TI Mindmap HUB
Threat Intelligence Report

TeamPCP’s Five-Day Siege: How One Stolen Token Cascaded Across GitHub Actions, Checkmarx, VS Code Extensions, and npm

📅 March 25, 2026 📰 phoenix.security 🔍 0 CVE(s) referenced

A single stolen GitHub token enabled TeamPCP to orchestrate an unprecedented, multi-vendor CI/CD supply chain attack that stealthily harvested credentials, deployed self-propagating npm malware with blockchain-based command-and-control, and compromised over 10,000 workflows—evading all traditional vulnerability detection methods.

vendor

Sign in to access the full report including:
detailed analysis, IOCs, MITRE ATT&CK mapping, and STIX bundle.

🔐 Sign In to Read Full Report

You'll need to accept our Terms of Service to access the platform.

📊 Visual Mindmap
🎯 IOC Extraction
⚔️ MITRE ATT&CK TTPs
📦 STIX 2.1 Bundle