TeamPCP: The Long‑standing Nemesis of Open‑Source Software

0
1

Key Takeaways

  • TeamPCP, the threat actor responsible for compromising over 1,000 open‑source packages in early 2025, has been active since at least 2020.
  • Oligo Security linked historical attacks to TeamPCP using shared IPs, domains, file‑ and command‑and‑control servers, and a GitHub profile that openly displayed the actor’s identity.
  • A late‑2025 campaign exploiting the ShadowRay vulnerability produced the first self‑propagating botnet running on hijacked AI infrastructure.
  • The rapid evolution of TeamPCP’s malware payloads—adjusted in near‑real time to the target environment—suggests heavy reliance on AI for autonomous adaptation.
  • The group’s public branding, social‑media activity, and boastful claims grew alongside the widespread adoption of AI tools, which both enabled and obscured their operations.
  • Open‑source AI‑centric infrastructure, while beneficial for developers, often shifts security responsibility onto users, creating exploitable trust gaps that TeamPCP exploits at scale.
  • Oligo Security believes many additional, unattributed or undetected attacks likely stem from TeamPCP’s long‑running campaign.

Background on TeamPCP’s Recent Notoriety
TeamPCP burst onto the threat‑intelligence scene in early 2025 after compromising and injecting malicious code into more than 1,000 software packages within a four‑month window. The sheer volume and speed of those attacks captured the attention of security researchers and threat‑hunting communities worldwide. Initially, analysts assumed the group had emerged only months prior, given the intensity of its activity. However, subsequent digging by Oligo Security revealed a far longer operational timeline, reshaping the understanding of TeamPCP’s capabilities and persistence.


Discovery of a Longer Operational History
Through meticulous correlation of network artifacts, Oligo Security’s researchers identified multiple intrusion sets dating back to 2020 that shared distinctive hallmarks with the 2025 TeamPCP campaigns. These hallmarks included recurring IP addresses, domain names, a specific file server used for payload staging, and a command‑and‑control (C2) infrastructure that remained consistent across years. By mapping these elements, the team established a clear lineage linking early‑stage activity to the later, high‑visibility assaults on open‑source repositories.


Linking Historical Activity to the ShadowRay 2.0 Campaign
One pivotal piece of evidence emerged from the investigation of a late‑2025 campaign exploiting the ShadowRay vulnerability—a flaw in a widely used AI‑orchestration framework. The attack resulted in the first known self‑propagating botnet that leveraged compromised AI infrastructure to spread autonomously. Artifacts from this campaign, such as specific malware hashes and C2 communication patterns, matched those observed in earlier intrusions traced to TeamPCP. This connection provided concrete proof that the actor’s toolkit and tactics had remained stable over several years, even as the underlying targets evolved.


AI‑Driven Payload Adaptation
Uri Katz, Director of Research at Oligo Security, emphasized the unprecedented speed at which TeamPCP’s payloads morphed during the ShadowRay 2.0 operation. Unlike typical malware that undergoes incremental, manually guided updates, TeamPCP’s code appeared to adjust autonomously to the nuances of each target environment. Katz attributed this agility to the actor’s use of artificial intelligence, which enabled rapid generation of variants capable of bypassing detection mechanisms and exploiting newly discovered weaknesses in real time.


Public Identity and Open‑Source Footprint
Avi Lumelsky, an AI security researcher at Oligo, noted that one of the domains associated with TeamPCP appeared openly in the threat actor’s GitHub profile. The profile was publicly accessible and made no effort to conceal the group’s identity, a stark contrast to the usual clandestine behavior of advanced threat actors. This transparency allowed investigators to correlate the GitHub activity with other infrastructure indicators, reinforcing the attribution of multiple campaigns to the same entity.


Consolidation of Multiple Aliases
Oligo’s analysis tied TeamPCP to several previously tracked threat‑activity clusters, including TA‑NATALSTATUS and IronErn. These aliases, active from 2020 through late 2025, exhibited identical IP ranges, domain registrations, file‑server usage, and C2 endpoints. The convergence of these data points under a single actor narrative suggests that TeamPCP operated under different monikers depending on the campaign’s focus or the audience it sought to mislead, while maintaining a stable backend infrastructure.


Emergence of a Public Brand
TeamPCP transitioned from a covert operation to a recognizable brand in late 2025. Gal Elbaz, co‑founder and CTO of Oligo Security, observed that once the group adopted the “TeamPCP” label, its activities became noticeably louder and more brazen. The actor began leveraging social media platforms to broadcast successes, claim victims, and tout its technical prowess. This public posturing coincided with the rapid adoption of AI technologies across industries, which TeamPCP adeptly incorporated into its offensive toolkit.


AI as a Force Multiplier for Attackers
Elbaz highlighted that the global rush to embed AI into business processes unintentionally empowered threat actors like TeamPCP. Organizations eager to avoid obsolescence deployed AI‑driven pipelines without fully grasping the associated security implications. The lack of visibility into how these AI systems behave internally creates blind spots that attackers can exploit. TeamPCP’s ability to commandeer AI infrastructure and orchestrate attacks using AI‑generated payloads exemplifies how the same technology that drives innovation can also amplify offensive capabilities when defenses lag.


Exploiting Trust in Open‑Source AI Ecosystems
Lumelsky pointed out that most AI infrastructure is inherently open source, born from the necessity to share development costs and expertise. While this model fosters innovation, it also shifts a significant portion of security responsibility onto end‑users and developers who may not be accustomed to scrutinizing the provenance and integrity of AI‑related components. TeamPCP capitalizes on this trust gap, injecting malicious code into widely used libraries and frameworks that downstream applications automatically incorporate, thereby achieving large‑scale impact with relatively modest effort.


Implications for Future Defense
Having established a multi‑year timeline for TeamPCP’s operations, Oligo Security expresses confidence that many additional attacks—either undetected or not yet attributed to the group—likely stem from the same actor. The research underscores the necessity for organizations to enhance visibility into AI‑centric supply chains, enforce rigorous code‑signing and provenance checks, and monitor for anomalous behavior in AI‑driven environments. As adversaries increasingly harness AI to accelerate and adapt their campaigns, defenders must evolve correspondingly, leveraging threat intelligence, automated analysis, and proactive hunting to stay ahead of threats like TeamPCP.

SignUpSignUp form

LEAVE A REPLY

Please enter your comment!
Please enter your name here