Robuta

https://app.daily.dev/posts/namastex-ai-npm-packages-hit-with-teampcp-style-canisterworm--fzxcvip7s Namastex.ai npm Packages Hit with TeamPCP-Style... Multiple npm packages tied to Namastex Labs (Automagik suite) have been compromised with malware closely resembling the TeamPCP CanisterWorm campaign.... npm packagesaihitteampcpstyle https://detection.fyi/sigmahq/sigma/emerging-threats/2026/ta/teampcp/proc_creation_lnx_teampcp_litellm_supply_chain_attack_indicators/ LiteLLM / TeamPCP Supply Chain Attack Indicators | Detection.FYI Detects process executions related to the backdoored versions of LiteLLM (v1.82.7 or v1.82.8). In March 2026, a supply chain attack was discovered involving... supply chain attacklitellmteampcpindicatorsdetection https://es.aikido.dev/blog/telnyx-pypi-compromised-teampcp-canisterworm El popular paquete telnyx comprometido en PyPI por TeamPCP El popular paquete telnyx en PyPI, utilizado por grandes empresas de IA, ha sido comprometido por TeamPCP el popularpaquetetelnyxenpypi https://www.ioupdate.com/2026/03/27/teampcp-backdoors-litellm-versions-1-82-7-1-82-8-likely-via-trivy-ci-cd-compromise/ TeamPCP Strikes Again: `litellm` Package Breached Mar 27, 2026 - The Escalating Threat of Software Supply Chain Attacks: TeamPCP Breaches `litellm` In a stark reminder of the ever-present dangers in the open-source ecosystem, teampcpstrikeslitellmpackage https://castbox.fm/episode/SANS-Stormcast-Monday%2C-March-30th%2C-2026%3A-More-TeamPCP%3A-telnyx%3B-Netscaler-Exploit%3B-macOS-ClickFix-Fix%3B-Windows-Smart-Install-id4826282-id926581439 SANS Stormcast Monday, March 30th, 2026: More TeamPCP: telnyx; Netscaler Exploit; macOS ClickFix... https://cyber.netsecops.io/articles/npm-threat-landscape-teampcp-supply-chain-attack-shai-hulud/ TeamPCP Weaponizes npm with Malicious Bitwarden CLI in Sophisticated Supply Chain Attack -... May 1, 2026 - Unit 42 details a sophisticated npm supply chain attack by TeamPCP using a malicious @bitwarden/cli package to harvest credentials and propagate like a worm.... https://thebytedive.com/cybersecurity/260331-ai-supply-chain-attack-litellm-trivy-teampcp/ AI Supply Chain Attack: LiteLLM, Trivy, TeamPCP | The ByteDive Apr 28, 2026 - AI supply chain attack in March 2026 weaponized LiteLLM (97M downloads) and Trivy. TeamPCP kill chain analysis and defense playbook for developers. ai supply chainattacklitellmtrivyteampcp https://www.cybersecurity-help.cz/blog/5385.html SAP npm packages compromised in suspected TeamPCP supply-chain attack Researchers found that the attackers planted a malicious preinstall script into the packages. npm packagessupply chainsapcompromisedsuspected