TeamPCP: Threat Actor Profile

TeamPCP is a financially motivated cybercrime group active since 2025, known for disrupting supply chains through attacks on developer tools, cloud infrastructure, and source code theft involving AI and cloud providers.
TeamPCP cybercrime threat actor profile

Also Known As: PCPcat, CanisterWorm

First Observed: September 2025

Primary Operations: Software supply chain attacks, credential theft, cloud compromise, source code theft, extortion, ransomware access brokerage

Motivation: Financially motivated

TeamPCP is a financially motivated cybercrime group that specializes in compromising software supply chains, cloud-native infrastructure, and enterprise development environments. Active since at least late 2025, the group has become one of the most disruptive supply chain threat actors observed in 2026 after compromising trusted developer tools used across thousands of organizations.

Unlike traditional ransomware groups, TeamPCP primarily targets developers, CI/CD pipelines, GitHub repositories, cloud infrastructure, and software publishing ecosystems. The group steals cloud credentials, SSH keys, Kubernetes secrets, API tokens, and proprietary source code before monetizing access through extortion, data sales, and partnerships with other cybercriminal operations.

In July 2026, the FBI published its first FLASH advisory dedicated to TeamPCP, describing the group’s software supply chain campaigns, malware families, indicators of compromise, and defensive recommendations for organizations. The advisory also confirmed TeamPCP has expanded beyond credential theft into extortion operations involving public leak sites and collaboration with other cybercriminal groups.

Latest activity tracker

This section is continuously updated as new TeamPCP activity is reported.

July 2026: FBI issues a FLASH advisory detailing TeamPCP malware, software supply chain attacks, extortion activity, and defensive guidance for organizations

May 2026: Allegedly lists GitHub internal source code and approximately 4,000 private repositories for sale

May 2026: OpenAI confirms an internal breach linked to the Mini Shai-Hulud supply chain campaign

May 2026: Claims sale of Mistral AI repositories and internal source code

May 2026: Lightning AI repositories allegedly leaked following the PyTorch Lightning compromise

April 2026: Bitwarden CLI compromised through a software supply chain attack

April 2026: European Commission breach publicly linked to TeamPCP activity

April 2026: Mercor compromised in a supply chain campaign targeting AI infrastructure

March 2026: Trivy, Checkmarx KICS, LiteLLM, and the Telnyx Python SDK compromised in large-scale software supply chain attacks

All TeamPCP coverage

Throughout 2026, BreachNews has tracked TeamPCP’s evolution from cloud-focused credential theft into one of the most active software supply chain threat groups targeting enterprise development environments.

Tactics and operational patterns

TeamPCP consistently targets trusted software distribution channels rather than end users directly. Operations focus on compromising packages, CI/CD infrastructure, developer workflows, and cloud environments where a single successful intrusion can cascade into thousands of downstream organizations.

Observed operational patterns include:

  • Software supply chain compromise
  • Malicious package publishing on npm and PyPI
  • Compromise of GitHub Actions workflows
  • Credential theft from cloud environments
  • SSH key and API token harvesting
  • Kubernetes secret extraction
  • Source code theft
  • Cloud infrastructure compromise
  • Extortion following data theft
  • Ransomware access brokerage

Malware ecosystem

Security researchers and the FBI have attributed multiple malware families to TeamPCP campaigns.

  • CanisterWorm harvests cloud credentials, API tokens, SSH keys, and authentication material from AWS, Azure, and Google Cloud Platform environments.
  • SANDCLOCK extracts AWS credentials, Kubernetes ServiceAccount tokens, environment variables, and cryptocurrency wallet data.
  • Mini Shai-Hulud is a self-propagating software supply chain worm capable of spreading across npm and PyPI ecosystems.
  • Miasma expands on Mini Shai-Hulud techniques by poisoning development environments while harvesting credentials.

Cloud and AI targeting

Much of TeamPCP’s activity has centered around AI companies, cloud platforms, developer infrastructure, and enterprise software vendors.

Public reporting and alleged victim claims have included organizations such as OpenAI, Mistral AI, Lightning AI, Mercor, GitHub, Cisco, and the European Commission. Rather than deploying ransomware immediately, the group frequently monetizes access by stealing repositories, cloud credentials, proprietary source code, and development secrets.

Shift toward extortion

Recent activity indicates TeamPCP has expanded beyond software supply chain compromise into direct extortion. According to the FBI, the group has published victim names on a public leak site, threatened organizations with data disclosure, and collaborated with other cybercriminal groups to monetize stolen access.

The advisory also warns that credentials stolen during TeamPCP intrusions should be treated as a long-term risk because affiliated threat actors may continue exploiting them well after the initial compromise.

Current threat assessment

TeamPCP remains one of the most significant supply chain threats currently facing organizations that rely on modern software development pipelines. By compromising trusted developer tools rather than individual victims, the group can rapidly affect thousands of downstream environments through a single malicious update.

The FBI’s July 2026 FLASH advisory elevated TeamPCP from a researcher-tracked operation to a formally recognized cybercrime threat, underscoring the group’s continued focus on software supply chains, cloud infrastructure, credential theft, and enterprise extortion.

Update (July 2026): Added the FBI FLASH advisory covering TeamPCP’s malware, software supply chain operations, indicators of compromise, extortion activity, and defensive recommendations for affected organizations.

Picture of m00s3c

m00s3c

Moose (@m00s3c) is the author of BreachNews, focusing on data breach intelligence, dark web monitoring, and threat analysis. His work involves analyzing breach claims, reviewing leaked datasets, and tracking threat actor activity to provide clear, factual reporting.

Latest News

BREACHNEWS.COM/SUPPORT/

Support Independent News.

Help support breach monitoring, investigations, infrastructure, and reporting.

Support the site