
TeamPCP supply chain attacks compromise 500+ software packages
TeamPCP may have compromised over 500 software packages in a series of supply chain attacks since March 2026. The attacks appear to have targeted trusted developer tools and spread to many ecosystems, including npm, Docker, and PyPI, mainly to steal credentials like GitHub tokens and cloud secrets. Researchers suggest the campaign used a shared tool and centralized control, and that any secrets exposed during affected workflows should be considered compromised. There is concern that TeamPCP might try new methods in the future, including targeting developer environments and IDEs. Security teams are advised to review their tools and rotate credentials as a precaution.













