TeamPCP

☆ pin
Also known as ShadowRay 2.0, IronErn, TA-NATALSTATUS, xploitrsturtle2, CipherForce, Mini Shai-Hulud, Replicating Marauder, UNC6780, PCPCat, SHADOW-WATER-058, pcpcats, Shellforce
Reports
50
First seen
Mar 26, 2026
Last seen
Aug 7, 2026
Motivation
Financial, Notoriety, Espionage

Relationships

Filled ◆ = CVE exploited in the wild. Entities that appear together in Signalis reporting — co-mention, not confirmed collaboration. Reports naming many actors at once (weekly roundups) are excluded from relationship edges.

Targeting

Victim regions
×1
×14
United States×14
Brazil×1

Victim country, only when stated. Corpus is predominantly English-language reporting, so US/EU coverage is overweighted relative to true victim distribution.

Top ATT&CK techniques

T1195 Supply Chain Compromise ×34T1041 Exfiltration Over C2 Channel ×28T1555 Credentials from Password Stores ×25T1005 Data from Local System ×21T1078 Valid Accounts ×19T1190 Exploit Public-Facing Application ×13T1003 OS Credential Dumping ×13T1486 Data Encrypted for Impact ×11T1566 Phishing ×10T1204 User Execution ×9T1059 Command and Scripting Interpreter ×8T1547 Boot or Logon Autostart Execution ×7

Indicators

cve ×135domain ×47filename ×41ip_v4 ×25hash_sha1 ×13url ×6hash_sha256 ×5email ×2

Indicator values are available on Pro and via the API.

Associated CVEs

Recent reports

High

TeamPCP Linked To Redis Attacks Dating Back To 2020 And Later Supply Chain Campaign

The Hacker News
Critical

TeamPCP threat actor's history extends to 2020, linked to ShadowRay botnet campaign

CyberScoop
Critical

Massive supply-chain attack compromises 440+ npm packages in four hours

CyberScoop
High

CrowdStrike: AI Now Both Weapon and Target in Cyberattacks

CyberScoop
High

Python Supply Chain Attack Techniques: Build Hooks and Package Content Abuses

Cisco Talos
High

Weekly Threat Intelligence Report – July 6: Ransomware Attacks, AI Threats, and Critical Vulnerabilities

Check Point Research
Critical

Ransomware Groups Exploit Citrix Bleed 2, BYOVD Techniques, and Supply Chain Credentials

The Hacker News
Critical

Vect and TeamPCP partner for ransomware campaigns targeting supply chain

Sophos News
High

Intelligence Insights: June 2026 – ClearFake, Kali365, and TeamPCP Lead Threat Rankings

Red Canary
Critical

TeamPCP's supply-chain attack spree: 1,000+ compromised packages in four months

CyberScoop
Critical

GitHub dismissed security reports on flaws exploited by Shai-Hulud supply-chain worm

The Record (Recorded Future News)
High

Microsoft Restores GitHub Repos as Miasma Supply Chain Campaign Continues

The Hacker News
Critical

Miasma Worm Compromises 73 Microsoft GitHub Repositories in Supply Chain Attack

The Hacker News
Critical

IronWorm and Miasma Worm Variant Hit npm in Supply Chain Attacks

The Hacker News
High

New IronWorm malware hits 36 packages in npm supply-chain attack

Bleeping Computer
High

CERT-EU Cyber Brief May 2026 – Espionage, Supply-Chain Attacks, and Ransomware Infrastructure Disruption

CERT-EU Threat Intel
High

Red Hat removes tainted packages after software pipeline compromise

The Record (Recorded Future News)
High

Red Hat npm packages compromised in supply-chain attack distributing Miasma credential stealer

Bleeping Computer
Info

Container security: attack vectors from escapes to supply chain compromise

Kaspersky Securelist
Critical

Malicious Sicoob NuGet and npm Packages Steal Banking Credentials and Cloud Secrets

The Hacker News
High

TeamPCP stole GitHub's internal repos

Risky Business
Critical

Weekly Recap: Linux Flaws, Defender 0-Days, Router Botnets, and Supply Chain Chaos

The Hacker News
Critical

Megalodon GitHub Attack Compromises 5,561 Repos with Malicious CI/CD Workflows

The Hacker News
Critical

GitHub breach linked to malicious Nx Console VS Code extension in TanStack supply-chain attack

Bleeping Computer
High

GitHub Internal Repositories Breached via Compromised Nx Console VS Code Extension

The Hacker News
High

Grafana breach caused by missed token rotation after TanStack attack

Bleeping Computer
High

GitHub internal repositories exfiltrated via poisoned VS Code extension

CyberScoop
High

GitHub confirms breach by TeamPCP via poisoned VS Code extension

The Record (Recorded Future News)
Critical

GitHub Breached via Poisoned VS Code Extension; TeamPCP Exfiltrates 3,800+ Internal Repos

The Hacker News
High

GitHub confirms breach of 3,800 repos via malicious VSCode extension

Bleeping Computer

This page shows data on a 7-day delay. Free accounts get the full delayed feed; real-time reports, indicators, and the API start at $29/mo.