca Breach Claimed Using TeamPCP Credentials

LAPSUS$ has claimed a 3GB breach of AstraZeneca, allegedly using credentials stolen during the TeamPCP campaign. The data includes cloud configs, code repositories, and employee information. This is the first named victim breach linked to the campaign.

Action: Proactively rotate credentials if your organization was exposed to any TeamPCP-compromised component. Do not wait for public disclosures.

Technical Deep Dive: LiteLLM CEO’s GitHub Compromise

ReversingLabs revealed TeamPCP targeted LiteLLM CEO Krish Dholakia’s personal GitHub account directly, not through generic token sweeps. This precision targeting underscores the group’s focus on high-impact PyPI maintainers.

Key Findings:

  • Attackers prioritized credentials with PyPI publishing privileges
  • Stolen credentials were triaged for maximum impact
  • LiteLLM’s .pth file exploitation allowed persistence across all Python processes

Critical Mitigation Steps

  1. Audit PyPI dependencies: Scan for telnyx versions 4.87.1/4.87.2 and litellm==1.82.8.
  2. Rotate credentials: Treat all credentials accessible to compromised environments as compromised.
  3. Monitor for C2 domains: Watch for HTTPS exfiltration to models.litellm.cloud.
  4. Update compliance audits: Verify third-party auditors like Delve are not rubber-stamping certifications.

Conclusion: The Urgency of Proactive Defense

The TeamPCP campaign has escalated from credential theft to coordinated ransomware deployment and high-profile breaches. Cybersecurity teams must treat this as a systemic risk. Immediate actions include credential rotation, dependency audits, and monitoring for Vect ransomware indicators.

Call to Action: Share this update with your team. Use the mitigation checklist above to secure your systems. Subscribe to threat intelligence feeds for real-time updates on TeamPCP’s evolving tactics.