Threat reportMalwareTL-2026-0981

TeamPCP Malware Injection into Microsoft-Linked GitHub Repositories (42+ repos, 236 branches, 2026-06-05)

criticalACTIVE

TeamPCP Malware Injection into Microsoft-Linked GitHub (TL-2026-0981), also tracked as GitHub Supply Chain Attack - Microsoft Repositories, is a critical-severity malware campaign, first published 2026-06-28. It is attributed to TeamPCP with high confidence, affects Microsoft Azure SDK for .NET, maps to 29 MITRE ATT&CK techniques (T1005, T1021, T1027), and is covered by 9 detection rules and 30 indicators of compromise.

Severity
CRITICALAssessed severity
CVEs
0None referenced
Techniques
29MITRE ATT&CK
Actors
1TeamPCP
Detection rules
9SPL · KQL · Sigma
IOCs
30Indicators of compromise

Key facts for TL-2026-0981

Threat ID
TL-2026-0981
Also known as
GitHub Supply Chain Attack - Microsoft Repositories, Azure SDK Malware Injection Campaign
Severity
CRITICAL
Status
ACTIVE
Category
MALWARE
First published
Last reviewed
Attribution
TeamPCP
Attribution confidence
HIGH
Motivation
ESPIONAGE
Target sectors
software development, cloud computing, enterprise technology, financial services, health, government administration, manufacturing, telecoms
Target regions
North America, Europe, Asia-Pacific, Global (via SDK distribution)
Detection rules
9
Indicators of compromise
30

Malware and tooling in TeamPCP Malware Injection into Microsoft-Linked GitHub

Malware and tooling: TeamPCP, TeamPCP-SDK-Trojan, Azure SDK for .NET, Azure SDK for Java, Azure SDK for JavaScript, Azure SDK for Python, GitHub-based C2

How TeamPCP Malware Injection into Microsoft-Linked GitHub works

On June 5, 2026, threat actor TeamPCP leveraged a compromised GitHub account to inject malicious code into 42+ repositories and 236 branches across Microsoft, Azure, and Azure-Samples GitHub organizations. Attack occurred 02:36-03:22 UTC via direct code injection (trojanized packages), establishing a high-impact supply chain compromise vector affecting enterprise SDK consumers.

TeamPCP conducted a sophisticated supply chain attack against Microsoft's public GitHub repositories, demonstrating advanced capability to maintain persistent access to high-value target accounts. The attack was executed through a single compromised GitHub account with write access across multiple Microsoft-controlled organizations (Azure, Azure-Samples, Microsoft).

Attack Chain & Analysis: 1. INITIAL ACCESS: Compromised GitHub account with elevated privileges in Microsoft organizations (likely phishing, credential theft, or session hijacking) 2. EXPLOITATION VECTOR: Direct repository code injection via git commits to 42+ repositories across multiple organizations 3. PAYLOAD DELIVERY: Malicious code embedded in source code across 236 branches, creating persistent trojanized packages 4. SCOPE: Attack affected high-profile repositories including Azure SDK libraries, Azure sample projects, and Microsoft-owned technology repositories 5. DETECTION: First observed during code review/monitoring on June 5, 2026; attack likely designed for downstream dependency chain execution

Key Characteristics: - Breadth: 42+ repositories represents significant organizational compromise scope - Depth: 236 branches affected indicates multiple active development branches and release channels were compromised - Sophistication: Ability to maintain access across multiple GitHub organizations suggests organizational account compromise at management/admin level - Stealth: Attack window (02:36-03:22 UTC) suggests timing for minimal detection (off-hours deployment) - Impact: Supply chain poisoning threatens downstream consumers of Azure SDK libraries and sample code

Attack Infrastructure: - Primary access point: Compromised GitHub account with organization-level permissions - Attack surface: GitHub.com cloud platform (no on-premises infrastructure required) - Persistence mechanism: Code commits embedded directly in repositories (difficult to detect without commit review)

Post-Compromise Objectives: - Distribute malicious code through major SDK libraries to enterprise consumers - Establish secondary access points through dependency chain compromise - Enable downstream exploitation of systems consuming affected libraries

This attack demonstrates TeamPCP's capability to compromise high-value SaaS accounts and leverage them for supply chain operations affecting Fortune 500 customers and developers globally.

MITRE ATT&CK techniques used in TL-2026-0981

Collection

T1005 Data from Local System; T1113 Screen Capture

Lateral Movement

T1021 Remote Services; T1550 Use Alternate Authentication Material

Defense Evasion

T1027 Obfuscated Files or Information; T1036 Masquerading; T1070 Indicator Removal

Exfiltration

T1041 Exfiltration Over C2 Channel

Execution

T1059 Command and Scripting Interpreter; T1072 Software Deployment Tools

Initial Access

T1078 Valid Accounts; T1195 Supply Chain Compromise; T1566 Phishing

Persistence

T1098 Account Manipulation; T1136 Create Account; T1556 Modify Authentication Process

