Sponsor of the Day:
Jerkmate
https://securitylabs.datadoghq.com/articles/litellm-compromised-pypi-teampcp-supply-chain-campaign/
LiteLLM and Telnyx compromised on PyPI: Tracing the TeamPCP supply chain campaign | Datadog...
On March 24 and 27, 2026, malicious PyPI releases of LiteLLM and Telnyx were published as part of the TeamPCP supply chain campaign. We trace the full campaign...
teampcp supply chainlitellmtelnyxcompromisedpypi
https://www.infosecurity-magazine.com/news/teampcp-litellm-pypi-supply-chain/
TeamPCP Expands Supply Chain Campaign With LiteLLM PyPI Compromise - Infosecurity Magazine
Apr 9, 2026 - Python package LiteLLM compromised with credential-stealing malware linked to TeamPCP threat group
supply chain campaignlitellm pypiinfosecurity magazineteampcpexpands
https://it.slashdot.org/story/26/04/24/2032218/bitwarden-cli-is-the-next-compromise-in-checkmarx-supply-chain-campaign
Bitwarden CLI Is the Next Compromise In Checkmarx Supply Chain Campaign - Slashdot
Longtime Slashdot reader Himmy32 writes: Socket Security published an article on the compromise of the Bitwarden CLI client, which was pushed from Bitwarden's...
checkmarx supply chainbitwarden clinextcompromisecampaign
https://thehackernews.com/2026/04/bitwarden-cli-compromised-in-ongoing.html
Bitwarden CLI Compromised in Ongoing Checkmarx Supply Chain Campaign
Bitwarden CLI 2026.4.0 was compromised via GitHub Actions in Checkmarx campaign, exposing secrets and distributing malicious npm code
checkmarx supply chainbitwarden clicompromisedongoingcampaign
https://ramimac.me/teampcp/
Incident Timeline // TeamPCP Supply Chain Campaign
Apr 7, 2026 - Timeline and IOCs for TeamPCP's March 2026 supply chain campaign. Trivy, KICS, LiteLLM, and 45+ npm packages compromised through chained credential theft.
teampcp supply chainincidenttimelinecampaign
https://www.sans.org/blog/when-security-scanner-became-weapon-inside-teampcp-supply-chain-campaign
When the Security Scanner Became the Weapon: Inside the TeamPCP Supply Chain Campaign | SANS...
Mar 26, 2026 - A trusted security scanner was weaponized. One stolen token cascaded across five ecosystems—CI/CD, npm, Docker, and AI infrastructure. The TeamPCP campaign...
teampcp supply chainsecurity scannerbecameweaponinside
https://securityboulevard.com/2026/04/bitwarden-cli-compromise-linked-to-ongoing-checkmarx-supply-chain-campaign/
Bitwarden CLI Compromise Linked to Ongoing Checkmarx Supply Chain Campaign - Security Boulevard
Apr 24, 2026 - While the attack on Bitwarden can be connected to the Checkmarx incident, it's unclear whether the same threat group is behind both.
checkmarx supply chainbitwarden clisecurity boulevardcompromiselinked
https://jamestown.org/prc-supply-chain-ecosystem-behind-irans-drone-campaign/
PRC Supply Chain Ecosystem Behind Iran's Drone Campaign - Jamestown
supply chain ecosystembehind irandrone campaignprcjamestown