TeamPCP resumes supply chain attacks, poisoning xinference PyPI and triggering a Bitwarden CLI cascade via compromised Docker image.
The TeamPCP supply chain campaign resumed after a 26-day pause with three concurrent compromises targeting Checkmarx KICS (Docker Hub), xinference (a popular AI inference PyPI package), and a …
AML.T0010 - ML Supply Chain Compromise
AML.T0019 - Publish Poisoned Datasets
AML.T0047 - ML-Enabled Product or Service