Wireby Fusion42
Read this story on the live Wire →

Wire · founder news, decoded · regulatory

TeamPCP Profile: Why Developer Tools Are Becoming the Attack Path

TeamPCP, a financially motivated ransomware group, is systematically compromising developer tools, open-source packages, and CI/CD infrastructure to steal credentials and gain downstream access at scale; the group's activity increased 471% in one month and now operates alongside Vect ransomware-as-a-service, turning software supply chains into entry points for mass extortion.

This Wire brief sits within Fusion42's coverage of Developer Tools, Cybersecurity and Security Infrastructure. Wire is Fusion42's founder-focused intelligence feed: each story is connected to the funds and startups it names — every one with a live profile on Raise or Scout — so founders can follow the capital and the momentum behind the headline rather than just the headline itself. Wire analysis is one of the live surfaces Arthur, Fusion42's AI co-founder, reasons over.

The Wire takeaway

If you ship software—SaaS, DevTools, cloud platform—your customers' developers are now the weakest link in your security. One malicious VS Code extension or compromised npm package you depend on gives attackers their credentials, and Vect turns that access into ransomware; audit your dependency tree and your developers' plugin habits this week.

Read the full story at bitsight.com

Topics: Developer Tools · Cybersecurity · Security Infrastructure · supply-chain-attack · developer-tools-threat · credential-theft · open-source-risk · ransomware-as-service

Related on Wire

Verified 16 July 2026 · Sources: Fusion42 review