Related Threat Clusters
-
Mini Shai-Hulud Supply Chain Attack Targets SAP npm Packages
A new supply chain attack, dubbed 'Mini Shai-Hulud', has compromised multiple npm packages related to SAP's Cloud Application Programming Model (CAP). This attack involves injecting malicious preinstall scripts into…
753 articles · Updated April 29, 2026 -
TeamPCP Hackers Arrested for Major Supply Chain Attacks
On August 26, 2026, Australian Federal Police arrested two men, Ruben Thomson and Louis Gaebler, linked to the TeamPCP hacking group. This group is notorious for sophisticated supply chain attacks that compromised over…
26 articles · Updated August 27, 2026 -
GitHub Breach: 3,800 Internal Repositories Compromised via Malicious VS Code Extension
On May 20, 2026, GitHub confirmed a significant security breach involving a poisoned Visual Studio Code (VS Code) extension that compromised an employee's device. The attack, attributed to the TeamPCP hacking group,…
149 articles · Updated May 20, 2026 -
TeamPCP Exploits Trust in Open-Source Software and AI Tools
In a span of four months, the threat actor TeamPCP has compromised over 1,000 open-source software packages, injecting malicious code and exploiting the trust developers place in these resources. The attack method…
7 articles · Updated June 19, 2026
Recent Intelligence Reports
- Two alleged TeamPCP members arrested and charged after months of software supply — Cyberscoop · August 27, 2026
- How software development’s speed obsession enabled TeamPCP’s chaos crusade — Cyberscoop · June 18, 2026
- GitHub breached via poisoned VS Code extension, 3,800 repos stolen — Thenextweb · May 20, 2026
- MistralAI PyPI Package Compromised to Inject Malicious Code — Cybersecuritynews · May 12, 2026
- Microsoft Warns: MistralAI PyPI Package Compromised with Malware — Gbhackers · May 12, 2026