보안위협 (악성코드, 취약점)/Threat Actor

TeamPCP - 패키지 저장소 전문 공격 그룹

쿨캣7 2026. 9. 1. 15:15
728x90
반응형

 

TeamPCP

 

TeamPCP는 2025년 말에 등장한 패키지 저장소 전문 공격 그룹입니다.

 

TeamPCP의 활동과 멀리서 그들을 지켜보는 경찰들 이미지 (by GROK)

 

 

LiteLLM Supply Chain Attack: Inside the AI Breach That Exposed 2,500+ Companies
https://socradar.io/blog/litellm-supply-chain-attack/ 

 

LiteLLM AI Supply Chain Attack Explained

Malicious LiteLLM PyPI packages compromised 2,500+ organizations in this AI supply chain breach. See what happened, who's affected, and how to respond.

socradar.io

 

 

활동 

 

가장 유명한 사건은 2026년 3월 Trivy, LiteLLM 공급망 공격입니다. 

 

시기 내용
2026.03.19 Trivy 공격 Trivy, Checkmarx KICS, SAP, TanStack 침해
03.20 CanisterWorm (npm) 발견
03.24 LiteLLM 공급망 공격 (실제로는 Trivy 공급망 공격에서 시작)
04.29 Mini Shai-Hulud 발견
05.12 Shai-Hulud 3.0 소스코드 공개 
08.26 조직원 2명 호주에서 검거

 

 

이 사이트에 가장 잘 정리되어 있습니다.

 

 

TeamPCP Supply Chain Campaign

https://ramimac.me/teampcp/

 

Incident Timeline // TeamPCP Supply Chain Campaign

Timeline and IOCs for TeamPCP's March-June 2026 supply chain campaign. Trivy, KICS, LiteLLM, TanStack, AntV ecosystem, Microsoft DurableTask, GitHub, Red Hat Cloud Services, and 500+ npm packages compromised through chained credential theft.

ramimac.me

 

 

 

3월 Trivy 공급망 공격은 이후 사건과 꾸준히 연결됩니다.

 

https://xcoolcat7.tistory.com/92216

 

TeamPCP 의 Trivy 공급망 (Supply Chain) 공격과 여파 - CanisterWorm 그리고 Checkmarx KICS, LiteLLM, Telnyx 침해까

* Trivy 침해Trivy는 Aqua Security에서 개발한 컨테이너 보안 스캐너입니다. https://trivy.dev/ TrivyTrivy is the most popular open source security scanner for Vulnerability &, IaC, SBOM discovery, cloud scanning and Kubernetes securitytriv

xcoolcat7.tistory.com

 

 

Ringing in Chaos: How TeamPCP Weaponized the Telnyx Python SDK (2026.03.29)

https://hexastrike.com/resources/blog/threat-intelligence/ringing-in-chaos-how-teampcp-weaponized-the-telnyx-python-sdk/

 

Ringing in Chaos: How TeamPCP Weaponized the Telnyx Python SDK - Hexastrike Cybersecurity

Executive Summary On March 27, 2026 at roughly 03:51 UTC, threat actor TeamPCP uploaded two malicious versions (4.87.1 and 4.87.2) of the telnyx Python SDK to PyPI. The package pulls approximately 750,000 monthly downloads, and the blast radius extends wel

hexastrike.com

 

Weaponizing the Protectors: TeamPCP’s Multi-Stage Supply Chain Attack on Security Infrastructure (2026.03.31)

https://unit42.paloaltonetworks.com/teampcp-supply-chain-attacks/

 

Weaponizing the Protectors: TeamPCP’s Multi-Stage Supply Chain Attack on Security Infrastructure

TeamPCP continues its string of supply chain attacks, and announces a partnership with Vect ransomware group.

unit42.paloaltonetworks.com

 

 

 

Trivy, Not LiteLLM Behind the 2,500 Org Compromise (2026.08.14)

https://www.securityweek.com/trivy-not-litellm-behind-the-2500-org-compromise/

 

Trivy, Not LiteLLM Behind the 2,500 Org Compromise

95% of the 2,500 organizations supposedly affected by the LiteLLM supply chain attack were exposed by the Trivy hack.

www.securityweek.com

 

 

멤버 2명 검거

 

2026년 8월 26일 멤버 2명이 검가되었습니다.

 

 

https://xcoolcat7.tistory.com/92457

 

TeamPCP 조직원 검거 - 허술한 OPSec

2026년 8월 26일, 호주 연방경찰(AFP)과 서호주 경찰(WAPF)이 FBI와의 공조 수사를 통해 TeamPCP 소속으로 지목된 Ellis 닉네임을 사용하는 21세 루벤 이언 톰슨 (Ruben Ian Thomson)과 23세 루이스 마이클 게이블

xcoolcat7.tistory.com

 

728x90
반응형