TeamPCP’s attack spree slows, but threat escalates with ransomware pivot
ID: 99c24bf1-d34d-512b-9442-c34874ddac1f
STIX ID: report--99c24bf1-d34d-512b-9442-c34874ddac1f
Feed Name: Help Net Security
TeamPCP conducted a rapid, automated supply-chain campaign in March 2026 that compromised multiple vendor ecosystems (security scanners, AI tooling, and telecommunications SDKs), deployed novel malware (including a self-propagating CanisterWorm and destructive, geo‑targeted payloads), and harvested an estimated 300 GB of credentials; the actor has shifted to monetization via a partnership with the Vect RaaS group, which has already executed at least one confirmed ransomware deployment using TeamPCP-sourced credentials. The campaign affected hundreds of public CI/CD repositories and thousands of PyPI packages, used advanced TTPs (WAV steganography, .pth auto-execution, GitHub Releases API exfiltration), and prompted package registries to quarantine malicious releases.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
