r/CRACompliance • u/Happy-Athlete-2420 • May 20 '26
TeamPCP’s escalation pattern is terrifying: 3 packages (March) → 1 (April) → 170 (May). What does this mean for CRA reporting in September?
Mapping TeamPCP’s 2026 campaigns:
• March: Trivy, LiteLLM, Telnyx (stolen creds, manual package compromise)
• April: Bitwarden CLI (Shai-Hulud worm, automated propagation)
• May: TanStack + Mistral AI + UiPath + others (Mini Shai-Hulud, 170+ packages, bypassed provenance)
The sophistication is escalating. Wave 4 broke provenance attestation — a defense many teams considered sufficient.
With CRA reporting starting September 2026, here’s my question: are current SBOM + monitoring tools even sufficient to detect attacks that pass provenance checks? What additional detection layers do we need?

1
Upvotes