Threat reportMalwareTL-2026-0981
TeamPCP Malware Injection into Microsoft-Linked GitHub Repositories (42+ repos, 236 branches, 2026-06-05)
TeamPCP Malware Injection into Microsoft-Linked GitHub (TL-2026-0981), also tracked as GitHub Supply Chain Attack - Microsoft Repositories, is a critical-severity malware campaign, first published 2026-06-28. It is attributed to TeamPCP with high confidence, affects Microsoft Azure SDK for .NET, maps to 29 MITRE ATT&CK techniques (T1005, T1021, T1027), and is covered by 9 detection rules and 30 indicators of compromise.
- Severity
- CRITICALAssessed severity
- CVEs
- 0None referenced
- Techniques
- 29MITRE ATT&CK
- Actors
- 1TeamPCP
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 30Indicators of compromise
Key facts for TL-2026-0981
- Threat ID
- TL-2026-0981
- Also known as
- GitHub Supply Chain Attack - Microsoft Repositories, Azure SDK Malware Injection Campaign
- Severity
- CRITICAL
- Status
- ACTIVE
- Category
- MALWARE
- First published
- Last reviewed
- Attribution
- TeamPCP
- Attribution confidence
- HIGH
- Motivation
- ESPIONAGE
- Target sectors
- software development, cloud computing, enterprise technology, financial services, health, government administration, manufacturing, telecoms
- Target regions
- North America, Europe, Asia-Pacific, Global (via SDK distribution)
- Detection rules
- 9
- Indicators of compromise
- 30
Malware and tooling in TeamPCP Malware Injection into Microsoft-Linked GitHub
Malware and tooling: TeamPCP, TeamPCP-SDK-Trojan, Azure SDK for .NET, Azure SDK for Java, Azure SDK for JavaScript, Azure SDK for Python, GitHub-based C2
How TeamPCP Malware Injection into Microsoft-Linked GitHub works
On June 5, 2026, threat actor TeamPCP leveraged a compromised GitHub account to inject malicious code into 42+ repositories and 236 branches across Microsoft, Azure, and Azure-Samples GitHub organizations. Attack occurred 02:36-03:22 UTC via direct code injection (trojanized packages), establishing a high-impact supply chain compromise vector affecting enterprise SDK consumers.
TeamPCP conducted a sophisticated supply chain attack against Microsoft's public GitHub repositories, demonstrating advanced capability to maintain persistent access to high-value target accounts. The attack was executed through a single compromised GitHub account with write access across multiple Microsoft-controlled organizations (Azure, Azure-Samples, Microsoft).
Attack Chain & Analysis: 1. INITIAL ACCESS: Compromised GitHub account with elevated privileges in Microsoft organizations (likely phishing, credential theft, or session hijacking) 2. EXPLOITATION VECTOR: Direct repository code injection via git commits to 42+ repositories across multiple organizations 3. PAYLOAD DELIVERY: Malicious code embedded in source code across 236 branches, creating persistent trojanized packages 4. SCOPE: Attack affected high-profile repositories including Azure SDK libraries, Azure sample projects, and Microsoft-owned technology repositories 5. DETECTION: First observed during code review/monitoring on June 5, 2026; attack likely designed for downstream dependency chain execution
Key Characteristics: - Breadth: 42+ repositories represents significant organizational compromise scope - Depth: 236 branches affected indicates multiple active development branches and release channels were compromised - Sophistication: Ability to maintain access across multiple GitHub organizations suggests organizational account compromise at management/admin level - Stealth: Attack window (02:36-03:22 UTC) suggests timing for minimal detection (off-hours deployment) - Impact: Supply chain poisoning threatens downstream consumers of Azure SDK libraries and sample code
Attack Infrastructure: - Primary access point: Compromised GitHub account with organization-level permissions - Attack surface: GitHub.com cloud platform (no on-premises infrastructure required) - Persistence mechanism: Code commits embedded directly in repositories (difficult to detect without commit review)
Post-Compromise Objectives: - Distribute malicious code through major SDK libraries to enterprise consumers - Establish secondary access points through dependency chain compromise - Enable downstream exploitation of systems consuming affected libraries
This attack demonstrates TeamPCP's capability to compromise high-value SaaS accounts and leverage them for supply chain operations affecting Fortune 500 customers and developers globally.
