Gallery

Contacts

411 University St, Seattle, USA

engitech@oceanthemes.net

+1 -800-456-478-23

A threat actor tracked as TeamPCP is running a third-generation npm supply chain campaign, placing malicious packages that impersonate widely used enterprise tools including SAP Cloud Application Programming (CAP) ecosystem libraries and the Bitwarden CLI password manager. Organizations consuming these packages via automated CI/CD pipelines are at risk of credential theft across AWS, Azure, GCP, and Kubernetes environments without any user interaction beyond a routine dependency install. The business risk is direct exfiltration of cloud access keys, pipeline secrets, and cryptocurrency wallets from enterprise build infrastructure at scale.

Author

Tech Jacks Solutions