step-security · Crawled Aug 13, 2026

Team PCP Stole 78,330 Secrets From 2,186 Organizations. CloudSEK Just Published the List.

6 IoCs
Read original article ↗

AI Summary

Team PCP, a threat actor active in 2026, executed a widespread software supply chain attack by compromising trusted open source projects such as Trivy, KICS, telnyx, and LiteLLM. The group injected credential stealers into CI/CD pipelines, exfiltrating 78,330 secrets from 2,186 organizations between March 19 and 24, 2026. These stolen credentials included cloud access keys, API tokens, and private keys, enabling further pivoting across organizations. The attack targeted CI/CD environments due to their weak security posture despite handling highly privileged credentials.

AI-extracted · verify before operational use

Indicators of Compromise 6 extracted

Type Value Detail
GitHub Repo trivy Details →
GitHub Repo checkmarx/kics Details →
Package telnyx Details →
Package littellm Details →
Package axios Details →
GitHub Repo backstage Details →