security1 distinct publisher
A misconfigured GitHub Actions workflow handed TeamPCP the token that poisoned five ecosystems
Two alleged TeamPCP operators are in custody, and Flare's account of the March 2026 chain puts the root cause inside Aqua Security's Trivy build workflow, where a leaked service-account token survived an incomplete rotation.
Publishers:flare.io
Reality
- Evidence38
- Adoption55
- Hype gap+24
- Incentives76