logo

TeamPCP’s attack spree slows, but threat escalates with ransomware pivot

ID: 99c24bf1-d34d-512b-9442-c34874ddac1f

STIX ID: report--99c24bf1-d34d-512b-9442-c34874ddac1f

Feed Name: Help Net Security

Threat Score
85/100

Date Published: 2026-03-30

Date Updated: 2026-04-28

Author: Zeljka Zorz

...
...

TeamPCP conducted a rapid, automated supply-chain campaign in March 2026 that compromised multiple vendor ecosystems (security scanners, AI tooling, and telecommunications SDKs), deployed novel malware (including a self-propagating CanisterWorm and destructive, geo‑targeted payloads), and harvested an estimated 300 GB of credentials; the actor has shifted to monetization via a partnership with the Vect RaaS group, which has already executed at least one confirmed ransomware deployment using TeamPCP-sourced credentials. The campaign affected hundreds of public CI/CD repositories and thousands of PyPI packages, used advanced TTPs (WAV steganography, .pth auto-execution, GitHub Releases API exfiltration), and prompted package registries to quarantine malicious releases.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.