Activity timeline
TeamPCP appears in 53 tracked threats between and ; the busiest month was 2026-03 with 13 reports.
ATT&CK techniques observed
- T1027 Obfuscated Files or Information — Stealth (formerly Defense Evasion)observed in 44 of 53 tracked threats
- T1005 Data from Local System — Collectionobserved in 41 of 53 tracked threats
- T1528 Steal Application Access Token — Credential Accessobserved in 39 of 53 tracked threats
- T1195 Supply Chain Compromise — Initial Accessobserved in 38 of 53 tracked threats
- T1041 Exfiltration Over C2 Channel — Exfiltrationobserved in 31 of 53 tracked threats
- T1036 Masquerading — Stealth (formerly Defense Evasion)observed in 30 of 53 tracked threats
- T1059 Command and Scripting Interpreter — Executionobserved in 30 of 53 tracked threats
- T1082 System Information Discovery — Discoveryobserved in 28 of 53 tracked threats
- T1552 Unsecured Credentials — Credential Accessobserved in 28 of 53 tracked threats
- T1567 Exfiltration Over Web Service — Exfiltrationobserved in 27 of 53 tracked threats
- T1552.001 Unsecured Credentials — Credential Accessobserved in 26 of 53 tracked threats
- T1105 Ingress Tool Transfer — Command and Controlobserved in 25 of 53 tracked threats
- T1199 Trusted Relationship — Initial Accessobserved in 24 of 53 tracked threats
- T1083 File and Directory Discovery — Discoveryobserved in 23 of 53 tracked threats
- T1195.002 Compromise Software Supply Chain — Initial Accessobserved in 21 of 53 tracked threats
Tracked threats
- Mini Shai-Hulud: Compromised @antv npm Packages Steal Developer and CI/CD Credentials (TeamPCP)HIGH
- Re-Enabled actions-cool GitHub Actions (issues-helper, maintain-one-comment) Resume Executing Mini Shai-Hulud CI/CD Credential-Theft PayloadHIGH
- Google Cloud Threat Intelligence: Supply Chain Compromise Campaigns and Mitigation Guidance (2025-2026)HIGH
- Open-Source Supply Chain Poisoning Campaigns Drive CrowdStrike Endpoint-Based Package InterceptionHIGH
- ChainDrop/Mini Shai-Hulud npm Worm Compromises keyv, cacheable, and 400+ Downstream Packages via Ethereum-Resolved C2CRITICAL
- npm Supply-Chain Compromise: @7nohe/openapi-react-query-codegen Ships "Trinitite" Credential-Harvesting WormCRITICAL
- Shai-Hulud npm Supply-Chain Worm: Two Alleged TeamPCP Members Charged by AFP/FBICRITICAL
- StepSecurity Dev Machine Guard adds fleet-wide developer credential inventory to close blind spot exploited by supply-chain attacks
- ChainDrop npm Supply-Chain Compromise: Self-Propagating Mini Shai-Hulud Credential-Stealing Worm Affecting 444+ PackagesCRITICAL
- Shai-Hulud NPM Worm Compromises keyv, file-entry-cache, flat-cache and Hundreds of Popular npm Packages via Maintainer Account TakeoverCRITICAL
- Keyv and Cacheable npm Supply Chain Attack via Compromised Maintainer Account (Shai-Hulud Malware)CRITICAL
- Popular npm Packages in the keyv and Cacheable Namespaces Compromised in Active Supply Chain AttackCRITICAL
- Ransomware Groups Exploit Citrix Bleed 2 (CVE-2025-5777) and Kontron Driver BYOVD for Access and Privilege EscalationCRITICAL
- TeamPCP Malware Injection into Microsoft-Linked GitHub Repositories (42+ repos, 236 branches, 2026-06-05)CRITICAL
- Miasma Supply Chain Attack Toolkit Open-Sourced on GitHub (Shai-Hulud / Mini Shai-Hulud Variant)CRITICAL
- Shai-Hulud 'Hades' Campaign — Trojanized PyPI Packages Auto-Execute Bun Credential Stealer via Python Wheel Startup Hooks (*-setup.pth)CRITICAL
- Miasma Worm Compromises 73 Microsoft GitHub Repositories Across Azure, Azure-Samples, Microsoft & MicrosoftDocs — Self-Replicating Mini Shai-Hulud Variant Weaponizing AI Coding Agents (TeamPCP)CRITICAL
- Shai-Hulud "Hades" Miasma Worm — New PyPI Wave: 37 Malicious Wheels Across 19 Packages Abuse *-setup.pth Startup Hook to Launch Bun-Powered Credential StealerCRITICAL
- Binding.gyp "Phantom Gyp" Supply Chain Attack (Miasma Worm) Enables CI/CD Worm Propagation Across 57 npm PackagesHIGH
- Miasma: Supply Chain Compromise in RedHat npm Packages - Credential Harvesting MalwareCRITICAL
- Miasma — @redhat-cloud-services npm Supply Chain Compromise (Mini Shai-Hulud Variant, GitHub Actions OIDC/SLSA Abuse with GCP/Azure Cloud-Identity Theft)CRITICAL
