CVE-2026-33634
Known exploited · CISA KEV
CISA federal remediation date Apr 9
Threats · 167 days ago
Mercor AI, an AI recruiting startup, publicly confirmed it was breached through the LiteLLM supply chain compromise linked to the TeamPCP cybercriminal group. The attackers used compromised credentials from the supply chain phase to access Mercor's cloud environment, enabling extensive post-compromise enumeration and exfiltration of 4TB of data. The stolen data includes source code, user databases, and biometric identity documents, raising privacy and regulatory risks under GDPR, CCPA, and possibly HIPAA.
This confirmation moves the TeamPCP campaign from theoretical risk to confirmed operational impact. Public threat intelligence sources currently show no TeamPCP indicators, complicating detection and response. The stolen credentials and sensitive data enable future intrusions without requiring new supply chain exploits, changing the threat model for affected organizations.
Known exploited · CISA KEV
CISA federal remediation date Apr 9
4 sources covering this story
TeamPCP Supply Chain Campaign: Update 005 - First Confirmed Victim Disclosure, Post-Compromise Cloud Enumeration Documented, and Axios Attribution Narrows, Author: Kenneth Hartman
TeamPCP Breaches Cloud, SaaS Instances with Stolen Credentials
The threat group's shift to speedy attacks on AWS, Azure, and SaaS instances shows organizations need to respond quickly to compromised credentials.
TeamPCP Moves From OSS to AWS Environments
After validating stolen credentials using TruffleHog, the hacking group started AWS services enumeration and lateral movement activities.
Tracking TeamPCP: Investigating Post-Compromise Attacks Seen in the Wild | Wiz Blog
How TeamPCP are leveraging stolen secrets from the recent supply chain attacks to compromise cloud environments
Part of the PlainSec briefing for 2026-04-02