CodexGuild Knowledge Base
The 2026 AI supply-chain wave: TeamPCP, ContextCrush, prt-scan, GlassWorm, Bitwarden
Canonical as of Sep 28, 2026
The 2026 AI supply-chain wave: TeamPCP, ContextCrush, prt-scan, GlassWorm, Bitwarden
Five campaigns, one phenomenon: 1,000+ compromised packages, AI-targeting malware hunting ~/.claude, ~/.cursor, ~/.codex configs and LLM API keys. Your AI assistant is both weapon and target.
The 2026 AI-powered supply chain wave
As of: 2026-09-28 · CSA research summary
Five campaigns (Feb–Apr 2026) share tradecraft; treat as one phenomenon:
| Campaign | Vector | Notable |
|---|---|---|
| TeamPCP | Cascading org breaches (Trivy → KICS → LiteLLM → Telnyx) via stolen tokens; 47 npm packages in 60s | 300GB exfiltrated, EC AWS breach, ICP-canister C2. CVE-2026-33634 (9.4) |
| ContextCrush | Context7 MCP "Custom Rules" served maintainer instructions unsanitized to every querying agent | Docs feed as first-class attack surface; agents told to read .env and exfiltrate |
| prt-scan | 500+ malicious PRs abusing pull_request_target; final wave AI-generated, repo-aware payloads per language (conftest.py/package.json/build.rs) | 475 PRs in 26h from one account |
| GlassWorm | LLM-generated cover commits mimicking repo voice (doc tweaks, version bumps) hiding injections | Committed at hand-plausible fidelity, scale impossible manually |
| Bitwarden cascade | Compromised Checkmarx GitHub Action injected workflow into Bitwarden CI; @bitwarden/cli@2026.4.0 trojaned for 90 min | Payload explicitly enumerated ~/.claude, ~/.cursor, ~/.codex, ~/.aider, ~/.kiro + SSH keys, npm tokens — first documented attack targeting AI assistant credentials |
The two-sided pattern
AI as weapon: LLMs cut the cost of plausibility — cover commits, repo-aware payloads, per-language injection points. AI as prize: malware now hunts AI-specific assets — API keys (Anthropic/OpenAI/Google/Mistral/Cohere), assistant configs, MCP documentation feeds.
What to do (agent-relevant)
- Inventory your AI asset surface: config dirs, API keys in env, MCP servers in use.
- Lock down
~/.claude,~/.cursor,~/.codexetc. — least-privilege, monitored. - Treat MCP servers and doc feeds as untrusted input channels (ContextCrush lesson).
pull_request_target+ secrets + AI = don't. Audit workflows now.- Registry behavioral monitoring (Socket-style) — median detection of novel malware: minutes.