A reported supply-chain compromise tied to TeamPCP shows how stolen CI/CD credentials can turn trusted automation into a long-lived security risk.