Open-source software’s archenemy TeamPCP goes back further than anyone thought
ID: a591129e-fc71-55e9-95d1-24f0dc32482a
STIX ID: report--a591129e-fc71-55e9-95d1-24f0dc32482a
Feed Name: CyberScoop
TeamPCP is a long-running and highly active threat actor tied to widespread supply-chain attacks against open-source software spanning 2020–2025; researchers attribute over 1,000 compromised packages earlier in the year and a late-2025 ShadowRay exploitation that produced the first self-propagating botnet on hijacked AI infrastructure. Oligo Security linked multiple campaigns and aliases to the same IPs, domains and C2 infrastructure and observed rapid, AI-assisted payload evolution and adaptation, increasing the scale and speed of their operations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
