{"id":8756,"date":"2026-06-18T10:25:33","date_gmt":"2026-06-18T15:25:33","guid":{"rendered":"https:\/\/cyberscoop.com\/?p=89398"},"modified":"2026-06-18T10:25:33","modified_gmt":"2026-06-18T15:25:33","slug":"how-software-developments-speed-obsession-enabled-teampcps-chaos-crusade","status":"publish","type":"post","link":"https:\/\/ddi.mohflo.net\/index.php\/2026\/06\/18\/how-software-developments-speed-obsession-enabled-teampcps-chaos-crusade\/","title":{"rendered":"How software development\u2019s speed obsession enabled TeamPCP\u2019s chaos crusade"},"content":{"rendered":"<p><head> <meta charset=\"UTF-8\"> <meta name=\"viewport\" content=\"width=device-width, initial-scale=1\"> <meta name=\"robots\" content=\"index, follow, max-image-preview:large, max-snippet:-1, max-video-preview:-1\"> <!-- This site is optimized with the Yoast SEO Premium plugin v24.5 (Yoast SEO v27.1.1) - https:\/\/yoast.com\/product\/yoast-seo-premium-wordpress\/ --> <title>How software development&#8217;s speed obsession enabled TeamPCP\u2019s chaos crusade | CyberScoop<\/title> <meta name=\"description\" content=\"The threat group\u2019s remarkable success targeting open-source software was inevitable and fueled by the industry\u2019s decision to prioritize code shipping over security.\"> <link rel=\"canonical\" href=\"https:\/\/cyberscoop.com\/teampcp-breaks-open-source-software-trust-model\/\"> <meta property=\"og:locale\" content=\"en_US\"> <meta property=\"og:type\" content=\"article\"> <meta property=\"og:title\" content=\"How software development's speed obsession enabled TeamPCP\u2019s chaos crusade\"> <meta property=\"og:description\" content=\"The threat group\u2019s remarkable success targeting open-source software was inevitable and fueled by the industry\u2019s decision to prioritize code shipping over security.\"> <meta property=\"og:url\" content=\"https:\/\/cyberscoop.com\/teampcp-breaks-open-source-software-trust-model\/\"> <meta property=\"og:site_name\" content=\"CyberScoop\"> <meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/cyberscoop\/\"> <meta property=\"article:published_time\" content=\"2026-06-18T15:25:33+00:00\"> <meta property=\"article:modified_time\" content=\"2026-06-18T15:25:36+00:00\"> <meta property=\"og:image\" content=\"https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2026\/06\/how-software-developments-speed-obsession-enabled-teampcps-chaos-crusade-2.jpg\"> <meta property=\"og:image:width\" content=\"6563\"> <meta property=\"og:image:height\" content=\"2917\"> <meta property=\"og:image:type\" content=\"image\/jpeg\"> <meta name=\"author\" content=\"Matt Kapko\"> <meta name=\"twitter:card\" content=\"summary_large_image\"> <meta name=\"twitter:creator\" content=\"@CyberScoopNews\"> <meta name=\"twitter:site\" content=\"@CyberScoopNews\"> <!-- \/ Yoast SEO Premium plugin. --> <link rel=\"dns-prefetch\" href=\"\/\/securepubads.g.doubleclick.net\">\n<link rel=\"dns-prefetch\" href=\"\/\/use.typekit.net\">\n<link rel=\"alternate\" type=\"application\/rss+xml\" title=\"CyberScoop \u00bb Feed\" href=\"https:\/\/cyberscoop.com\/feed\/\">\n<link rel=\"alternate\" type=\"application\/rss+xml\" title=\"CyberScoop \u00bb Comments Feed\" href=\"https:\/\/cyberscoop.com\/comments\/feed\/\"> <link rel=\"stylesheet\" id=\"all-css-2\" href=\"https:\/\/cyberscoop.com\/wp-includes\/css\/dist\/block-library\/style.min.css?m=1778775768g\" type=\"text\/css\" media=\"all\"> <link rel=\"stylesheet\" id=\"all-css-6\" href=\"https:\/\/cyberscoop.com\/wp-content\/mu-plugins\/search\/elasticpress\/dist\/css\/related-posts-block-styles.min.css?m=1781636452g\" type=\"text\/css\" media=\"all\"> <link rel=\"stylesheet\" id=\"all-css-8\" href=\"https:\/\/cyberscoop.com\/wp-content\/themes\/scoopnewsgroup\/dist\/css\/frontend.css?m=1775068334g\" type=\"text\/css\" media=\"all\">\n<link rel=\"stylesheet\" id=\"typekit-css\" href=\"https:\/\/use.typekit.net\/itk2qbh.css?ver=13897d660a0ac2c9c7d1\" media=\"all\"> <link rel=\"https:\/\/api.w.org\/\" href=\"https:\/\/cyberscoop.com\/wp-json\/\"><link rel=\"alternate\" title=\"JSON\" type=\"application\/json\" href=\"https:\/\/cyberscoop.com\/wp-json\/wp\/v2\/posts\/89398\"><meta name=\"generator\" content=\"WordPress 6.8.5\">\n<link rel=\"shortlink\" href=\"https:\/\/cyberscoop.com\/?p=89398\">\n<link rel=\"alternate\" title=\"oEmbed (JSON)\" type=\"application\/json+oembed\" href=\"https:\/\/cyberscoop.com\/wp-json\/oembed\/1.0\/embed?url=https%3A%2F%2Fcyberscoop.com%2Fteampcp-breaks-open-source-software-trust-model%2F\">\n<link rel=\"alternate\" title=\"oEmbed (XML)\" type=\"text\/xml+oembed\" href=\"https:\/\/cyberscoop.com\/wp-json\/oembed\/1.0\/embed?url=https%3A%2F%2Fcyberscoop.com%2Fteampcp-breaks-open-source-software-trust-model%2F&amp;format=xml\"> <!