#TeamPCP
As the TeamPCP cybercrime group carried out an unprecedented spree of software supply chain hacking this year, it had been infiltrated by an undercover analyst from Google's threat intel division. Google watched from inside, warned victims, even disrupted extortions. www.wired.com/story/an-und...
An Undercover Google Analyst Infiltrated a Notorious Supply Chain Hacking Gang
TeamPCP pulled off the worst-ever software supply chain hacking spree and breached thousands of companies. Now Google’s threat intelligence group has revealed it had a mole inside the hackers’ inner c...
www.wired.com
September 18, 2026 at 4:04 PM
TeamPCP SUPPLY CHAINED AXIOS
March 31, 2026 at 3:46 AM
NEW: A Google researcher snuck into the group chat of TeamPCP, the hacker gang responsible for the worst-ever supply chain hacking spree, allowing the company to disrupt the group's attacks. @agreenberg.bsky.social has the scoop: www.wired.com/story/an-und...
An Undercover Google Analyst Infiltrated a Notorious Supply Chain Hacking Gang
TeamPCP pulled off the worst-ever software supply chain hacking spree and breached thousands of companies. Now Google’s threat intelligence group has revealed it had a mole inside the hackers’ inner c...
www.wired.com
September 18, 2026 at 4:04 PM
GitHub is just the latest victim of TeamPCP, a gang that has carried out a spree of software supply chain attacks that has impacted hundreds of organizations.
A Hacker Group Is Poisoning Open Source Code at an Unprecedented Scale
GitHub is just the latest victim of TeamPCP, a gang that has carried out a spree of software supply chain attacks that has impacted hundreds of organizations.
wrd.cm
May 23, 2026 at 2:45 PM
TeamPCP pulled off the worst-ever software supply chain hacking spree and breached thousands of companies. Now Google’s threat intelligence group has revealed it had a mole inside the hackers’ inner circle. www.wired.com/story/an-und...
An Undercover Google Analyst Infiltrated a Notorious Supply Chain Hacking Gang
TeamPCP pulled off the worst-ever software supply chain hacking spree and breached thousands of companies. Now Google’s threat intelligence group has revealed it had a mole inside the hackers’ inner...
www.wired.com
September 18, 2026 at 4:02 PM
lapsus$ guys are claiming the github thing, saying they're doing a crossover with TeamPCP cyberplace.social/@GossiTheDog...
Kevin Beaumont (@GossiTheDog@cyberplace.social)
Attached: 2 images LAPSUS$ claim they are extorting Github in a Kpop supergroup crossover with TeamPCP. #GAYINT
cyberplace.social
May 20, 2026 at 3:12 PM
GitHub is just the latest victim of TeamPCP, a gang that has carried out a spree of software supply chain attacks that has impacted hundreds of organizations. www.wired.com/story/teampc...
A Hacker Group Is Poisoning Open Source Code at an Unprecedented Scale
GitHub is just the latest victim of TeamPCP, a gang that has carried out a spree of software supply chain attacks that has impacted hundreds of organizations.
www.wired.com
May 21, 2026 at 9:05 AM
NEW: An unknown group of hackers is taking over systems already compromised by the cybercrime group TeamPCP and immediately kicking the group out, according to a new report.

It’s unclear who this new group of hackers are, but one possible explanation is that they are former members of TeamPCP.
Hackers hack victims hacked by other hackers | TechCrunch
An unknown group of hackers is breaking into systems previously breached by the cybercrime group TeamPCP. Once inside, the hackers immediately kick out TeamPCP and remove its hacking tools from the vi...
techcrunch.com
May 7, 2026 at 6:29 PM
NEW: This week's GitHub breach is just the latest in a string of at least 20 software supply chain attacks carried out by the hacker group TeamPCP. @agreenberg.bsky.social and @lhn.bsky.social report: www.wired.com/story/teampc...
A Hacker Group Is Poisoning Open Source Code at an Unprecedented Scale
GitHub is just the latest victim of TeamPCP, a gang that has carried out a spree of software supply chain attacks that has impacted hundreds of organizations.
www.wired.com
May 21, 2026 at 1:15 PM
Australian police say they have arrested two people involved in the TeamPCP hacks, which hit GitHub, OpenAI and others.

