(TLP:CLEAR) FBI Warns of TeamPCP Software Supply Chain Compromises
Created: Thursday, July 9, 2026 - 14:01
Categories: Cybersecurity, Federal & State Resources, Security Preparedness
Summary: The FBI recently released a FLASH report on TeamPCP, a cyber criminal group linked to large-scale software supply chain compromises. In plain terms, the group targets trusted software tools and update channels so malicious code can reach organizations through software that appears legitimate. The FBI reports TeamPCP has modified developer and security tools, including Trivy, KICS, LiteLLM, and the Telnyx Python SDK, to steal sensitive access information and maintain access to victim environments.
Analyst Note: This activity matters for water and wastewater utilities because many organizations rely on vendors, cloud tools, and security products that connect into sensitive environments. Even if a utility is not developing software itself, a compromised vendor tool or exposed credential can create risk beyond the original point of infection.
The FBI notes that stolen credentials may remain useful to attackers long after the first compromise. Utilities can reduce their exposure by reviewing where sensitive credentials are stored, limiting access granted to third-party tools, and ensuring incident response plans account for software supply chain events. WaterISAC encourages members to make use of the IOCs included in the FBI FLASH to support detection, threat hunting, and vendor follow-up.
Original Source: https://www.ic3.gov/CSA/2026/260702.pdf
Additional Reading:
- Defending against TeamPCP software supply chain attacks
- Weaponizing the Protectors: TeamPCP’s Multi-Stage Supply Chain Attack on Security Infrastructure
Related WaterISAC PIRs: 6, 7, 7.1, 10, 11, 12