-- Google Tag Manager --> <!-- End Google Tag Manager --> <link rel=\"icon\" href=\"https:\/\/cyberscoop.com\/wp-content\/uploads\/sites\/3\/2023\/01\/cropped-cs_favicon-2.png?w=32\" sizes=\"32x32\">\n<link rel=\"icon\" href=\"https:\/\/cyberscoop.com\/wp-content\/uploads\/sites\/3\/2023\/01\/cropped-cs_favicon-2.png?w=192\" sizes=\"192x192\">\n<link rel=\"apple-touch-icon\" href=\"https:\/\/cyberscoop.com\/wp-content\/uploads\/sites\/3\/2023\/01\/cropped-cs_favicon-2.png?w=180\">\n<meta name=\"msapplication-TileImage\" content=\"https:\/\/cyberscoop.com\/wp-content\/uploads\/sites\/3\/2023\/01\/cropped-cs_favicon-2.png?w=270\"> <\/head><body class=\"wp-singular post-template-default single single-post postid-89398 single-format-standard wp-theme-scoopnewsgroup wp-child-theme-cyberscoop\" id=\"readabilityBody\"> <a href=\"https:\/\/cyberscoop.com\/teampcp-breaks-open-source-software-trust-model\/#main\" class=\"skip-to-content-link visually-hidden-focusable\">Skip to main content<\/a> <\/p>\n<div class=\"ad ad--top ad--top-desktop\">\n<div class=\"ad__inner\"> <span class=\"screen-reader-text\">Advertisement<\/span> <\/div>\n<\/div>\n<p> <main id=\"main\" role=\"main\" tabindex=\"-1\"> <\/p>\n<div class=\"ad ad--top ad--top-mobile\">\n<div class=\"ad__inner\"> <span class=\"screen-reader-text\">Advertisement<\/span> <\/div>\n<\/div>\n<section id=\"stickybar\" class=\"stickybar stickybar--newsletter js-stickybar\" readability=\"0.82\"> <button class=\"stickybar__close js-stickybar-close\" aria-controls=\"stickybar\"> <svg class=\"icon icon--close\" width=\"21\" height=\"22\" viewBox=\"0 0 21 22\" fill=\"none\"><path d=\"m.822.518-.805.805L9.695 11 .017 20.678l.805.805 9.678-9.678 9.677 9.678.806-.805L11.305 11l9.678-9.677-.806-.805-9.677 9.677L.822.518Z\" fill=\"currentColor\" \/><\/svg> <span class=\"visually-hidden\">Close<\/span> <\/button> <\/section>\n<article class=\"single-article content\">\n<div class=\"single-article__container js-single-article-content\">\n<header class=\"single-article__header \" readability=\"25.390969162996\">\n<div class=\"single-article__header-content\" readability=\"34.441913439636\">\n<p> The threat group\u2019s remarkable success targeting open-source software was inevitable and fueled by the industry\u2019s decision to prioritize code shipping over security. <\/p>\n<p> <!-- Listen to this article section --> <!-- Audio Element --><br \/>\n<audio id=\"audio-player\" src=\"https:\/\/wp-tts-cdn.api.scpnewsgrp.com\/cyberscoop\/89398\/english.openai.mp3\"><\/audio> <\/p>\n<div readability=\"11\">\n<div>\n<p>Listen to this article<\/p>\n<p> <!-- Countdown Timer --> <\/p>\n<p>0:00<\/p>\n<\/p><\/div>\n<p> <!-- Tooltip --> <\/p>\n<p> <span id=\"tts-tooltip\">Learn more.<\/span> <span> This feature uses an automated voice, which may result in occasional errors in pronunciation, tone, or sentiment. <\/span> <\/p>\n<\/div>\n<p> <!-- End of audio player --> <\/div>\n<div class=\"single-article__cover-wrap\">\n<figure class=\"single-article__cover\"> <img data-recalc-dims=\"1\" fetchpriority=\"high\" width=\"640\" height=\"284\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2026\/06\/how-software-developments-speed-obsession-enabled-teampcps-chaos-crusade.jpg?resize=640%2C284&#038;ssl=1\" class=\"single-article__cover-image wp-post-image\" alt decoding=\"async\" fetchpriority=\"high\" srcset=\"https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2026\/06\/how-software-developments-speed-obsession-enabled-teampcps-chaos-crusade-2.jpg 6563w, https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2026\/06\/how-software-developments-speed-obsession-enabled-teampcps-chaos-crusade-2.jpg?resize=300,133 