Skip to content

other

TeamPCP

Threat actor group tied to the Shai-Hulud npm supply-chain attacks, stealing credentials and secrets from developer build pipelines.

Known aliases

  • Altered Spider
  • PCPcat
  • @pcpcats
  • PCPsh
  • Persy_PCP
  • ResoluteXBF
  • ShellForce
  • Team PCP
  • tpcp
  • UNC6780

Relationships

No evidence-backed relationships are recorded.

Current stories

security1 publisher

TeamPCP's package attacks reused the stolen-token techniques of S1ngularity and Shai-Hulud

Two TeamPCP-linked actors are under arrest after package compromises that ReversingLabs says caused a suspected hundreds of millions of dollars in damages. The waves since September 2025 began with a stolen publishing credential and reached victims through updates their own pipelines installed.

Reality

Evidence35
Adoption
Insufficient
Hype gap+25
Incentives75
Confidence35
security17 publishers

AFP sizes the Shai-Hulud syndicate's take at more than 500,000 credentials

Two men arrested in Australia this week are alleged TeamPCP members. The AFP estimate filed alongside the case puts the worm's take at more than 500,000 credentials and 300GB of data, and that scale makes token lifetime the live question.

Perspective Coverage

17 publishers
Builder
Builder 33%
Operator
Operator 50%
Investor
Investor 17%

Reality

Evidence68
Adoption
Insufficient
Hype gap+25
Incentives55
Confidence62
security3 publishers

Attacker agents ran a mass credential harvest from inside the victim's own cloud in six hours

Mandiant traced the Q2 2026 campaign to an AI coding chatbot, one prompt and a set of agent instructions that ran the scanning pipeline, fixed its own errors and rotated IPs with nobody at the keyboard.

Perspective Coverage

3 publishers
Builder
Builder 30%
Operator
Operator 57%
Investor
Investor 13%

Reality

Evidence58
Adoption62
Hype gap+24
Incentives70
Confidence66

Earlier coverage

  1. Flare traced TeamPCP's GitHub handle to a HackerOne profile carrying a real name

    Product · August 27, 2026 · 1 publisher

  2. A repo compromise found in week four outlives GitHub's seven-day Git event log

    Security · August 27, 2026 · 1 publisher

  3. LiteLLM 1.82.7 and 1.82.8 shipped an infostealer: rotate everything those machines touched

    Science · August 20, 2026 · 1 publisher

  4. VECT 2.0 shreds anything over 128 KB, which makes paying its ransom pointless

    Leadership · August 18, 2026 · 1 publisher

  5. The 2,500-org compromise was a Trivy problem. LiteLLM was the closing act.

    Security · August 14, 2026 · 1 publisher