Two TeamPCP-linked actors are under arrest after package compromises that ReversingLabs says caused a suspected hundreds of millions of dollars in damages. The waves since September 2025 began with a stolen publishing credential and reached victims through updates their own pipelines installed.
Reality
- Evidence35
- Adoption
- Insufficient
- Hype gap+25
- Incentives75
- Confidence35
Two men arrested in Australia this week are alleged TeamPCP members. The AFP estimate filed alongside the case puts the worm's take at more than 500,000 credentials and 300GB of data, and that scale makes token lifetime the live question.
Perspective Coverage
17 publishers
- Builder
- Builder 33%
- Operator
- Operator 50%
- Investor
- Investor 17%
Reality
- Evidence68
- Adoption
- Insufficient
- Hype gap+25
- Incentives55
- Confidence62
Austin Larsen of Google's threat intelligence group says a Mandiant persona sat in TeamPCP's inner circle from almost the start of the campaign. For the companies the group breached, that infiltration was the warning system.
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap+20
- Incentives60
- Confidence55
A dev.to writeup traces roughly 3,800 exfiltrated GitHub repositories to one trojanised Nx Console install from the official Marketplace, where the sandbox that would have contained it has been an open feature request since 2018.
Reality
- Evidence42
- Adoption28
- Hype gap+18
- Incentives62
- Confidence45
TeamPCP's npm compromise of TanStack reached CrowdSec through a departed employee's laptop, and the company learned its private repositories had been copied only when the code surfaced on a dark web forum in September.
Reality
- Evidence58
- Adoption55
- Hype gap+12
- Incentives72
- Confidence60
GitHub's volume counters and Chainguard's account of agent-written code both point at dependency review as the step nobody is doing. Mandiant estimates mean time-to-exploit at minus seven days in 2025.
Reality
- Evidence43
- Adoption55
- Hype gap+27
- Incentives76
- Confidence42
TeamPCP hijacked developer accounts, poisoned hundreds of programs and released a worm to automate the spread. Google says the inside access let it warn victims, revoke stolen credentials and help patch an AI-developed zero-day.
Reality
- Evidence32
- Adoption38
- Hype gap+22
- Incentives68
- Confidence30
GTIG's 2026 accounting traces one crew from package-registry compromises on PyPI, npm and Docker Hub to agent instructions that planned and ran the campaign, then out to public malware releases anyone can reuse.
Reality
- Evidence48
- Adoption45
- Hype gap+22
- Incentives72
- Confidence45
Aikido says the pair, both in their early 20s, ran TeamPCP's npm supply chain campaigns with a worm they cloned from Shai-Hulud. Whoever wrote the original is still unidentified, and the code is still published.
Reality
- Evidence41
- Adoption44
- Hype gap−6
- Incentives63
- Confidence45
Mandiant traced the Q2 2026 campaign to an AI coding chatbot, one prompt and a set of agent instructions that ran the scanning pipeline, fixed its own errors and rotated IPs with nobody at the keyboard.
Perspective Coverage
3 publishers
- Builder
- Builder 30%
- Operator
- Operator 57%
- Investor
- Investor 13%
Reality
- Evidence58
- Adoption62
- Hype gap+24
- Incentives70
- Confidence66
Install hooks and .pth files execute before your first import, which puts the useful controls in resolver precedence and environment scope rather than in a test suite that passes either way.
Reality
- Evidence34
- Adoption58
- Hype gap+20
- Incentives55
- Confidence33
Two litellm releases that never came out of the project's CI harvested SSH keys and cloud credentials from every host that installed them. litellm traces the entry point to the Trivy scanner in its own pipeline.
Reality
- Evidence48
- Adoption
- Insufficient
- Hype gap+12
- Incentives78
- Confidence42
Two suspects in Western Australia are in custody over the supply-chain worm that hit Trivy, KICS, LiteLLM and Telnyx. The 500,000 credentials it harvested stay valid until someone rotates them. Only 78,000 have surfaced publicly.
Reality
- Evidence50
- Adoption62
- Hype gap+14
- Incentives45
- Confidence52
Google places the spree with a single operator in South Africa, which makes one arrest plausible, while Palo Alto Networks counts three core members. Either way, the packages moved because almost nobody checks what they ingest.
Reality
- Evidence58
- Adoption74
- Hype gap+10
- Incentives68
- Confidence55
Anthropic, Sysdig, Unit 42 and GitGuardian describe the same shape of failure, which puts the interesting number on your side of the fence: how long an issued token keeps working after it leaves your control.
Reality
- Evidence27
- Adoption44
- Hype gap+37
- Incentives71
- Confidence57
A week of takedowns removed people and froze assets across five separate actions, while the kit that manufactures the stolen Microsoft 365 sessions those crews depend on still sells on Telegram for $320 a month.
Reality
- Evidence28
- Adoption52
- Hype gap+30
- Incentives58
- Confidence36
Unit 42 says the group backdoored Trivy, KICS, LiteLLM and Telnyx's Python SDK, tools that run inside CI with the privileges needed to reach production secrets, which is also why the headline counts deserve a slow read.
Reality
- Evidence55
- Adoption58
- Hype gap+32
- Incentives78
- Confidence48
Datadog's investigation puts genuine PyPI releases of litellm and telnyx inside the same campaign that poisoned Trivy on March 19, which makes the unit of remediation the secrets the build could see rather than the version pin.
Publishers:securitylabs.datadoghq.com
Reality
- Evidence71
- Adoption62
- Hype gap−8
- Incentives58
- Confidence64
Police allege a small number of trusted components carried the compromise into more than 1000 organisations, and the charge sheet puts the heaviest sentencing exposure on the money laundering count, well above anything tied to the code itself.
Publishers:abc.net.au · afp.gov.au Reality
- Evidence58
- Adoption41
- Hype gap+26
- Incentives72
- Confidence63
The Ray, Docker and Redis endpoints hijacked in ShadowRay 2.0 were worked by operators Oligo now ties to TA-NATALSTATUS activity from 2020, which makes the AI-cluster worm a tooling upgrade on an old farm.
Publishers:oligo.security
Reality
- Evidence55
- Adoption45
- Hype gap+25
- Incentives75
- Confidence50