300w, https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2026\/06\/how-software-developments-speed-obsession-enabled-teampcps-chaos-crusade-2.jpg?resize=768,341 768w, https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2026\/06\/how-software-developments-speed-obsession-enabled-teampcps-chaos-crusade-2.jpg?resize=1024,455 1024w, https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2026\/06\/how-software-developments-speed-obsession-enabled-teampcps-chaos-crusade-2.jpg?resize=1536,683 1536w, https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2026\/06\/how-software-developments-speed-obsession-enabled-teampcps-chaos-crusade-2.jpg?resize=2048,910 2048w, https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2026\/06\/how-software-developments-speed-obsession-enabled-teampcps-chaos-crusade-2.jpg?resize=600,267 600w, https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2026\/06\/how-software-developments-speed-obsession-enabled-teampcps-chaos-crusade-2.jpg?resize=1200,533 1200w, https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2026\/06\/how-software-developments-speed-obsession-enabled-teampcps-chaos-crusade-2.jpg?resize=1500,667 1500w\" sizes=\"(max-width: 1200px) 100vw, 1200px\"><figcaption> (Getty Images) <\/figcaption><\/figure>\n<\/p><\/div>\n<\/header>\n<div class=\"single-article__content\">\n<div class=\"single-article__content-inner has-drop-cap\"> <html readability=\"151.27652881148\"><body readability=\"311.51537455021\"><\/p>\n<p>TeamPCP is on a rampage through open-source software.<\/p>\n<p>In less than four months, the threat actor has compromised and injected malicious code into more than 1,000 software packages. The extraordinary spree has transformed how software developers and maintainers distribute and manage their code, as their dependencies and repositories have become one of the most effective and prevalent attack vectors this year.<\/p>\n<p>While there has been a host of technical exploits, TeamPCP\u2019s greatest attack has been the uprooting of trust \u2014 repeatedly proving that most organizations fail to verify the code they ingest into their systems is legitimate, abusing a nearly blind faith that much of the software development industry relies on to power today\u2019s modern economy.<\/p>\n<p>Starting with <a href=\"https:\/\/cyberscoop.com\/trivy-supply-chain-attack-aqua-downstream-extortion-fallout\/\">Trivy in February<\/a>, TeamPCP\u2019s attacks have shaken that trust many times over.<\/p>\n<div class=\"ad ad--inline_1 \">\n<div class=\"ad__inner\"> <span class=\"screen-reader-text\">Advertisement<\/span> <\/div>\n<\/div>\n<p>The scale of TeamPCP\u2019s attacks lies partly in the automated systems companies use to deploy code, like CI\/CD pipelines. It is also capitalizing on new security gaps created by developers\u2019 increasing reliance on AI. Yet, with relatively low effort and unoriginal tactics, TeamPCP is wrecking open-source frameworks and underlying systems at levels the technology community has rarely reckoned with.<\/p>\n<p>\u201cDevelopers didn\u2019t do a great job of analyzing the security of their open-source dependencies before but, now with AI, there\u2019s in some cases virtually no human in the loop or any kind of sanity check on what these tools are doing,\u201d Feross Aboukhadijeh, founder and CEO at Socket, told CyberScoop.<\/p>\n<p>\u201cYou have agents installing packages that haven\u2019t been vetted,\u201d he said. \u201cWhen an attacker gets in, the impact is even broader because there\u2019s less checks and balances to stop it from affecting everybody.\u201d<\/p>\n<p>TeamPCP hasn\u2019t identified a new problem or proved anything novel. The crux of these attacks hinge on a central theme \u2014 defensive vulnerabilities the entire software industry has known about for years.&nbsp; Researchers and developers know the open source trust model is broken and susceptible to sabotage. Yet, the software industry has not fixed this problem.&nbsp;<\/p>\n<p>\u201cThe speed and scale of these attacks is what makes it most notable, not necessarily the methodology behind it, because at the core it is really about exploiting third-party trusts that we have,\u201d said Kimberly Goody, senior manager at Google Threat Intelligence Group.