UnattributedUnknown

TeamPCP

TeamPCP is a financially motivated cybercriminal group active since late 2025, specialising in software supply chain attacks targeting developer tooling, open source packages, and CI/CD infrastructure. The group has conducted sustained attack campaigns against GitHub, PyPI, npm, and Docker registries, embedding credential-stealing malware into widely used open source tools including Trivy, LiteLLM, TanStack, and Checkmarx components. TeamPCP operates a worm-based propagation framework (Shai-Hulud / Mini Shai-Hulud) and has established partnerships with BreachForums and DragonForce ransomware. Victims include GitHub, OpenAI, Mistral AI, and the European Commission. Attribution remains unresolved — operators are English-speaking with no confirmed nation-state affiliation.

Attribution signal

?Score = mentions × confidence weight, summed across all attributed sources. Higher source diversity increases the score.≥ 10 High≥ 3 Moderate< 3 Low
52.9
High signal strength
Mentions85
Sources16
High conf.51
Last seenJun 2026
First observed
2025-12-01
Last active
Origin
Unknown — English-speaking, financially motivated, no confirmed nation-state affiliation
Aliases
1
Techniques
0
Campaigns
0

Attribution signals

85 mentions · 16 sources
#1attributedhigh
Unspecified
dark-reading
Jun 2026

"Some cybersecurity vendors attributed previous Mini Shai-Hulud attacks to TeamPCP, a financially motivated threat actor that formally emerged in late 2025 by exploiting the React2Shell vulnerability as well as targeting misconfigured Docker APIs and Next.js."

#2attributed tohigh
TTP matchMalware
bleepingcomputer
May 2026

"A similar capability was observed in the payload delivered in the TanStack attack attributed to TeamPCP"

Campaign: TanStack attack
#3attributed tohigh
MalwareTTP match
bleepingcomputer
May 2026

"In the ongoing Shai-Hulud malware campaign attributed to TeamPCP hackers, dozens of TanStack packages infected with credential-stealing code were published on the npm index"

Campaign: Shai-Hulud
#4confirmedhigh
InfrastructureTTP matchMalware
wechat-nsfocus-cert
May 2026

"Analysis confirmed it was supply chain poisoning on PyPI by the TeamPCP group."

#5attributehigh
Unspecified
tenable
Jun 2026

"Multiple independent security firms attribute the campaign to TeamPCP, a financially motivated cybercriminal group that emerged in late 2025."

Campaign: Mini Shai-Hulud
#6attributed tohigh
Unspecified
habr
May 2026

"This attack is attributed to the hacker group TeamPCP"

#7attributed tohigh
Malware
bleepingcomputer
May 2026

"The campaigns were attributed to the TeamPCP hacker group."

Campaign: Shai-Hulud
#8attributed tohigh
Malware
bleepingcomputer
May 2026

"the chalk-tempalte package contains a clone of the Shai-Hulud malware attributed to the TeamPCP hacker group that is reponsible for the recent Mini Shai-Hulud software supply-chain attack"

#9launchedhigh
Malware
security-affairs
May 2026

"the TeamPCP group launched a new wave of the Mini Shai-Hulud worm, compromising legitimate npm packages through hijacked GitHub Actions OIDC tokens"

Campaign: Mini Shai-Hulud worm
#10compromisedhigh
Unspecified
bleepingcomputer
May 2026

"In March, the hacker group also compromised Aqua Security's Trivy vulnerability scanner , which is believed to have led to cascading compromises affecting Aqua Security Docker images and the Checkmarx KICS project"

#11threatenedhigh
Unspecified
bleepingcomputer
May 2026

"threatened to leak the Mistral AI source code stolen using compromised CI/CD credentials"

#12abusedhigh
Unspecified
security-affairs
May 2026

"the TeamPCP hacking group abused weaknesses in the package publishing process to distribute 84 malicious packages tied to the TanStack open source development ecosystem"

Campaign: TanStack supply chain attack

Hedge terms observed

abusedaffectedallowedappearsappears to beappears to haveassessed as responsibleassesses with moderate confidenceAttackedattackersattributeattributedattributed toattributescarried outcarried out byclaimclaimedclaimed creditclaimingclaiming to becompromisecompromisedCompromisedconfirmedconsistent in directionconsistent withDeployedemergedexploitedgot compromised byhackedhad stolenhas attackedhas repeatedly exploitedhave begunisknown asknown forlaunchedleaked on GitHub bylinked tono evidenceopens the possibilityseemed toshould be treated as evidence of TTP overlap rather than definitive attributionsuggestsSupply chain poisoningsuspectedtaken creditthreatenedtied it totracked asunclearunspecifiedusedWe believe