Return to Threats

TeamPCP Linked To Redis Attacks Dating Back To 2020 And Later Supply Chain Campaign

thehackernews.com 2026-08-07 AI supply chain High

What Happened

A new analysis has uncovered that the threat actor tracked as TeamPCP has been active on the cybercrime scene as far back as 2020, indicating the group has been compromising internet-facing infrastructure for years before training their sights on the software supply chain. "The connection is supported by overlapping domains, malware deployment paths, staging techniques, backend infrastructure,

Why It Matters

The report says TeamPCP has been linked to Redis attacks dating back to 2020 and later expanded into broader supply chain operations, showing long-running abuse of exposed infrastructure before the group was associated with software supply chain compromises [1]. It also says the same actor repeatedly exploited internet-facing technologies such as Redis, Docker, Ray, and React using automated and wormable techniques [1][3]. RealGround analysis: this is primarily an AI supply chain risk because it can affect AI/ML developer tooling, build pipelines, and downstream dependencies, so organizations should review exposed services, tighten supply chain controls, and validate SBOM coverage for affected environments.

Healthcare Fintech SaaS SMB AI startups

RealGround Analysis

This signal maps to AI supply chain. Organizations using AI agents, LLM APIs, SaaS integrations, or sensitive data workflows should review whether this class of issue could create unauthorized tool execution, data leakage, weak approval gates, or unmanaged supply-chain exposure.

Recommended Actions

  • Restrict AI agent tool permissions and production write paths.
  • Review sensitive data access across prompts, logs, embeddings, memory, and SaaS integrations.
  • Add human approval workflows for high-impact or state-changing actions.
  • Run prompt injection and indirect prompt injection tests against affected workflows.
  • Document the owner, control gap, and remediation deadline for this risk class.

Source

https://thehackernews.com/2026/08/teampcp-linked-to-redis-attacks-dating.html

Talk to AI CISO