<\/p>\n<div class=\"ad ad--inline_1 \">\n<div class=\"ad__inner\"> <span class=\"screen-reader-text\">Advertisement<\/span> <\/div>\n<\/div>\n<p>Software packages are typically subjected to intensive security monitoring to test for vulnerabilities and poisoned updates before they are released to live environments.&nbsp;<\/p>\n<p>Yet, the real vulnerability highlighted by TeamPCP lies further up the chain of the command with the organizations or individuals that publish these packages to the wider market, according to Nathaniel Quist, manager of cloud threat intelligence at Palo Alto Networks.<\/p>\n<p>\u201cIt is their responsibility to secure their credentials and not provide a jump off point to trigger a supply-chain event,\u201d he said. \u201cEverything that interacts with or crosses through that zone must be highly monitored and controlled to ensure a compromise can be contained quickly and easily.\u201d<\/p>\n<h4 class=\"wp-block-heading\" id=\"h-teampcp-s-motivation\">TeamPCP\u2019s motivation<\/h4>\n<p>TeamPCP, like any prolific cybercriminal, has captured significant attention from threat hunters since it emerged in late 2025. Google attributes the activity to one core operator.<\/p>\n<div class=\"ad ad--inline_1 \">\n<div class=\"ad__inner\"> <span class=\"screen-reader-text\">Advertisement<\/span> <\/div>\n<\/div>\n<p>The company said it traced TeamPCP\u2019s residential and mobile IP address connections to South Africa, indicating the primary operator was located there during at least some of its attacks.<\/p>\n<p>\u201cWe don\u2019t believe that there\u2019s an established core group, at least not yet, and that a lot of this has been conducted by an individual,\u201d Goody said. Google declined to name the core operator or confirm it knows the person\u2019s true identity.&nbsp;<\/p>\n<p>Palo Alto Networks said the core manager of TeamPCP uses the \u201cResoluteXBF\u201d handle on multiple platforms. The cybersecurity firm is also tracking two additional core members: \u201cdiencracked\u201d and \u201cShinigami.\u201d<\/p>\n<p>If TeamPCP is primarily run by one person, law enforcement has a rare opportunity to make a lasting impact with a single arrest.<\/p>\n<p>TeamPCP has collaborated with other cybercriminals, but most of those partnerships were short-lived and ended in a public feud or otherwise failed to get off the ground in any meaningful way, Goody said.<\/p>\n<div class=\"ad ad--inline_1 \">\n<div class=\"ad__inner\"> <span class=\"screen-reader-text\">Advertisement<\/span> <\/div>\n<\/div>\n<p>Researchers have linked TeamPCP to extortion crews, dark web forums and affiliates including Lapsus$, ShinyHunters, Vect, DragonForce, BreachForums and \u201cHasanBroker.\u201d TeamPCP listed about 4,000 private code repositories on a dark web forum with an asking price of $95,000.<\/p>\n<p>The actions to date, including unpredictable behavior, indicate motivations beyond financial gain and a \u201cclear desire for notoriety,\u201d Goody said. \u201cThey seem to like to make chaos.\u201d<\/p>\n<p>Quist draws the same conclusion from his months-long investigation, noting that it encourages other cybercriminals to get in on the action, at one point offering financial rewards for the largest software supply-chain attack.&nbsp;<\/p>\n<p>TeamPCP isn\u2019t in the game for extortion payments, he said. \u201cThese actors are more interested in the underground street cred they are gaining\u201d and \u201ccausing as much damage and mayhem as possible.\u201d<\/p>\n<h4 class=\"wp-block-heading\" id=\"h-victims-abound-but-exposure-limited\">Victims abound, but exposure limited<\/h4>\n<div class=\"ad ad--inline_1 \">\n<div class=\"ad__inner\"> <span class=\"screen-reader-text\">Advertisement<\/span> <\/div>\n<\/div>\n<p>TeamPCP has been remarkably noisy, opportunistically injecting malware into open-source software for the purpose of stealing credentials for Kubernetes environments, Amazon Web Services, Microsoft Azure, Google Cloud and many other connected services.