As cited
Copy frozen at (site build).
threat intel
The Worm That Keeps on Digging: TeamPCP Hits @antv in Latest Wave
TeamPCP has conducted a multi-ecosystem supply chain compromise targeting GitHub, NPM, and Visual Studio Code (VSCode) environments. The attack aims to steal credentials and establish persistence across these development platforms. This represents a coordinated effort to infiltrate multiple layers of the software development toolchain.
Why it matters: Developers and organizations using GitHub, NPM, and VSCode are at immediate risk of credential theft and unauthorized access to their repositories and systems. Teams should audit package dependencies, review access logs, and rotate credentials if exposed through these compromised ecosystems.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
threat intel
The Worm That Keeps on Digging: TeamPCP Hits @antv in Latest Wave
TeamPCP has conducted a multi-ecosystem supply chain compromise targeting GitHub, NPM, and Visual Studio Code (VSCode) environments. The attack aims to steal credentials and establish persistence across these development platforms. This represents a coordinated effort to infiltrate multiple layers of the software development toolchain.
Why it matters: Developers and organizations using GitHub, NPM, and VSCode are at immediate risk of credential theft and unauthorized access to their repositories and systems. Teams should audit package dependencies, review access logs, and rotate credentials if exposed through these compromised ecosystems.
- Source published
- First seen by Cybersecurity Tracker