PulseAugur
EN
LIVE 09:49:26
research · [1 source] ·

TeamPCP exploits GitHub, Grafana, and VS Code in supply chain attacks

A coordinated series of cyberattacks, attributed to the group TeamPCP, has exploited vulnerabilities across the software supply chain. These attacks, which began with a malicious VS Code extension on a GitHub employee's device, led to the exfiltration of thousands of internal repositories. Further incidents include the compromise of Grafana via an unrotated token, a breach of a widely used GitHub Action, and the discovery of sensitive credentials in a public spreadsheet, highlighting the pervasive nature of supply chain risks. AI

Summary written by gemini-2.5-flash-lite from 1 sources. How we write summaries →

RANK_REASON The cluster details a coordinated and sophisticated supply chain attack impacting multiple high-profile platforms and tools, leading to significant data exfiltration and highlighting a major shift in cyberat [lever_c_demoted from significant: ic=1 ai=0.1]

Read on Mastodon — sigmoid.social →

COVERAGE [1]

  1. Mastodon — sigmoid.social TIER_1 · [email protected] ·

    🕵🏻‍♂️ [InfoSec MASHUP] 21/2026 - The Supply Chain Didn't Break. It Was Walked. This week's issue reads like a case study in cascade failure. A malicious VS Code

    🕵🏻‍♂️ [InfoSec MASHUP] 21/2026 - The Supply Chain Didn't Break. It Was Walked. This week's issue reads like a case study in cascade failure. A malicious VS Code extension on one # GitHub employee's device leads to 3,800 internal repositories exfiltrated — by # TeamPCP , the same …