CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

The Worm That Keeps on Digging: TeamPCP Hits @antv in Latest Wave

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 1278

As cited

Copy frozen at (site build).

threat intel

The Worm That Keeps on Digging: TeamPCP Hits @antv in Latest Wave

TeamPCP has conducted a multi-ecosystem supply chain compromise targeting GitHub, NPM, and Visual Studio Code (VSCode) environments. The attack aims to steal credentials and establish persistence across these development platforms. This represents a coordinated effort to infiltrate multiple layers of the software development toolchain.

Why it matters: Developers and organizations using GitHub, NPM, and VSCode are at immediate risk of credential theft and unauthorized access to their repositories and systems. Teams should audit package dependencies, review access logs, and rotate credentials if exposed through these compromised ecosystems.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

The Worm That Keeps on Digging: TeamPCP Hits @antv in Latest Wave

TeamPCP has conducted a multi-ecosystem supply chain compromise targeting GitHub, NPM, and Visual Studio Code (VSCode) environments. The attack aims to steal credentials and establish persistence across these development platforms. This represents a coordinated effort to infiltrate multiple layers of the software development toolchain.

Why it matters: Developers and organizations using GitHub, NPM, and VSCode are at immediate risk of credential theft and unauthorized access to their repositories and systems. Teams should audit package dependencies, review access logs, and rotate credentials if exposed through these compromised ecosystems.

VendorsGitHub
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary