Home / Companies / Socket / Blog / Post Details
Content Deep Dive

TeamPCP Partners With Ransomware Group Vect to Target Open Source Supply Chains

Blog post from Socket

Post Details
Company
Date Published
Author
Sarah Gooding
Word Count
757
Company Posts That Month
42
Language
English
Hacker News Points
-
Post removed?
No
Summary

The ongoing cyberattacks on open-source security tools like Trivy and LiteLLM have intensified, with reports indicating a collaboration between TeamPCP and the Vect ransomware group to exploit supply chain compromises for ransomware operations. Vect, a ransomware-as-a-service operation, and TeamPCP, known for their recent supply chain attacks, plan to deploy ransomware across affected companies, leveraging their partnership with BreachForums to expand their affiliate network. BreachForums, a prominent cybercrime marketplace, is enabling this expansion by distributing Vect affiliation keys to its members, potentially increasing the scale of ransomware attacks. This development marks a significant shift in targeting strategies, as attackers focus on open-source ecosystems and CI/CD workflows, gaining internal access to enterprise environments. TeamPCP has reportedly exfiltrated vast amounts of credentials and tokens from these environments, highlighting vulnerabilities within open-source infrastructure and emphasizing the need for increased security measures.

Trends Found in this Post
Trend Post Mentions Total Month Mentions Posts Companies MoM
Secrets Management 1 1,488 268 99 +7%
Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.