Threats

TeamPCP's Open-Source Software Attacks

June 19, 2026 04:09 · 12 min read
TeamPCP's Open-Source Software Attacks

Introduction to TeamPCP's Attacks

TeamPCP is a threat actor that has been on a rampage through open-source software, compromising and injecting malicious code into more than 1,000 software packages in less than four months. This extraordinary spree has transformed how software developers and maintainers distribute and manage their code, as their dependencies and repositories have become one of the most effective and prevalent attack vectors this year.

Scale of the Attacks

The scale of TeamPCP's attacks lies partly in the automated systems companies use to deploy code, like CI/CD pipelines. It is also capitalizing on new security gaps created by developers' increasing reliance on AI. Yet, with relatively low effort and unoriginal tactics, TeamPCP is wrecking open-source frameworks and underlying systems at levels the technology community has rarely reckoned with.

"Developers didn’t do a great job of analyzing the security of their open-source dependencies before but, now with AI, there’s in some cases virtually no human in the loop or any kind of sanity check on what these tools are doing," Feross Aboukhadijeh, founder and CEO at Socket, told CyberScoop. "You have agents installing packages that haven’t been vetted," he said. "When an attacker gets in, the impact is even broader because there’s less checks and balances to stop it from affecting everybody."

Methodology Behind the Attacks

TeamPCP hasn't identified a new problem or proved anything novel. The crux of these attacks hinge on a central theme — defensive vulnerabilities the entire software industry has known about for years. Researchers and developers know the open source trust model is broken and susceptible to sabotage. Yet, the software industry has not fixed this problem.

"The speed and scale of these attacks is what makes it most notable, not necessarily the methodology behind it, because at the core it is really about exploiting third-party trusts that we have," said Kimberly Goody, senior manager at Google Threat Intelligence Group.

Motivation Behind TeamPCP's Attacks

TeamPCP, like any prolific cybercriminal, has captured significant attention from threat hunters since it emerged in late 2025. Google attributes the activity to one core operator. The company said it traced TeamPCP's residential and mobile IP address connections to South Africa, indicating the primary operator was located there during at least some of its attacks.

"We don’t believe that there’s an established core group, at least not yet, and that a lot of this has been conducted by an individual," Goody said. Google declined to name the core operator or confirm it knows the person’s true identity.

Victims and Exposure

TeamPCP has been remarkably noisy, opportunistically injecting malware into open-source software for the purpose of stealing credentials for Kubernetes environments, Amazon Web Services, Microsoft Azure, Google Cloud and many other connected services. The group's claimed victim list is staggering: Checkmarx, Bitwarden, LiteLLM, Telnyx, Mercor AI, PyTorch Lightning, AntV, SAP, GitHub, TanStack, UiPath, MistralAI, Microsoft DurableTask, Red Hat and Nx Console.

The full collection of packages compromised or poisoned by TeamPCP to date accounts for roughly 500 million weekly downloads combined, according to Nathaniel Quist, manager of cloud threat intelligence at Palo Alto Networks. While the breadth of potential downstream compromise flowing from those downloads is substantial, many endpoints infected with those malware-riddled packages aren’t exposed to the internet and less susceptible to attack, he added.

Defensive Gaps Create Openings for Attack

TeamPCP's attack spree has also underscored how difficult it is for organizations to revoke compromised secrets. Multiple victims have experienced recurring infections, sometimes falling prey to TeamPCP three times within a month, because they didn’t rotate secrets properly, according to Amitai Cohen, head of the attack vector intel team at Wiz.

At its core, these attacks highlight a direct trade-off organizations accept when they update software quickly to fix vulnerabilities, but learn that doing so too quickly could expose them to illegitimate registries containing malware. TeamPCP has targeted what Aboukhadijeh describes as a "public good," open-source registries that were never perfect but widely trusted and rarely turned into a point of entry for supply-chain attacks.

Conclusion

Rapid open source software installation is one of the most dangerous things an organization can do right now, according to Aboukhadijeh, adding that there’s a roughly 1 in 10 chance that any package installed by an organization could trigger an active attack. TeamPCP has compromised security scanners, password managers, automation tools, data visualization software, and CI/CD infrastructure across various environments. And it’s lifted a trove of credentials and other sensitive data from victims.

Researchers like Cohen at Wiz, who have been tracking this attack spree since the beginning, are nearing a breaking point. "This is also too hard on us. We’re very tired. I’m sure a lot of people working on this problem space are very tired, and it’s just kind of become untenable," Cohen said.


Source: CyberScoop

Source: CyberScoop

Powered by ZeroBot

Protect your website from bots, scrapers, and automated threats.

Try ZeroBot Free