<\/p>\n<p>The group\u2019s claimed victim list is staggering: Checkmarx, Bitwarden, LiteLLM, Telnyx, Mercor AI, PyTorch Lightning, AntV, SAP, GitHub, TanStack, UiPath, MistralAI, Microsoft DurableTask, Red Hat and Nx Console.<\/p>\n<p>The full collection of packages compromised or poisoned by TeamPCP to date accounts for roughly 500 million weekly downloads combined, according to Quist.<\/p>\n<p>While the breadth of potential downstream compromise flowing from those downloads is substantial, many endpoints infected with those malware-riddled packages aren\u2019t exposed to the internet and less susceptible to attack, he added.<\/p>\n<p>\u201cI don\u2019t think there\u2019s going to be a very extremely large number of victims,\u201d Quist said. \u201cThere\u2019s going to be a lot of people who potentially could be compromised and have potentially vulnerable packages in their environment, but that doesn\u2019t necessarily mean they\u2019re in an exploitable position.\u201d<\/p>\n<div class=\"ad ad--inline_1 \">\n<div class=\"ad__inner\"> <span class=\"screen-reader-text\">Advertisement<\/span> <\/div>\n<\/div>\n<p>While these incidents have grabbed headlines, TeamPCP hasn\u2019t accumulated payouts nearly as large as other cybercriminals. The broader reputational impact it has wrought, however, is massive.<\/p>\n<p>TeamPCP has publicly claimed more than 10,000 victims and about $90,000 in extortions, according to Quist.<\/p>\n<p>\u201cThey might not be making a lot of money, but they are causing a lot of impact,\u201d Goody said. \u201cTheir campaigns have been very disruptive.\u201d<\/p>\n<h4 class=\"wp-block-heading\" id=\"h-how-teampcp-s-operating-model-targets-development\">How TeamPCP\u2019s operating model targets development<\/h4>\n<p>TeamPCP\u2019s victim list has grown as its hijacked open-source repositories on npm, PyPI, GitHub and other outsourced developer tools that are incorporated into upstream code running in production environments.<\/p>\n<div class=\"ad ad--inline_1 \">\n<div class=\"ad__inner\"> <span class=\"screen-reader-text\">Advertisement<\/span> <\/div>\n<\/div>\n<p>Developer laptops and other endpoints that are assigned to install, build and publish software widely contain keys and access to source code that create incredibly valuable supply-chain targets for attackers, Amitai Cohen, head of the attack vector intel team at Wiz, explained during a June presentation on TeamPCP at SleuthCon in Arlington, Va.&nbsp;<\/p>\n<p>The group targets CI runners, which are automated systems that build, test, and publish code. TeamPCP injects malware into the code repositories these runners maintain. When other developers pull that code into their own systems, they unknowingly download the malware alongside it.&nbsp;<\/p>\n<p>Some of these artifacts, including Python libraries, npm registries and GitHub Actions, are downloaded almost immediately by thousands or millions of developers who\u2019ve set their runners up to consistently pull the latest version, according to Cohen. \u201cWe as a security industry have taught them that that is the right thing to do. You want to use the latest version because you want to be protected against vulnerabilities, and obviously you want to benefit from all the latest features.\u201d<\/p>\n<p>That instinct is exactly what TeamPCP exploits. By compromising one company\u2019s CI\/CD workflow, the group gains access to every downstream user who automatically pulls that infected code. \u201cThis is what allows [TeamPCP] to leverage initial access to some patient zero, some company that had a vulnerability in their CI\/CD workflow, in order to gain access to their downstream users,\u201d Cohen said. \u201cThat\u2019s just how the software supply chain works. Everything has dependencies upon dependencies upon dependencies.\u201d<\/p>\n<p>Some of the packages compromised by TeamPCP were live for almost 13 hours, but security practitioners have responded by identifying code-injection attacks much quicker now, pulling some compromised repositories within 15 minutes, said Ben Read, director of strategic intelligence at Wiz.