- durabletask PyPI Supply Chain Compromise (v1.4.1–1.4.3) — Microsoft-Published Azure Durable Functions SDK Trojanized w/ Cross-Cloud Credential Stealer + Linux Disk Wiper (TeamPCP / Mini Shai-Hulud)CRITICAL
- Nx Console VS Code Extension Backdoored (v18.95.0) — TeamPCP Mini Shai-Hulud Pivot from TanStack npm Worm to GitHub Internal Repository Breach (CVE-2026-48027)CRITICAL
- GitHub Internal Breach — TeamPCP Exfiltrates 3,800+ Repos via Poisoned VS Code Extension Tied to Mini Shai-Hulud WormCRITICAL
- TeamPCP @antv Supply Chain Wave — Mini Shai-Hulud Multi-Ecosystem npm/GitHub Actions/VSCode CompromiseCRITICAL
- Backdoored Cemu v2.6 GitHub Release — TeamPCP Supply Chain Campaign Extends to Cemu Nintendo Wii U Emulator (cemu-project/Cemu)HIGH
- Mini Shai-Hulud v3 — TanStack/UiPath/Mistral AI npm & PyPI Supply Chain Compromise (TeamPCP)CRITICAL
- GTIG AI Threat Tracker (May 2026) — First AI-Developed Zero-Day Exploit (2FA Bypass), PROMPTFLUX/HONESTCUE/CANFAIL/LONGSTREAM/PROMPTSPY AI-Enabled Malware, and APT27/APT45/UNC2814/UNC5673/UNC6201/TeamPCP AI-Augmented OperationsHIGH
- Checkmarx Jenkins AST Plugin Supply Chain Compromise — TeamPCP Backdoored Plugin on Jenkins MarketplaceHIGH
- Mini Shai-Hulud Resurfaces — intercom-client@7.0.4 npm Worm Harvesting GitHub & Cloud Credentials (TeamPCP)CRITICAL
- lightning PyPI Package Compromise — Versions 2.6.2 & 2.6.3 Execute Bun-Based JavaScript Credential Stealer on Import (Shai-Hulud-Overlapping)CRITICAL
- SAP CAP & Cloud MTA npm Packages Compromised — Mini Shai-Hulud (TeamPCP) Bun-Based Credential StealerCRITICAL
- Xinference PyPI Supply Chain Compromise — TeamPCP-Marked Credential Harvester (v2.6.0–2.6.2)CRITICAL
- VECT Ransomware 2.0 — Russian-Speaking RaaS with ChaCha20 Buffer-Reuse Bug Producing Permanent Data Destruction (Wiper-by-Accident) Across Windows, Linux, and ESXiCRITICAL
- Bitwarden CLI npm Supply Chain Compromise (@bitwarden/cli v2026.4.0) — Shai-Hulud: The Third Coming / TeamPCPCRITICAL
- Bitwarden CLI Hijacked in npm Supply Chain Attack Linked to TeamPCP & Checkmarx BreachCRITICAL
- Coordinated supply chain attacks on Checkmarx and Bitwarden developer tools sharing audit.checkmarx.cx C2 infrastructureHIGH
- Bitwarden CLI 2026.4.0 (@bitwarden/cli) Compromised via Abused GitHub Action in Ongoing Checkmarx Supply Chain CampaignCRITICAL
- Telnyx Python SDK PyPI Compromise — TeamPCP CanisterWorm Supply Chain Attack (telnyx 4.87.1/4.87.2)CRITICAL
- Escalating Kubernetes Attacks: React2Shell (CVE-2025-55182), Slow Pisces, and Cloud-Native Threat ActorsCRITICAL
- TeamPCP LiteLLM Supply Chain Attack — Trojaned PyPI Packages (v1.82.7/1.82.8) with Multi-Stage C2 PayloadCRITICAL
- TeamPCP Cascading Supply Chain Campaign: Telnyx PyPI Compromise with WAV SteganographyCRITICAL
- TeamPCP Supply Chain Attack via Backdoored Telnyx PyPI Package with Steganographic WAV PayloadsCRITICAL
- LiteLLM Supply Chain Compromise — TeamPCP Multi-Ecosystem Campaign via Trojanized PyPI PackagesCRITICAL
- TeamPCP Partners With Vect Ransomware Group to Escalate Cross-Ecosystem Open Source Supply Chain AttacksCRITICAL
- TeamPCP Supply Chain Attack on LiteLLM — Trojanized PyPI Packages with .pth Persistence and Multi-Stage Credential StealerCRITICAL
- Trivy Supply Chain Compromise — TeamPCP Credential-Stealing Malware Injected into CI/CD Pipelines (CVE-2026-33634)CRITICAL
- TeamPCP Supply Chain Campaign: LiteLLM PyPI Compromise, CanisterWorm npm Propagation, and Multi-Ecosystem Attack (CVE-2026-33634)CRITICAL
- Checkmarx KICS GitHub Action Supply Chain Compromise by TeamPCP (kics-github-action Tag Hijacking)CRITICAL
- Trivy Supply Chain Attack — Credential Theft Infostealer via Malicious GitHub Actions Tags (GHSA-69fq-xp46-6x23)CRITICAL
- Trivy Ecosystem Supply Chain Compromise — Infostealer via Hijacked GitHub Actions and Container Images (CWE-506)CRITICAL
- CanisterWorm npm Supply Chain Compromise — Worm-Enabled Backdoor Across 29+ Packages via Publisher Credential TheftHIGH
- Trivy Supply Chain Compromise by TeamPCP — Credential-Stealing Malware in v0.69.4, trivy-action, and setup-trivy GitHub ActionsCRITICAL