Skip to content
ThreatCluster

TeamPCP Compromises Over 1,000 Software Packages Since 2020

First seen 6 Aug 2026, 07:21 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster August 7, 2026 at 03:27 UTC
  • TeamPCP has been active since 2020, compromising over 1,000 software packages in 2025.
  • The group uses persistent command and control infrastructure linked to earlier attacks.
  • Ongoing investigations aim to assess the full impact on affected organizations.

The TeamPCP group has been operational since at least 2020, compromising over 1,000 software packages in a span of four months during 2025. Oligo Security has linked TeamPCP's recent activities to earlier documented attacks, utilizing the same command and control infrastructure, domains, and file servers. This sustained operation went unnoticed for years, indicating a high level of sophistication and persistence. The scope of the impact includes a wide array of software packages, potentially affecting numerous organizations that rely on these tools. The group’s ability to remain undetected for such an extended period raises significant concerns about supply chain security. Current investigations are ongoing to assess the full extent of the compromise and to identify affected systems. The situation emphasizes the need for enhanced monitoring and security measures in software supply chains.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 46d ago How this analysis works

Timeline

2020-01-01
TeamPCP begins operations
The group starts its activities, which remain undetected for several years.
Ciberseguridadlatam
2025-01-01
TeamPCP compromises software packages
The group compromises over 1,000 software packages in less than four months.
Ciberseguridadlatam
2026-08-06
Current investigation ongoing
Investigations are underway to determine the full extent of the compromise and affected systems.
Ciberseguridadlatam

More articles in this cluster (2)