Skip to content

Security1 publisher2 min readPublished Updated

TeamPCP poisoned more than 1,000 packages with tactics anyone can copy

Google places the spree with a single operator in South Africa, which makes one arrest plausible, while Palo Alto Networks counts three core members. Either way, the packages moved because almost nobody checks what they ingest.

The Watch · Security desk

What happened

  • TeamPCP injected malicious code into more than 1,000 software packages in less than four months, a run CyberScoop dates from the compromise of Trivy in February.
  • Google says it traced the actor's residential and mobile IP connections to South Africa, indicating the primary operator was there during at least some of the attacks.
  • Palo Alto Networks says the core manager uses the handle ResoluteXBF across multiple platforms, and the firm is separately tracking two more core members, diencracked and Shinigami.
  • TeamPCP listed roughly 4,000 private code repositories on the dark web, output that stays available regardless of what happens to the people who took them.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • contradiction Google's read of a lone individual with no established core group and Palo Alto's roster of three handles imply different arrest math: one gives investigators a person whose removal stops the publishing, the other gives them a bench.
  • exposure Socket's Feross Aboukhadijeh says AI tooling has left some dependency decisions with virtually no human in the loop, which means one stolen publishing credential now reaches every project that lets an agent resolve its own packages.
  • constraint Palo Alto's Nathaniel Quist locates the credential that matters at the publisher, so the control that would have stopped this sits outside the reach of every downstream consumer who ingested the code.
  • precedent Because the industry has known the open-source trust model is broken for years and has not fixed it, the playbook stays priced for anyone who wants it, with no development work required.

Eight injected packages a day, averaged, is the floor the count implies [11]. That pace comes from the delivery machinery, not the tradecraft. CI/CD pipelines carry code onward without a human reading it, and the gaps opened by developers' reliance on AI tooling sit in the same column, according to CyberScoop's account [17].

The inspection point matters here. Packages are typically put through intensive monitoring for vulnerabilities and poisoned updates before they reach live environments [12]. That control assumes the poison arrives from outside the publisher. When the publisher's own credential signs the release, the check runs and the release passes.

Kimberly Goody, senior manager at Google Threat Intelligence Group, puts the core of the activity at third-party trust exploitation, and says the speed and scale are what make it notable rather than the method [5]. That framing carries the weight of the assessment, since the tactics needed no new capability to pull off.

On the arrest question, CyberScoop notes that if TeamPCP is primarily run by one person, law enforcement has a rare chance at lasting impact from a single arrest [10]. Charging someone requires identifying them, and Google declined to name the core operator or confirm that it knows the person's true identity [13]. The actor has been tracked by threat hunters since it emerged in late 2025 [18].

An arrest, though, would leave one part of the picture untouched. Goody says TeamPCP's collaborations with other criminals were mostly short-lived and ended in public feuds or never got off the ground [14], so there is no obvious crew standing by to inherit infrastructure, even though researchers have linked the actor to extortion groups and affiliates including Lapsus$, ShinyHunters, Vect, DragonForce, BreachForums and HasanBroker [19]. An arrest would stop this run without closing the delivery path, which stays open to whoever steals the next publishing token.

The arithmetic on the rate: more than 1,000 packages across a window shorter than four months, taken at four months of 30 days, is 1,000 divided by 120, or 8.3 packages a day [11]. Both inputs push the real figure higher, since the count is a floor and the window is a ceiling [1].

What to watch

  • Whether Google names, or any authority charges, the operator it places in South Africa.
  • Whether packages keep appearing from the ResoluteXBF, diencracked and Shinigami handles after any arrest.
  • Whether the roughly 4,000 listed private repositories turn into follow-on credential compromises at named publishers.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories