HIGH
TeamPCP Linked To Redis Attacks Dating Back To 2020 And Later Supply Chain Campaign
Researchers have linked the threat actor TeamPCP to Redis-targeting attacks dating back to 2020, predating its more recent pivot into a software supply chain campaign. The attribution rests on overlapping domains, malware deployment paths, staging techniques, and shared backend infrastructure. The findings suggest a threat actor with years of experience compromising internet-facing infrastructure is now applying that tradecraft to supply chain targets. No specific packages or victims were named in the available summary.