Also Known As: PCPcat, CanisterWorm
First Observed: September 2025
Primary Operations: Software supply chain attacks, credential theft, cloud compromise, source code theft, extortion, ransomware access brokerage
Motivation: Financially motivated
TeamPCP is a financially motivated cybercrime group that specializes in compromising software supply chains, cloud-native infrastructure, and enterprise development environments. Active since at least late 2025, the group has become one of the most disruptive supply chain threat actors observed in 2026 after compromising trusted developer tools used across thousands of organizations.
Unlike traditional ransomware groups, TeamPCP primarily targets developers, CI/CD pipelines, GitHub repositories, cloud infrastructure, and software publishing ecosystems. The group steals cloud credentials, SSH keys, Kubernetes secrets, API tokens, and proprietary source code before monetizing access through extortion, data sales, and partnerships with other cybercriminal operations.
In July 2026, the FBI published its first FLASH advisory dedicated to TeamPCP, describing the group’s software supply chain campaigns, malware families, indicators of compromise, and defensive recommendations for organizations. The advisory also confirmed TeamPCP has expanded beyond credential theft into extortion operations involving public leak sites and collaboration with other cybercriminal groups.
Latest activity tracker
This section is continuously updated as new TeamPCP activity is reported.
July 2026: FBI issues a FLASH advisory detailing TeamPCP malware, software supply chain attacks, extortion activity, and defensive guidance for organizations
May 2026: Allegedly lists GitHub internal source code and approximately 4,000 private repositories for sale
May 2026: OpenAI confirms an internal breach linked to the Mini Shai-Hulud supply chain campaign
May 2026: Claims sale of Mistral AI repositories and internal source code
May 2026: Lightning AI repositories allegedly leaked following the PyTorch Lightning compromise
April 2026: Bitwarden CLI compromised through a software supply chain attack
April 2026: European Commission breach publicly linked to TeamPCP activity
April 2026: Mercor compromised in a supply chain campaign targeting AI infrastructure
March 2026: Trivy, Checkmarx KICS, LiteLLM, and the Telnyx Python SDK compromised in large-scale software supply chain attacks
All TeamPCP coverage
Throughout 2026, BreachNews has tracked TeamPCP’s evolution from cloud-focused credential theft into one of the most active software supply chain threat groups targeting enterprise development environments.
- FBI issues FLASH warning on TeamPCP supply chain attacks and extortion activity
- Alleged TeamPCP sale of GitHub internal source code and private repositories
- OpenAI confirms internal breach linked to Mini Shai-Hulud
- TeamPCP claims sale of Mistral AI internal repositories and source code
- Lightning AI repositories allegedly leaked following PyTorch Lightning compromise
- Bitwarden CLI compromised in TeamPCP supply chain attack
- European Commission breach linked to TeamPCP and ShinyHunters
- Mercor supply chain attack exposing AI training secrets
- Mini Shai-Hulud malware campaign
Tactics and operational patterns
TeamPCP consistently targets trusted software distribution channels rather than end users directly. Operations focus on compromising packages, CI/CD infrastructure, developer workflows, and cloud environments where a single successful intrusion can cascade into thousands of downstream organizations.
Observed operational patterns include:
- Software supply chain compromise
- Malicious package publishing on npm and PyPI
- Compromise of GitHub Actions workflows
- Credential theft from cloud environments
- SSH key and API token harvesting
- Kubernetes secret extraction
- Source code theft
- Cloud infrastructure compromise
- Extortion following data theft
- Ransomware access brokerage
Malware ecosystem
Security researchers and the FBI have attributed multiple malware families to TeamPCP campaigns.
- CanisterWorm harvests cloud credentials, API tokens, SSH keys, and authentication material from AWS, Azure, and Google Cloud Platform environments.
- SANDCLOCK extracts AWS credentials, Kubernetes ServiceAccount tokens, environment variables, and cryptocurrency wallet data.
- Mini Shai-Hulud is a self-propagating software supply chain worm capable of spreading across npm and PyPI ecosystems.
- Miasma expands on Mini Shai-Hulud techniques by poisoning development environments while harvesting credentials.
Cloud and AI targeting
Much of TeamPCP’s activity has centered around AI companies, cloud platforms, developer infrastructure, and enterprise software vendors.
Public reporting and alleged victim claims have included organizations such as OpenAI, Mistral AI, Lightning AI, Mercor, GitHub, Cisco, and the European Commission. Rather than deploying ransomware immediately, the group frequently monetizes access by stealing repositories, cloud credentials, proprietary source code, and development secrets.
Shift toward extortion
Recent activity indicates TeamPCP has expanded beyond software supply chain compromise into direct extortion. According to the FBI, the group has published victim names on a public leak site, threatened organizations with data disclosure, and collaborated with other cybercriminal groups to monetize stolen access.
The advisory also warns that credentials stolen during TeamPCP intrusions should be treated as a long-term risk because affiliated threat actors may continue exploiting them well after the initial compromise.
Current threat assessment
TeamPCP remains one of the most significant supply chain threats currently facing organizations that rely on modern software development pipelines. By compromising trusted developer tools rather than individual victims, the group can rapidly affect thousands of downstream environments through a single malicious update.
The FBI’s July 2026 FLASH advisory elevated TeamPCP from a researcher-tracked operation to a formally recognized cybercrime threat, underscoring the group’s continued focus on software supply chains, cloud infrastructure, credential theft, and enterprise extortion.
Update (July 2026): Added the FBI FLASH advisory covering TeamPCP’s malware, software supply chain operations, indicators of compromise, extortion activity, and defensive recommendations for affected organizations.