<\/p>\n<div class=\"ad ad--inline_1 \">\n<div class=\"ad__inner\"> <span class=\"screen-reader-text\">Advertisement<\/span> <\/div>\n<\/div>\n<p>The threat group\u2019s operations remain high-tempo. TeamPCP infects new software packages almost daily, validates compromises and captures sensitive data within 24 hours, according to Wiz researchers.<\/p>\n<p>The threat group has consistently evolved its tactics, developing payloads in JavaScript and Python while spreading from local files to Kubernetes application programming interfaces and bundled software development kits. Most recently, it\u2019s been stealing credentials via custom protocols.&nbsp;<\/p>\n<p>The group\u2019s ambitions have expanded beyond its own attacks. TeamPCP is also responsible for a self-replicating piece of malware known as <a href=\"https:\/\/cyberscoop.com\/mini-shai-hulud-supply-chain-malware-attack\/\">Mini Shai-Hulud<\/a>, which infected hundreds of software packages across open-source registries in <a href=\"https:\/\/cyberscoop.com\/mini-shai-hulud-malware-npm-packages-compromised-again\/\">back-to-back attack sprees<\/a> last month. A TeamPCP affiliate published the full source code for the malware on GitHub last month and encouraged other cybercriminals to use it for their own campaigns.<\/p>\n<p>\u201cTeamPCP is going for volume. They are not being discriminating, they\u2019re not necessarily trying to be stealthy or trying to maximize ROI. They\u2019re going for an all-of-the-above strategy,\u201d Read said during the Sleuthcon presentation.<\/p>\n<h4 class=\"wp-block-heading\" id=\"h-defensive-gaps-create-openings-for-attack\">Defensive gaps create openings for attack<\/h4>\n<p>TeamPCP\u2019s attack spree has also underscored how difficult it is for organizations to revoke compromised secrets. Multiple victims have experienced recurring infections, sometimes falling prey to TeamPCP three times within a month, because they didn\u2019t rotate secrets properly, Cohen said.&nbsp;<\/p>\n<div class=\"ad ad--inline_1 \">\n<div class=\"ad__inner\"> <span class=\"screen-reader-text\">Advertisement<\/span> <\/div>\n<\/div>\n<p>At its core, these attacks highlight a direct trade-off organizations accept when they update software quickly to fix vulnerabilities, but learn that doing so too quickly could expose them to illegitimate registries containing malware.<\/p>\n<p>TeamPCP has targeted what Aboukhadijeh describes as a \u201cpublic good,\u201d open-source registries that were never perfect but widely trusted and rarely turned into a point of entry for supply-chain attacks.&nbsp;<\/p>\n<p>Rapid open source software installation is one of the most dangerous things an organization can do right now, he said, adding that there\u2019s a roughly 1 in 10 chance that any package installed by an organization could trigger an active attack.&nbsp;<\/p>\n<p>TeamPCP has compromised security scanners, password managers, automation tools, data visualization software, and CI\/CD infrastructure across various environments.<\/p>\n<p>And it\u2019s lifted a trove of credentials and other sensitive data from victims.<\/p>\n<div class=\"ad ad--inline_1 \">\n<div class=\"ad__inner\"> <span class=\"screen-reader-text\">Advertisement<\/span> <\/div>\n<\/div>\n<p>Researchers like Cohen at Wiz, who have been tracking this attack spree since the beginning, are nearing a breaking point.&nbsp;<\/p>\n<p>\u201cThis is also too hard on us. We\u2019re very tired. I\u2019m sure a lot of people working on this problem space are very tired, and it\u2019s just kind of become untenable,\u201d Cohen said.<\/p>\n<p>\u201cYou can\u2019t keep existing in a world where you wake up every morning and some super prevalent package is compromised and everybody\u2019s just going to be using it like nothing,\u201d he added. \u201cWe need to start taking this a bit more seriously.