ThreatCluster

TeamPCP Compromises Over 1,000 Software Packages Since 2020

First seen 6 Aug 2026, 07:21 UTC Ciberseguridadlatam 83% similarity 67

Article Content

Browse articles
ThreatCluster

The TeamPCP group has been operational since at least 2020, compromising over 1,000 software packages in a span of four months during 2025. Oligo Security has linked TeamPCP's recent activities to earlier documented attacks, utilizing the same command and control infrastructure, domains, and file servers. This sustained operation went unnoticed for years, indicating a high level of sophistication and persistence. The scope of the impact includes a wide array of software packages, potentially affecting numerous organizations that rely on these tools. The group’s ability to remain undetected for such an extended period raises significant concerns about supply chain security. Current investigations are ongoing to assess the full extent of the compromise and to identify affected systems. The situation emphasizes the need for enhanced monitoring and security measures in software supply chains.

Key Points: • TeamPCP has been active since 2020, compromising over 1,000 software packages in 2025. • The group uses persistent command and control infrastructure linked to earlier attacks. • Ongoing investigations aim to assess the full impact on affected organizations.

ThreatCluster AI How this analysis works

Timeline

2020-01-01
TeamPCP begins operations
The group starts its activities, which remain undetected for several years.
Ciberseguridadlatam
2025-01-01
TeamPCP compromises software packages
The group compromises over 1,000 software packages in less than four months.
Ciberseguridadlatam
2026-08-06
Current investigation ongoing
Investigations are underway to determine the full extent of the compromise and affected systems.
Ciberseguridadlatam

Community

Browse all →