# TeamPCP Malware Injection into Microsoft-Linked GitHub Repositories (42+ repos, 236 branches, 2026-06-05)

> On June 5, 2026, threat actor TeamPCP leveraged a compromised GitHub account to inject malicious code into 42+ repositories and 236 branches across Microsoft, Azure, and Azure-Samples GitHub organizations. Attack occurred 02:36-03:22 UTC via direct code injection (trojanized packages), establishing a high-impact supply chain compromise vector affecting enterprise SDK consumers.

- **Published:** 2026-06-28T00:00:00Z
- **Last reviewed:** 2026-06-28T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-0981
- **ID:** TL-2026-0981
- **Severity:** CRITICAL
- **Category:** MALWARE
- **Status:** ACTIVE
- **Actor:** TeamPCP
- **Detections:** 9 · **IOCs:** 30 (full data via the Threadlinqs MCP server — Purple tier)

## Description

TeamPCP conducted a sophisticated supply chain attack against Microsoft's public GitHub repositories, demonstrating advanced capability to maintain persistent access to high-value target accounts. The attack was executed through a single compromised GitHub account with write access across multiple Microsoft-controlled organizations (Azure, Azure-Samples, Microsoft).

Attack Chain & Analysis:
1. INITIAL ACCESS: Compromised GitHub account with elevated privileges in Microsoft organizations (likely phishing, credential theft, or session hijacking)
2. EXPLOITATION VECTOR: Direct repository code injection via git commits to 42+ repositories across multiple organizations
3. PAYLOAD DELIVERY: Malicious code embedded in source code across 236 branches, creating persistent trojanized packages
4. SCOPE: Attack affected high-profile repositories including Azure SDK libraries, Azure sample projects, and Microsoft-owned technology repositories
5. DETECTION: First observed during code review/monitoring on June 5, 2026; attack likely designed for downstream dependency chain execution

Key Characteristics:
- Breadth: 42+ repositories represents significant organizational compromise scope
- Depth: 236 branches affected indicates multiple active development branches and release channels were compromised
- Sophistication: Ability to maintain access across multiple GitHub organizations suggests organizational account compromise at management/admin level
- Stealth: Attack window (02:36-03:22 UTC) suggests timing for minimal detection (off-hours deployment)
- Impact: Supply chain poisoning threatens downstream consumers of Azure SDK libraries and sample code

Attack Infrastructure:
- Primary access point: Compromised GitHub account with organization-level permissions
- Attack surface: GitHub.com cloud platform (no on-premises infrastructure required)
- Persistence mechanism: Code commits embedded directly in repositories (difficult to detect without commit review)

Post-Compromise Objectives:
- Distribute malicious code through major SDK libraries to enterprise consumers
- Establish secondary access points through dependency chain compromise
- Enable downstream exploitation of systems consuming affected libraries

This attack demonstrates TeamPCP's capability to compromise high-value SaaS accounts and leverage them for supply chain operations affecting Fortune 500 customers and developers globally.

## MITRE ATT&CK

- T1566 Phishing
- T1078 Valid Accounts
- T1195 Supply Chain Compromise
- T1098 Account Manipulation
- T1136 Create Account
- T1556 Modify Authentication Process
- T1036 Masquerading
- T1070 Indicator Removal
- T1684.001 Impersonation
- T1027 Obfuscated Files or Information
- T1110 Brute Force
- T1566 Phishing
- T1552 Unsecured Credentials
- T1550 Use Alternate Authentication Material
- T1021 Remote Services
- T1548 Abuse Elevation Control Mechanism
- T1059 Command and Scripting Interpreter
- T1072 Software Deployment Tools
- T1113 Screen Capture
- T1005 Data from Local System
- T1105 Ingress Tool Transfer
- T1572 Protocol Tunneling
- T1041 Exfiltration Over C2 Channel
- T1195 Supply Chain Compromise
- T1561 Disk Wipe
- T1491 Defacement
- T1583 Acquire Infrastructure
- T1587 Develop Capabilities
- T1594 Search Victim-Owned Websites
- T1598 Phishing for Information
- T1589 Gather Victim Identity Information

## Sources

- [TeamPCP adds malware to multiple Microsoft-linked GitHub projects](https://threats.wiz.io/all-incidents/teampcp-adds-malware-to-multiple-microsoft-linked-github-projects)
- [GitHub Security: Preventing account takeover and unauthorized repository access](https://docs.github.com/en/code-security/security-advisories)
- [MITRE ATT&CK: Compromise Software Supply Chain (T1195.002)](https://attack.mitre.org/techniques/T1195/002/)
- [Microsoft Security Response Center - GitHub Account Compromise](https://msrc.microsoft.com/)
- [CISA: Software Supply Chain Attacks and Mitigations](https://www.cisa.gov/resources/tools-and-services/software-bill-materials-sbom)
- [GitHub: Securing code with branch protection rules](https://docs.github.com/en/repositories/configuring-branches-and-merges-in-your-repository/managing-protected-branches)
- [Supply Chain Attack Framework and Detection](https://attack.mitre.org/techniques/T1195/)
- [Azure Security Best Practices for Repository Access Control](https://docs.microsoft.com/en-us/azure/devops/)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-0981