\u201d<\/p>\n<p><\/body> <\/p>\n<footer class=\"single-article__footer\" readability=\"2.3899253731343\">\n<div class=\"author-card\" readability=\"14\">\n<div class=\"author-card__avatar\">\n<figure class=\"author-card__image-wrap\"> <img data-recalc-dims=\"1\" decoding=\"async\" class=\"author-card__image\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2026\/06\/how-software-developments-speed-obsession-enabled-teampcps-chaos-crusade-1.jpg?w=640&#038;ssl=1\" alt=\"Matt Kapko\"> <\/figure>\n<\/p><\/div>\n<p><h4 class=\"author-card__name\">Written by Matt Kapko<\/h4>\n<p> Matt Kapko is a reporter at CyberScoop. His beat includes cybercrime, ransomware, software defects and vulnerability (mis)management. The lifelong Californian started his journalism career in 2001 with previous stops at Cybersecurity Dive, CIO, SDxCentral and RCR Wireless News. Matt has a degree in journalism and history from Humboldt State University. <\/p>\n<\/p><\/div>\n<div class=\"single-article__tags-container\">\n<h4 class=\"single-article__tags-title\">In This Story<\/h4>\n<\/p><\/div>\n<\/footer>\n<p> <\/html><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"single-article__ads js-single-article-sidebar\">\n<div class=\"ad ad--sidebar js-single-article-sidebar-5 ad--rightrail_1 \">\n<div class=\"ad__inner\"> <span class=\"screen-reader-text\">Advertisement<\/span> <\/div>\n<\/div>\n<div class=\"ad ad--sidebar js-single-article-sidebar-4 ad--rightrail_2 \">\n<div class=\"ad__inner\"> <span class=\"screen-reader-text\">Advertisement<\/span> <\/div>\n<\/div>\n<div class=\"ad ad--sidebar js-single-article-sidebar-3 ad--rightrail_3 \">\n<div class=\"ad__inner\"> <span class=\"screen-reader-text\">Advertisement<\/span> <\/div>\n<\/div><\/div>\n<\/article>\n<div class=\"popular-stories popular-stories--single-post\">\n<div class=\"popular-stories__container\">\n<h2 class=\"popular-stories__title\"> More Scoops <\/h2>\n<p> <!-- .popular-stories__stories --> <\/div>\n<p><!-- .popular-stories__inner -->\n<\/div>\n<p><!-- .popular-stories --> <\/p>\n<section class=\"latest-podcasts\">\n<h2 class=\"latest-podcasts__title\"> Latest Podcasts\t<\/h2>\n<\/section>\n<div class=\"top-categories\">\n<div class=\"top-categories__container\">\n<h3 class=\"top-categories__category-title\">Government<\/h3>\n<\/p><\/div>\n<div class=\"top-categories__container\">\n<h3 class=\"top-categories__category-title\">Technology<\/h3>\n<\/p><\/div>\n<\/p><\/div>\n<p> <\/main> <\/p>\n<div class=\"ad ad--bottom \">\n<div class=\"ad__inner\"> <span class=\"screen-reader-text\">Advertisement<\/span> <\/div>\n<\/div>\n<div id=\"interstitial\" class=\"welcome__container\"> <button id=\"close-modal-1\" class=\"welcome__clickable_area\"><\/button> <\/p>\n<div class=\"welcome__ad_wrapper\">\n<p> <button id=\"close-modal-3\" class=\"welcome__continue-button\">Continue to CyberScoop<\/button> <\/p>\n<\/p><\/div>\n<\/p><\/div>\n<p> <!-- Start of HubSpot Embed Code --> <!-- End of HubSpot Embed Code --> <\/body> <a href=\"https:\/\/cyberscoop.com\/teampcp-breaks-open-source-software-trust-model\/\">Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>How software development&#8217;s speed obsession enabled TeamPCP\u2019s chaos crusade |<\/p>\n","protected":false},"author":11,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[6876,6877,6878,5419,282,78,1807,323,725,387,3729,6879,6880,6881,6597,4446,6882,1073,3288,715,6883,6884,6885,46,2767,4197,2151,2095,3876,1813,1866,649,6886,6697,6887,288,6274,6571,6888,3610],"tags":[6889,6890,6891,5429,286,86,1810,327,728,391,3731,6892,6893,6894,6600,4448,6895,1076,3290,720,6896,6897,6898,54,2768,4198,2155,2098,3878,1814,1868,652,6899,6698,6900,294,6276,6572,6901,3613],"class_list":["post-8756","post","type-post","status-publish","format-standard","hentry","category-antv","category-bitwarden","category-checkmarx","category-ci-cd","category-cybercrime","category-cybersecurity","category-exclusive","category-extortion","category-github","category-google","category-google-threat-intelligence-group","category-litellm","category-mercer-ai","category-microsoft-durabletask","category-mini-shai-hulud","category-mistral-ai","category-nx-console","category-open-source","category-open-source-software","category-palo-alto-networks","category-pypi","category-python","category-pytorch-lightning","category-ransomware","category-red-hat","category-sap","category-shinyhunters","category-sleuthcon","category-socket","category-supply-chain","category-supply-chain-attacks","category-supply-chain-security","category-tanstack","category-teampcp","category-telnyx","category-threats","category-trivy","category-uipath","category-vect","category-wiz","tag-antv","tag-bitwarden","tag-