1
Threat Overview
TeamPCP is a supply chain campaign that affects multiple package ecosystems, including GitHub, and has been observed to trojanize a Microsoft-published Python SDK. The threat appears to have open-sourced its own framework on GitHub. This campaign poses a significant risk to users of affected packages.
2
Key Intelligence Points
1. TeamPCP operates across three package ecosystems in parallel, including GitHub. 2. The threat has been observed to trojanize a Microsoft-published Python SDK. 3. TeamPCP has open-sourced its own framework on GitHub. 4. Detection opportunities may include unusual package dependencies or code modifications in GitHub repositories.
3
MITRE ATT&CK Techniques
T1190 - Spyware: Malware is used to steal sensitive information from the victim's system
4
Indicators of Compromise (IOCs) / Affected Systems
TeamPCP framework on GitHub, GitHub repository names, affected Python SDK versions
5
Mitigation & Detection
Users should review their dependencies and update to the latest versions of affected packages. Additionally, developers should scrutinize open-source code for potential tampering.