< Back to all clusters
[TECHNOLOGY] · United States, China · 2 sources

Global Cyber Threats: Interpol‑Phishing Scam and TeamPCP Supply‑Chain Attack

Bitdefender reported a coordinated phishing campaign that masqueraded as INTERPOL to lure small‑ and medium‑sized enterprises worldwide into downloading a malicious script. The fake law‑enforcement emails claimed recipients were under international investigation, prompting victims across Europe, Asia, the Middle East and North America to install a Trojan that enabled ransomware deployment. The operation targeted sectors such as food, agriculture, legal services, pharmaceuticals, media, technology and finance, and used the anonymous messaging platform Tox for ransom negotiations.

Separately, the FBI issued a FLASH alert identifying the cyber‑crime group TeamPCP as the source of large‑scale software‑supply‑chain compromises. The actors injected malicious code into trusted developer tools—including Trivy, KICS, LiteLLM and the Telnyx Python SDK—and distributed the poisoned updates through normal package repositories. The compromised tools automatically installed credential‑stealing malware in CI/CD pipelines, harvesting cloud access tokens, Kubernetes secrets and cryptocurrency wallet data for AWS, GCP and Azure. TeamPCP also deployed self‑replicating worms (Mini Shai‑Hulud and its Miasma variant) that spread across npm and PyPI registries, and engaged in extortion by publishing victim names on a public leak site. The FBI advises organizations to treat any stolen credentials as permanently compromised and to remediate affected tools promptly.