TeamPCP Supply Chain Campaign Update: Critical Threats & Mitigation
Key Developments in the TeamPCP Threat Landscape
The TeamPCP supply chain campaign continues to evolve with alarming speed. This update highlights three critical developments: a new PyPI SDK compromise, a ransomware affiliate partnership, and the first named victim breach. Cybersecurity teams must act swiftly to mitigate these risks.
Telnyx Python SDK Compromised via WAV Steganography
On March 27, 2026, TeamPCP exploited stolen PyPI credentials to publish malicious versions of the telnyx SDK (4.87.1 and 4.87.2). These versions embedded payloads using WAV audio file steganography, leveraging Telnyx’s telecom API purpose to hide malicious code. Key indicators include:
- Windows: Persistent
msbuild.exein Startup folders - Linux/macOS: Credential harvesters mirroring LiteLLM patterns
- Exfiltration:
tpcp.tar.gzdata transfers to known domains
Action: Audit Python environments for versions 4.87.1/4.87.2. Rotate credentials immediately if found. The last safe version is 4.87.0.
TeamPCP & Vect Ransomware: A 300,000-Affiliate Mobilization
TeamPCP has partnered with Vect ransomware-as-a-service and BreachForums to distribute affiliate keys to 300,000 users. This marks a shift from credential theft to industrialized ransomware deployment. Analysts warn this could become the largest ransomware affiliate campaign ever recorded.
Implications: Organizations exposed to TeamPCP’s Trivy, Checkmarx, or LiteLLM compromises must assume credentials are now widely distributed. Monitor for Vect ransomware indicators immediately.
AstraZeneca Breach Claimed Using TeamPCP Credentials
LAPSUS$ has claimed a 3GB breach of AstraZeneca, allegedly using credentials stolen during the TeamPCP campaign. The data includes cloud configs, code repositories, and employee information. This is the first named victim breach linked to the campaign.
Action: Proactively rotate credentials if your organization was exposed to any TeamPCP-compromised component. Do not wait for public disclosures.
Technical Deep Dive: LiteLLM CEO’s GitHub Compromise
ReversingLabs revealed TeamPCP targeted LiteLLM CEO Krish Dholakia’s personal GitHub account directly, not through generic token sweeps. This precision targeting underscores the group’s focus on high-impact PyPI maintainers.
Key Findings:
- Attackers prioritized credentials with PyPI publishing privileges
- Stolen credentials were triaged for maximum impact
- LiteLLM’s
.pthfile exploitation allowed persistence across all Python processes
Critical Mitigation Steps
- Audit PyPI dependencies: Scan for
telnyxversions 4.87.1/4.87.2 andlitellm==1.82.8. - Rotate credentials: Treat all credentials accessible to compromised environments as compromised.
- Monitor for C2 domains: Watch for HTTPS exfiltration to
models.litellm.cloud. - Update compliance audits: Verify third-party auditors like Delve are not rubber-stamping certifications.
Conclusion: The Urgency of Proactive Defense
The TeamPCP campaign has escalated from credential theft to coordinated ransomware deployment and high-profile breaches. Cybersecurity teams must treat this as a systemic risk. Immediate actions include credential rotation, dependency audits, and monitoring for Vect ransomware indicators.
Call to Action: Share this update with your team. Use the mitigation checklist above to secure your systems. Subscribe to threat intelligence feeds for real-time updates on TeamPCP’s evolving tactics.







