Skip to main content
Emerging ThreatsSupply Chain Attacks

TeamPCP's Origins Exposed in Long-Running Open-Source Attacks

Software development workspace with laptop, papers, and notes, overlooking cityscape through large window.

“The scariest thing in this campaign is the speed at which the payloads evolved and changed and adapted to the environment they run in.” — Uri Katz, director of research, Oligo Security.

Oligo Security traces TeamPCP activity back to 2020

Research firm Oligo Security shared with CyberScoop that TeamPCP, the threat actor blamed for a wave of open-source supply-chain compromises earlier this year, has a far longer operational history than previously understood. Oligo’s team tied multiple attacks dating back to 2020 to the same actor, using shared infrastructure such as IP addresses, domain names, a file server and command‑and‑control servers. The vendor reported that TeamPCP was behind compromises that injected malicious code into more than 1,000 software packages in less than four months earlier this year.

ShadowRay 2.0 campaign: a late‑2025 turning point

Oligo’s investigators identified a late‑2025 campaign that exploited a ShadowRay vulnerability and, in their assessment, produced “the first self‑propogating botnet running on hijacked AI infrastructure.” Evidence from that investigation linked back to historical activity associated with the same IPs and domains used in the earlier package injections. Oligo also mapped TeamPCP activity to aliases tracked under multiple names, including TA‑NATALSTATUS and IronErn, spanning the 2020–late‑2025 timeframe.

Public presence, fast iteration, and AI-driven orchestration

According to Oligo, TeamPCP emerged publicly as a brand in late 2025. The group’s public profile expanded rapidly thereafter; Oligo found a domain in July 2025 that appeared in the profile of TeamPCP’s official GitHub account, a detail AI security researcher Avi Lumelsky highlighted: “It’s public, they’re not even trying to hide their identity.”

Oligo’s researchers describe an unusual tempo to TeamPCP’s work. Uri Katz pointed to rapid changes in payloads and adaptation to target environments that the team judged were “clearly with the help of AI.” Gal Elbaz, co‑founder and CTO at Oligo Security, said the actor’s broader campaigns became noisier after the brand went public and that “widespread adoption of AI and TeamPCP’s use of the technology supported this growth as the threat actor built a brand, got more active on social media and boasted publicly about its activities and claimed victims.”

Elbaz also emphasized the operational advantage AI gave the attacker: “The ability to control the infrastructure and orchestrate the attack with AI was also super new, and I’m sure it helps them.” Oligo framed that advantage as both a force multiplier for the attacker and a growing blind spot for defenders who rely on automated AI infrastructure.

Open‑source AI infrastructure as an attack surface

Oligo’s reporting notes that TeamPCP’s recent campaigns exploited security gaps tied to developers’ increasing reliance on AI and to the automated systems companies use to build and deploy code. Avi Lumelsky observed that much AI infrastructure is open source by design: “Most AI infrastructure is open source by design because nobody has the manpower and money to develop everything from scratch.” He added a caution about default responsibilities: “Many of these tools place the responsibility of using it right and security on the user, and developers are not used to these new kinds of animals. That’s why the trust can be exploited at scale.”

What this means for technologists, open‑source maintainers, and enterprises

  • Technologists and security teams: Accelerated payload evolution — which Oligo ties to AI assistance — suggests defenders will need faster detection, richer telemetry linking behavior across IPs and domains, and tighter controls around automated deployment pipelines.
  • Open‑source maintainers and developers: The attacker’s success in compromising widely used packages highlights the risks of trusting supply‑chain components and the distribution mechanisms that feed automated AI tooling; maintainers may have to prioritize provenance, signing, and stricter onboarding processes for package publication.
  • Enterprises and procurement leaders: Oligo’s linkage of multiple aliases and shared infrastructure across years indicates a persistent threat actor likely responsible for attacks that remain undetected; organizations should reassess assumptions about which dependencies are “safe” to consume by default.

Oligo Security’s work, disclosed to CyberScoop, leaves a pointed final note from Gal Elbaz: “There’s a lot more out there that we haven’t caught or been able to prove up until now.” The firm’s reconstruction of TeamPCP’s history — from discrete early incidents through a late‑2025 ShadowRay campaign and a noisy, AI‑assisted public phase — demands a simple, urgent question for defenders: how many of those older compromises are still invisible until they are weaponized at scale?

Read the original CyberScoop story