Brian Krebs has the full back story with one of the hackers, and it's one hell of a read. I audibly gasped at least twice.
Two Alleged ‘TeamPCP’ Hackers Arrested in Australia – Krebs on Security
krebsonsecurity.com
August 27, 2026 at 11:18 AM
If the Trivy, RICS, and LiteLLM incidents have confused you, the team at OpenSourceMalware has published a profile of TeamPCP, the group behind the larger attack (as well on how the attack was carried out)

opensourcemalware.com/blog/teampcp...
March 28, 2026 at 10:55 PM
An unknown group of hackers is breaking into systems previously breached by the cybercrime group TeamPCP. Once inside, the hackers immediately kick out TeamPCP and remove its hacking tools from the victims’ systems.
Hackers hack victims hacked by other hackers | TechCrunch
An unknown group of hackers is breaking into systems previously breached by the cybercrime group TeamPCP. Once inside, the hackers immediately kick out TeamPCP and remove its hacking tools from the victims’ systems.
techcrunch.com
May 7, 2026 at 6:33 PM
> wake up
> check computer
> contacted by teampcp
> sends me msbuild and wav payload

its called science
March 29, 2026 at 3:34 PM
TeamPCP wird für den weitreichenden LiteLLM-Lieferkettenangriff verantwortlich gemacht. Jetzt wurden wohl zwei Mitglieder der Cybergang in Australien gefasst. #Cybercrime
Zwei mutmaßlich zu TeamPCP gehörende Cyberkriminelle in Australien verhaftet
TeamPCP wird für den weitreichenden LiteLLM-Lieferkettenangriff verantwortlich gemacht. Jetzt wurden wohl zwei Mitglieder der Cybergang in Australien gefasst.
www.heise.de
August 28, 2026 at 3:38 AM
The TeamPCP hacking group is feeding credentials stolen in the Trivy and Checkmarx KICS supply chain attacks to the Vect ransomware group, per a new report: www.dataminr.com/resources/in...
Cyber Intel Brief: Vect, BreachForums, and TeamPCP Converge
An unprecedented ransomware partnership that mobilizes 300,000 cybercrime forum members and weaponizes stolen supply chain credentials.
www.dataminr.com
April 19, 2026 at 7:21 PM
Australian cops cuff alleged TeamPCP masterminds
Australian cops cuff alleged TeamPCP masterminds
Alleged crew behind the Shai-Hulud worm and other supply chain attacks nabbed with help from the FBI
www.theregister.com
August 28, 2026 at 3:36 AM
Completely undone by cat photos - cyberscoop.com/teampcp-cybe...

VX Underground is somewhere laughing
Two alleged TeamPCP members arrested and charged after months of software supply-chain chaos
Australian authorities have arrested two alleged members of cybercrime group TeamPCP over widespread supply-chain attacks that compromised more than 1,000 organizations worldwide.
cyberscoop.com
August 27, 2026 at 2:38 PM
‼️🚨 BREAKING: GitHub has been compromised by TeamPCP. GitHub has confirmed the internal breach. A poisoned VS Code extension on an employee device exfiltrated ~3,800 internal repositories.

TeamPCP is already selling the data on a cybercrime forum.
May 20, 2026 at 8:18 AM
📢⚠️ GitHub confirmed a breach after attackers used a malicious VS Code extension to compromise a developer device and steal 3,800 internal repositories. TeamPCP is now selling the stolen data online for $95K. 👀

Read: hackread.com/github-breac...

#GitHub #DataBreach #CyberSecurity #VSCode #TeamPCP
GitHub Breach: TeamPCP Steals 3,800 Repositories via VS Code Extension
GitHub Breach: TeamPCP stole 3,800 internal repositories through a malicious VS Code extension and is now selling the data online for $95,000.
hackread.com
May 20, 2026 at 2:01 PM
Email: Google links the Axios supply chain incident to UNC1069 (and not TeamPCP)
March 31, 2026 at 6:57 PM
Google'ın tehdit istihbaratı ekibi, tedarik zinciri saldırıları düzenleyen TeamPCP adlı hacker grubunun içine sızmayı başardı. Google analistlerinin içeriden bilgi topladığı operasyon, siber güvenlik dünyasında büyük ses getirdi.
September 20, 2026 at 11:55 AM
🚨 Breaking: Namastex Labs, the team behind Automagik[.]dev, hit with a supply chain attack affecting its npm packages.

The malicious versions replicate TeamPCP-style Canister Worm tradecraft, including secret theft, exfiltration, and self-propagation.

socket.dev/blog/namaste...
Namastex.ai npm Packages Hit with TeamPCP-Style CanisterWorm...
Malicious Namastex.ai npm packages appear to replicate TeamPCP-style Canister Worm tradecraft, including exfiltration and self-propagation.
socket.dev
April 22, 2026 at 12:49 AM