There is currently a wave of supply chain attacks clustered around TeamPCP, a financially motivated threat actor.
Today, the latest news was telnyx's python package had malicious versions pushed. This follows trivy, checkmarx (kics), and litellm incidents.
Get the details: ramimac.me/teampcp
ramimac.me
TeamPCP Supply Chain Campaign | Attack Timeline & IOCs
Timeline and IOCs for TeamPCP's March 2026 supply chain campaign. Trivy, KICS, LiteLLM, and 45+ npm packages compromised through chained credential theft.