MITRE ATT&CK techniques used in TL-2026-0981
Collection
T1005 Data from Local System; T1113 Screen Capture
Lateral Movement
T1021 Remote Services; T1550 Use Alternate Authentication Material
Defense Evasion
T1027 Obfuscated Files or Information; T1036 Masquerading; T1070 Indicator Removal
Exfiltration
T1041 Exfiltration Over C2 Channel
Execution
T1059 Command and Scripting Interpreter; T1072 Software Deployment Tools
Initial Access
T1078 Valid Accounts; T1195 Supply Chain Compromise; T1566 Phishing
Persistence
T1098 Account Manipulation; T1136 Create Account; T1556 Modify Authentication Process
Command and Control
T1105 Ingress Tool Transfer; T1572 Protocol Tunneling
Credential Access
T1110 Brute Force; T1552 Unsecured Credentials
initial-access
T1195 Supply Chain Compromise; T1566 Phishing
Impact
T1491 Defacement; T1561 Disk Wipe
privilege-escalation
T1548 Abuse Elevation Control Mechanism
Resource Development
T1583 Acquire Infrastructure; T1587 Develop Capabilities
Reconnaissance
T1589 Gather Victim Identity Information; T1594 Search Victim-Owned Websites; T1598 Phishing for Information
stealth
Affected products and versions in TeamPCP Malware Injection into Microsoft-Linked GitHub
- Microsoft — Azure SDK for .NET
Vulnerable versions: All versions from packages published 2026-06-05 02:36-03:22 UTC
Fixed in: Patched versions post-incident - Microsoft — Azure SDK for Python
Vulnerable versions: All versions from packages published 2026-06-05 02:36-03:22 UTC
Fixed in: Patched versions post-incident - Microsoft — Azure SDK for JavaScript
Vulnerable versions: All versions from packages published 2026-06-05 02:36-03:22 UTC
Fixed in: Patched versions post-incident - Microsoft — Azure SDK for Java
Vulnerable versions: All versions from packages published 2026-06-05 02:36-03:22 UTC
Fixed in: Patched versions post-incident - Microsoft — Azure Samples
Vulnerable versions: All sample projects with commits from 2026-06-05 02:36-03:22 UTC
Fixed in: Reverted/patched versions - Microsoft — GitHub Enterprise
Vulnerable versions: On-premises instances using affected Azure repos
Fixed in: N/A - depends on remediation of source repos
Remediation for TeamPCP Malware Injection into Microsoft-Linked GitHub
Patches
- Revert all commits from compromised account
- Release patched versions of affected Azure SDK libraries
- Publish security advisories for all affected repositories
- Coordinate with NuGet, npm, and other package managers for removal of trojanized versions
Immediate actions
- Revoke compromised GitHub account access across all Microsoft organizations immediately
- Audit all commits from compromised account between 2026-06-04 and 2026-06-05 for malicious code
- Quarantine affected branches and commits from 02:36-03:22 UTC on 2026-06-05
- Review git logs and audit trails for account access patterns and unusual activities
- Notify all downstream consumers of affected Azure SDK versions
- Implement emergency code review and scanning of all 42+ affected repositories
- Rotate authentication tokens and API keys for GitHub account
- Enable MFA enforcement and review GitHub organization security settings
Workarounds
- Pin dependency versions to commits before 2026-06-05 02:36 UTC
- Implement runtime code verification and sandboxing
- Use alternative SDK versions or vendors during incident response
- Monitor for network indicators of compromise from trojanized code execution
Longer-term hardening
- Implement mandatory code signing for all repository commits
- Deploy binary authorization and software supply chain verification
- Establish SBOM (Software Bill of Materials) requirements for all releases
- Implement hardware security keys for GitHub account access by privileged admins
- Deploy continuous monitoring and anomaly detection for repository activity
- Establish repository access controls with principle of least privilege
- Implement branch protection rules with required peer review for all Microsoft organizations
- Deploy OSS-to-Enterprise (O2E) threat intelligence integration for upstream vulnerability tracking
- Establish Supply Chain Levels for Software Artifacts (SLSA) compliance
- Create automated scanning for malicious code patterns in commits
Weaknesses (CWE) in TeamPCP Malware Injection into Microsoft-Linked GitHub
Timeline of TeamPCP Malware Injection into Microsoft-Linked GitHub
- Likely date of GitHub account compromise; threat actor gains access to Azure, Azure-Samples, and Microsoft GitHub organizations
- Microsoft Security Response Center and GitHub Security team initiate public disclosure and notification to affected users
- Wiz Threat Intelligence publishes incident report: 'TeamPCP adds malware to multiple Microsoft-linked GitHub projects'
- Attack detected by Microsoft security team and Wiz threat intelligence analysts
- 03:22 UTC: Last malicious commit detected; attack window closes
- 02:36-03:22 UTC: Threat actor TeamPCP injects malicious code into 42+ repositories across 236 branches (46-minute window)
- 02:36 UTC: First malicious commit injected into Microsoft-linked GitHub repositories by compromised account
- GitHub revokes compromised account access; Microsoft rotates affected credentials and begins repository audits
- Microsoft releases patched versions of affected Azure SDK libraries and sample repositories
- Comprehensive threat intelligence analysis complete; attribution to TeamPCP confirmed with HIGH confidence
- Wiz report updated; incident status changed to 'Finalized' and marked as contained
Sources cited for TeamPCP Malware Injection into Microsoft-Linked GitHub
- TeamPCP adds malware to multiple Microsoft-linked GitHub projects
- GitHub Security: Preventing account takeover and unauthorized repository access
- MITRE ATT&CK: Compromise Software Supply Chain (T1195.002)
- Microsoft Security Response Center - GitHub Account Compromise
- CISA: Software Supply Chain Attacks and Mitigations
- GitHub: Securing code with branch protection rules
- Supply Chain Attack Framework and Detection
- Azure Security Best Practices for Repository Access Control
Detection coverage for TL-2026-0981
As of 2026-06-28, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0981 across Splunk SPL, Microsoft KQL and Sigma, covering 30 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.