Arresti in Australia per TeamPCP e maxi campagna di supply-chain compromise

Arrests in Australia for TeamPCP and a massive supply-chain compromise campaign

Australian police have charged two men from Western Australia, accused of being part of the TeamPCP group, at the center of a long-running campaign of software supply chain attacks. According to authorities, the group hid malicious code in open source projects and then used it to steal credentials and data from thousands of organizations worldwide. Investigations, carried out together with the FBI and the Western Australia Police Force, led to searches in Perth and a total of 14 charges. Sources link the campaign to compromises of widely used tools such as Trivy, Checkmarx KICS and LiteLLM, making the case particularly serious for the open source ecosystem. The emergence of more than 500,000 stolen credentials shows the operational scale of the operation. The incident is important because it shows how a single compromise in the software supply chain can quickly spread across many different companies.

Source: Security Affairs

Leave a Reply

Your email address will not be published. Required fields are marked *


Post Comment