Threat Advisories

TeamPCP Supply Chain Attack: Affected Organisations Disclosed

Written by Integrity360 | Aug 13, 2026, 1:05:52 PM

Digital Risk solutions provider CloudSek has published a list of organisations affected by a high profile campaign by TeamPCP.

TeamPCP is a threat actor that specialises in supply chain attacks, with the Shai Hulud malware and variants being attributed.

In this recent disclosure, TeamPCP is suspected of using a new malware variant, SANDCLOCK, which is also an information stealer with container-escape, credential harvesting and encryption-in-transit capabilities. Interestingly, the malware attempts to send collected credentials to a command and control channel, however if this fails the malware creates a repository inside the github repository, publishing the attack.

By looking for GitHub repositories created by the malware, a public list of affected organisations has been built by Cloudsek, spanning approximately 2500 organisations.

The attack specialises in compromising CICD pipelines. Many of the affected companies are AI early adopters, showing the inherent risk in complex, modern CICD deployments relying on hundreds or thousands of open source software packages.

Organisations are encouraged to review their CICD Pipeline practises, monitoring the code they use for malicious components and reducing the attack surface.

 

Credentials affected by this incident include:

AWS credentials

Azure credentials

OpenAI API Keys
Kubernetes ServiceAccount tokens
Local environment variables
Cryptocurrency wallet data

Cloud credentials
All API tokens
SSH keys

 

If you believe your organisation may have been affected by this incident, or are concerned about the risk posed to a CICD pipeline in your development environment, contact Integrity360 for assistance. Companies included in the list of affected organisations should contact the Integrity360 Incident Response team as soon as possible.