TeamPCP allegedly conducted a large-scale software supply-chain compromise campaign, tampering with hundreds of open-source packages, stealing developer accounts, and breaching more than 1,000 organizations. The operation deployed the self-propagating Shai-Hulud worm to automate repository compromise and propagation. Google threat intelligence reportedly placed an undercover analyst inside the group, while Australian authorities arrested and charged two suspected members in August 2026.
A Mandiant investigation separately found an attacker hijacked an active AI coding-assistant session at a SaaS provider, used a malicious recommended package to install an infostealer, and stole GitHub OAuth tokens, repository secrets, and source code. The attacker spread Shai-Hulud through about 100 internal repositories, poisoned a package in the provider's official namespace, and infected another employee who pulled the compromised release. Open-source reporting also links TeamPCP-related aliases, including CipherForce and PCPcat, through shared underground infrastructure and contact identifiers, though those links do not establish the operators' real-world identities or definitively attribute every claimed intrusion to TeamPCP.

Trace attribution and downstream blast radius.
12 events from the most recent confirmed update back to the earliest known activity.
Mandiant reported an intrusion at an unnamed SaaS provider in which an attacker hijacked a developer's active AI coding-assistant session, installed an infostealer via a poisoned PyPI package, and stole GitHub OAuth tokens, repository secrets, and product source code. The attacker spread the self-propagating Shai-Hulud worm to roughly 100 internal repositories and infected a second employee through a poisoned official-namespace package.
Third-party messages in the Data Hoarder Telegram channel claimed that BreachForums owners, including T-PCP, had been arrested and that the forum would become a honeypot. The report did not independently verify either claim.
A Telegram account identified as T-PCP, using TeamPCP-style naming and a black-cat avatar also seen on associated accounts, had a recorded profile-creation date of August 8, 2026.
A historical snapshot showed that a Tor site previously indexed as CipherForce was branded as TeamPCP, providing infrastructure-based evidence of a later TeamPCP rebrand.
Australian authorities arrested and charged two alleged TeamPCP members. The available source specifies only that the action occurred in August 2026.
A June snapshot of Breached showed the TeamPCP account holding co-owner and staff-member roles.
A TeamPCP account announced that it had become a co-owner of the Breached forum and claimed responsibility for functions including infrastructure reliability, staff management, escrow, partnerships, and database/tool verification.
CipherForce posted a "BMW Group Internal Documents/Recon" listing marked for sale, describing purported German automotive-sector data and using an offer-based price and underground-forum contact methods.
A Telegram post attributed to PCPcat alleged exploitation of Next.js and React environments affecting more than 59,000 servers. The report treats this as activity associated with the wider identity set later linked to TeamPCP, not definitive attribution to TeamPCP itself.
Google's threat-intelligence group reportedly embedded an undercover analyst within TeamPCP's inner circle.
TeamPCP allegedly tainted hundreds of open-source programs with malware, stole developer accounts, and released a Dune-themed self-propagating worm to automate supply-chain compromises. The campaign reportedly breached more than 1,000 companies.
A TeamPCP account presenting itself as a Breached co-owner offered approximately 4,000 private GitHub repositories and internal organizations for sale, with a $50,000 minimum offer and a stated current offer of $95,000. A Telegram message promoting the sale reused Session and TOX identifiers associated with the TeamPCP/CipherForce cluster.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See attribution and downstream blast radius, and whether this package or vendor reaches your builds.
3 references tracked. Mallory keeps watching after this page renders.
wired.com
Open sourcestealthmole-intelligence-hub.blogspot.com
Open sourcethehackernews.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.