Command and Control

T1105 Ingress Tool Transfer; T1572 Protocol Tunneling

Credential Access

T1110 Brute Force; T1552 Unsecured Credentials

initial-access

T1195 Supply Chain Compromise; T1566 Phishing

Impact

T1491 Defacement; T1561 Disk Wipe

privilege-escalation

T1548 Abuse Elevation Control Mechanism

Resource Development

T1583 Acquire Infrastructure; T1587 Develop Capabilities

Reconnaissance

T1589 Gather Victim Identity Information; T1594 Search Victim-Owned Websites; T1598 Phishing for Information

stealth

T1684.001 Impersonation

Affected products and versions in TeamPCP Malware Injection into Microsoft-Linked GitHub

  • Microsoft — Azure SDK for .NET
    Vulnerable versions: All versions from packages published 2026-06-05 02:36-03:22 UTC
    Fixed in: Patched versions post-incident
  • Microsoft — Azure SDK for Python
    Vulnerable versions: All versions from packages published 2026-06-05 02:36-03:22 UTC
    Fixed in: Patched versions post-incident
  • Microsoft — Azure SDK for JavaScript
    Vulnerable versions: All versions from packages published 2026-06-05 02:36-03:22 UTC
    Fixed in: Patched versions post-incident
  • Microsoft — Azure SDK for Java
    Vulnerable versions: All versions from packages published 2026-06-05 02:36-03:22 UTC
    Fixed in: Patched versions post-incident
  • Microsoft — Azure Samples
    Vulnerable versions: All sample projects with commits from 2026-06-05 02:36-03:22 UTC
    Fixed in: Reverted/patched versions
  • Microsoft — GitHub Enterprise
    Vulnerable versions: On-premises instances using affected Azure repos
    Fixed in: N/A - depends on remediation of source repos

Remediation for TeamPCP Malware Injection into Microsoft-Linked GitHub

Patches

  • Revert all commits from compromised account
  • Release patched versions of affected Azure SDK libraries
  • Publish security advisories for all affected repositories
  • Coordinate with NuGet, npm, and other package managers for removal of trojanized versions

Immediate actions

  • Revoke compromised GitHub account access across all Microsoft organizations immediately
  • Audit all commits from compromised account between 2026-06-04 and 2026-06-05 for malicious code
  • Quarantine affected branches and commits from 02:36-03:22 UTC on 2026-06-05
  • Review git logs and audit trails for account access patterns and unusual activities
  • Notify all downstream consumers of affected Azure SDK versions
  • Implement emergency code review and scanning of all 42+ affected repositories
  • Rotate authentication tokens and API keys for GitHub account
  • Enable MFA enforcement and review GitHub organization security settings

Workarounds

  • Pin dependency versions to commits before 2026-06-05 02:36 UTC
  • Implement runtime code verification and sandboxing
  • Use alternative SDK versions or vendors during incident response
  • Monitor for network indicators of compromise from trojanized code execution

Longer-term hardening

  • Implement mandatory code signing for all repository commits
  • Deploy binary authorization and software supply chain verification
  • Establish SBOM (Software Bill of Materials) requirements for all releases
  • Implement hardware security keys for GitHub account access by privileged admins
  • Deploy continuous monitoring and anomaly detection for repository activity
  • Establish repository access controls with principle of least privilege
  • Implement branch protection rules with required peer review for all Microsoft organizations
  • Deploy OSS-to-Enterprise (O2E) threat intelligence integration for upstream vulnerability tracking
  • Establish Supply Chain Levels for Software Artifacts (SLSA) compliance
  • Create automated scanning for malicious code patterns in commits

Weaknesses (CWE) in TeamPCP Malware Injection into Microsoft-Linked GitHub

CWE-434, CWE-427, CWE-662, CWE-501

Timeline of TeamPCP Malware Injection into Microsoft-Linked GitHub

  • Likely date of GitHub account compromise; threat actor gains access to Azure, Azure-Samples, and Microsoft GitHub organizations
  • Microsoft Security Response Center and GitHub Security team initiate public disclosure and notification to affected users
  • Wiz Threat Intelligence publishes incident report: 'TeamPCP adds malware to multiple Microsoft-linked GitHub projects'
  • Attack detected by Microsoft security team and Wiz threat intelligence analysts
  • 03:22 UTC: Last malicious commit detected; attack window closes
  • 02:36-03:22 UTC: Threat actor TeamPCP injects malicious code into 42+ repositories across 236 branches (46-minute window)
  • 02:36 UTC: First malicious commit injected into Microsoft-linked GitHub repositories by compromised account
  • GitHub revokes compromised account access; Microsoft rotates affected credentials and begins repository audits
  • Microsoft releases patched versions of affected Azure SDK libraries and sample repositories
  • Comprehensive threat intelligence analysis complete; attribution to TeamPCP confirmed with HIGH confidence
  • Wiz report updated; incident status changed to 'Finalized' and marked as contained

Sources cited for TeamPCP Malware Injection into Microsoft-Linked GitHub

Detection coverage for TL-2026-0981

As of 2026-06-28, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0981 across Splunk SPL, Microsoft KQL and Sigma, covering 30 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
30 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats