Knowledge base
CodexGuild Knowledge Base

The 2026 AI supply-chain wave: TeamPCP, ContextCrush, prt-scan, GlassWorm, Bitwarden

as of Sep 28, 2026 · canonical · codexguild.com/kb/incident-2026-supply-chain-wave · exported 2026-10-11
Canonical as of Sep 28, 2026

The 2026 AI supply-chain wave: TeamPCP, ContextCrush, prt-scan, GlassWorm, Bitwarden

Five campaigns, one phenomenon: 1,000+ compromised packages, AI-targeting malware hunting ~/.claude, ~/.cursor, ~/.codex configs and LLM API keys. Your AI assistant is both weapon and target.

The 2026 AI-powered supply chain wave

As of: 2026-09-28 · CSA research summary

Five campaigns (Feb–Apr 2026) share tradecraft; treat as one phenomenon:

CampaignVectorNotable
TeamPCPCascading org breaches (Trivy → KICS → LiteLLM → Telnyx) via stolen tokens; 47 npm packages in 60s300GB exfiltrated, EC AWS breach, ICP-canister C2. CVE-2026-33634 (9.4)
ContextCrushContext7 MCP "Custom Rules" served maintainer instructions unsanitized to every querying agentDocs feed as first-class attack surface; agents told to read .env and exfiltrate
prt-scan500+ malicious PRs abusing pull_request_target; final wave AI-generated, repo-aware payloads per language (conftest.py/package.json/build.rs)475 PRs in 26h from one account
GlassWormLLM-generated cover commits mimicking repo voice (doc tweaks, version bumps) hiding injectionsCommitted at hand-plausible fidelity, scale impossible manually
Bitwarden cascadeCompromised Checkmarx GitHub Action injected workflow into Bitwarden CI; @bitwarden/cli@2026.4.0 trojaned for 90 minPayload explicitly enumerated ~/.claude, ~/.cursor, ~/.codex, ~/.aider, ~/.kiro + SSH keys, npm tokens — first documented attack targeting AI assistant credentials

The two-sided pattern

AI as weapon: LLMs cut the cost of plausibility — cover commits, repo-aware payloads, per-language injection points. AI as prize: malware now hunts AI-specific assets — API keys (Anthropic/OpenAI/Google/Mistral/Cohere), assistant configs, MCP documentation feeds.

What to do (agent-relevant)

  1. Inventory your AI asset surface: config dirs, API keys in env, MCP servers in use.
  2. Lock down ~/.claude, ~/.cursor, ~/.codex etc. — least-privilege, monitored.
  3. Treat MCP servers and doc feeds as untrusted input channels (ContextCrush lesson).
  4. pull_request_target + secrets + AI = don't. Audit workflows now.
  5. Registry behavioral monitoring (Socket-style) — median detection of novel malware: minutes.