Uncovering TeamPCP's Extended History
TeamPCP, the threat actor responsible for a surge of attacks on open-source software, has been active for a longer period than initially thought. Research by Oligo Security, shared exclusively with CyberScoop, reveals that TeamPCP's activities date back to 2020.
The threat actor gained notoriety for compromising and injecting malicious code into over 1,000 software packages in less than four months. Oligo Security's research team discovered multiple attacks bearing the markings of TeamPCP, including a late 2025 campaign involving the exploitation of a ShadowRay vulnerability.
Exploiting AI Infrastructure
The ShadowRay 2.0 campaign resulted in the first self-propagating botnet running on hijacked AI infrastructure. Evidence from this investigation was linked to historical attacks originating from the same IPs, domains, and infrastructure used by TeamPCP in earlier attacks.
“The scariest thing in this campaign is the speed at which the payloads evolved and changed and adapted to the environment they run in. We saw changes in the speed that we’re not used to seeing in these kinds of attacks. They’re usually slow, careful,” said Uri Katz, director of research at Oligo Security.
Katz attributed the rapid evolution of payloads to the use of AI, stating, “This was clearly with the help of AI — the payloads changed rapidly to adjust and change to the environment that they were trying to attack.”
Uncovering TeamPCP's Identity
Oligo Security identified a domain in July 2025 that was linked to TeamPCP's official GitHub account. Avi Lumelsky, AI security researcher at Oligo Security, noted, “It’s public, they’re not even trying to hide their identity.”
From this discovery, Oligo linked TeamPCP to activity tracked under multiple names, including TA-NATALSTATUS and IronErn, spanning from 2020 to late 2025. Much of this activity was traced to the same IPs, domain names, file server, and command-and-control server.
TeamPCP's Growth and Tactics
TeamPCP emerged publicly as a brand in late 2025 and soon began conducting broader, noisier campaigns. Gal Elbaz, co-founder and CTO at Oligo Security, attributed this growth to the widespread adoption of AI and TeamPCP's effective use of the technology.
“The ability to control the infrastructure and orchestrate the attack with AI was also super new, and I’m sure it helps them,” Elbaz said. He warned that companies' rush to adopt AI without proper visibility into its behavior creates an environment conducive to attacks.
Capitalizing on Security Gaps
TeamPCP's recent attacks have exploited new security gaps created by developers' increasing reliance on AI and automated systems. The threat actor has consistently targeted open-source frameworks and software packages, which are often used in these systems.
Lumelsky noted, “Most AI infrastructure is open source by design because nobody has the manpower and money to develop everything from scratch.” However, he emphasized that the responsibility for using these tools securely falls on the user, and developers are not accustomed to the new challenges posed by AI-powered attacks.
As Oligo Security continues to uncover TeamPCP's operational history, the company has gained more confidence in understanding the threat actor's tactics. However, this also means that TeamPCP may have been involved in other attacks that have not been attributed to them or remain undetected.
“There’s a lot more out there that we haven’t caught or been able to prove up until now,” Elbaz said.
Source: CyberScoop