people · May 20, 2026
TeamPCP Supply Chain Campaign Remains Active Through May 17 2026
Share the canonical public link.
SANS Internet Storm Center reported that the TeamPCP supply chain campaign continued its activity through May 17 2026 with LiteLLM remaining a key target in the ongoing series of attacks. The campaign previously compromised Trivy to enable credential theft from LiteLLM and Telnyx packages on PyPI. Researchers noted the loudest stretch of activity since earlier 2026 incidents as of the May 17 update. The diary entry covers ongoing monitoring of the same threat actor group behind the March LiteLLM backdoor publications.
Below validation threshold — auto-passed without scoring