Researchers have linked TeamPCP to a broader criminal operation spanning AI infrastructure hijacking and open-source software supply-chain compromise. Oligo Security said infrastructure overlaps tied TeamPCP to aliases including IronErn and TA-NATALSTATUS, and connected the group to the ShadowRay 2.0 campaign, which abused Ray’s exposed Jobs API behavior tracked as CVE-2023-48022 to achieve remote code execution on internet-facing Ray clusters. The campaign turned compromised AI systems into a self-propagating botnet used for CPU and GPU cryptomining, including targeting NVIDIA A100 resources, while also enabling reverse shells, persistence, data theft, and DDoS activity.
Separate threat intelligence reporting said TeamPCP evolved from cloud intrusions and XMRig-based Monero mining into a credential-theft-led supply-chain operation that allegedly compromised projects and distribution channels including Trivy, Checkmarx KICS, LiteLLM, the Telnyx Python SDK, Bitwarden CLI, Xinference, and elementary-data, and was also linked to an AWS breach affecting the European Commission. ThreatMon said the group’s March-April 2026 activity affected more than 1,000 SaaS environments, exposed roughly 500,000 credentials, and led to more than 300 GB of data theft, while newer reporting suggests the actor has likely been active since 2020 and has accelerated its operations by exploiting AI adoption, automation, and trust in open-source ecosystems.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
25 events from the most recent confirmed update back to the earliest known activity.
ThreatMon Research Team published a threat intelligence report in July 2026 describing TeamPCP's evolution from cloud intrusions and cryptomining into a major open-source software supply-chain threat actor.
ThreatMon reported that TeamPCP injected a script into elementary-data through a pull request comment that exploited unsanitized interpolation in GitHub Actions.
ThreatMon said TeamPCP hijacked the Bitwarden CLI package @bitwarden/cli using npm tokens stolen during the earlier KICS compromise.
ThreatMon reported a multichannel campaign targeting Xinference and Checkmarx KICS via Docker Hub, OpenVSX, and GitHub Actions.
ThreatMon said the ransomware group Vect began publishing victims using data stolen by TeamPCP, reflecting TeamPCP's monetization of stolen access through ransomware ecosystems.
ThreatMon reported an AWS breach affecting the European Commission over 2-3 April 2026 as part of TeamPCP-linked activity.
ThreatMon reported that TeamPCP compromised the Telnyx Python SDK, using steganographic payload delivery against a package with roughly 742,000 monthly downloads.
ThreatMon said TeamPCP compromised LiteLLM through PyPI versions 1.82.7 and 1.82.8. The package reportedly had about 95 million downloads per month at the time.
ThreatMon reported that TeamPCP compromised Checkmarx KICS across GitHub Actions, Docker Hub, and OpenVSX, using the JavaScript stealer mcpAdEdonx.js executed via the Bun runtime.
ThreatMon said TeamPCP deployed the CanisterWorm worm around 20 March 2026 using stolen npm tokens. The worm reportedly used an Internet Computer Protocol canister as decentralized command-and-control infrastructure.
ThreatMon reported that TeamPCP compromised Trivy via a malicious v0.69.4 tag tied to CVE-2026-33634, with the tainted release propagating across GitHub Releases, Docker Hub, AWS ECR, and GitHub Container Registry within about four hours.
Oligo reported that new TeamPCP kube.py variants observed in March 2026 added destructive functionality. The malware deployed the Kamikaze wiper on Kubernetes clusters configured for the Iran timezone, used CanisterWorm on non-Iran Kubernetes nodes, and ran a poison_pill routine to erase non-Kubernetes Iranian systems.
GitHub blocked an account and repository used in the ShadowRay 2.0 campaign after Oligo reported the activity, but the attackers created a new account the same day and continued operating.
The operators behind ShadowRay 2.0 moved their campaign infrastructure to GitHub to continue operations after the GitLab takedown.
After Oligo reported the malicious activity, GitLab removed the attacker account and repository used for payload hosting and updates in the ShadowRay 2.0 campaign.
Oligo reported renewed exploitation activity targeting internet-exposed Ray clusters in early November 2025, describing an active global campaign later dubbed ShadowRay 2.0.
Oligo identified a domain in July 2025 that appeared in the profile of TeamPCP’s official GitHub account, which researchers said helped connect the actor to broader activity.
ThreatMon's July 2026 report states that TeamPCP emerged in late 2025 as a cybercriminal group that initially exploited exposed cloud infrastructure and deployed XMRig for Monero mining before pivoting to supply-chain compromise.
Oligo assessed that TeamPCP emerged publicly as a brand in late 2025 and then began conducting broader, noisier campaigns while becoming more active on social media and claiming victims.
Oligo reported evidence suggesting the operation later described as ShadowRay 2.0 may have been active since September 2024. The campaign abused exposed Ray infrastructure for malicious job execution and propagation.
Oligo published research on the ShadowRay campaign, documenting exploitation of internet-exposed Ray clusters via the unauthenticated Jobs API behavior tracked as CVE-2023-48022.
Oligo previously observed exploitation of the Ray issue tracked as CVE-2023-48022 in late 2023, preceding its later ShadowRay reporting. MITRE tracks the earlier activity as the ShadowRay campaign.
Oligo Security assessed that TeamPCP has likely been active since 2020, linking later operations to earlier attacks through shared IP addresses, domains, a file server, and a command-and-control server. The activity was also connected to aliases including TA-NATALSTATUS and IronErn.
CyberScoop reported Oligo Security's assessment that TeamPCP's history extends back to 2020 and that the actor was linked to the late-2025 ShadowRay campaign through shared infrastructure and aliases.
Oligo Security published research on ShadowRay 2.0, describing an active global campaign exploiting internet-exposed Ray clusters to build a self-propagating botnet used for cryptomining, persistence, reverse shells, data theft, and DDoS.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
thehackernews.com
Open sourcecyberscoop.com
Open sourcecyberveille.ch
Open sourceoligo.security
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.