checkmarx","tag-ci-cd","tag-cybercrime","tag-cybersecurity","tag-exclusive","tag-extortion","tag-github","tag-google","tag-google-threat-intelligence-group","tag-litellm","tag-mercer-ai","tag-microsoft-durabletask","tag-mini-shai-hulud","tag-mistral-ai","tag-nx-console","tag-open-source","tag-open-source-software","tag-palo-alto-networks","tag-pypi","tag-python","tag-pytorch-lightning","tag-ransomware","tag-red-hat","tag-sap","tag-shinyhunters","tag-sleuthcon","tag-socket","tag-supply-chain","tag-supply-chain-attacks","tag-supply-chain-security","tag-tanstack","tag-teampcp","tag-telnyx","tag-threats","tag-trivy","tag-uipath","tag-vect","tag-wiz"],"featured_image_urls":{"full":"","thumbnail":"","medium":"","medium_large":"","large":"","1536x1536":"","2048x2048":"","chromenews-featured":"","chromenews-large":"","chromenews-medium":""},"author_info":{"display_name":"Cyber Scoop","author_link":"https:\/\/ddi.mohflo.net\/index.php\/author\/cyberscoop\/"},"category_info":"<a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/antv\/\" rel=\"category tag\">AntV<\/a> <a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/bitwarden\/\" rel=\"category tag\">Bitwarden<\/a> <a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/checkmarx\/\" rel=\"category tag\">Checkmarx<\/a> <a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/ci-cd\/\" rel=\"category tag\">CI\/CD<\/a> <a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/cybercrime\/\" rel=\"category tag\">cybercrime<\/a> <a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/cybersecurity\/\" rel=\"category tag\">Cybersecurity<\/a> <a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/exclusive\/\" rel=\"category tag\">Exclusive<\/a> <a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/extortion\/\" rel=\"category tag\">extortion<\/a> <a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/github\/\" rel=\"category tag\">GitHub<\/a> <a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/google\/\" rel=\"category tag\">Google<\/a> <a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/google-threat-intelligence-group\/\" rel=\"category tag\">Google Threat Intelligence Group<\/a> <a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/litellm\/\" rel=\"category tag\">LiteLLM<\/a> <a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/mercer-ai\/\" rel=\"category tag\">Mercer AI<\/a> <a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/microsoft-durabletask\/\" rel=\"category tag\">Microsoft DurableTask<\/a> <a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/mini-shai-hulud\/\" rel=\"category tag\">mini shai hulud<\/a> <a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/mistral-ai\/\" rel=\"category tag\">Mistral AI<\/a> <a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/nx-console\/\" rel=\"category tag\">Nx Console<\/a> <a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/open-source\/\" rel=\"category tag\">open source<\/a> <a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/open-source-software\/\" rel=\"category tag\">open source software<\/a> <a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/palo-alto-networks\/\" rel=\"category tag\">Palo Alto Networks<\/a> <a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/pypi\/\" rel=\"category tag\">PyPI<\/a> <a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/python\/\" rel=\"category tag\">Python<\/a> <a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/pytorch-lightning\/\" rel=\"category tag\">PyTorch Lightning<\/a> <a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/ransomware\/\" rel=\"category tag\">ransomware<\/a> <a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/red-hat\/\" rel=\"category tag\">Red Hat<\/a> <a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/sap\/\" rel=\"category tag\">SAP<\/a> <a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/shinyhunters\/\" rel=\"category tag\">ShinyHunters<\/a> <a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/sleuthcon\/\" rel=\"category tag\">Sleuthcon<\/a> <a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/socket\/\" rel=\"category tag\">Socket<\/a> <a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/supply-chain\/\" rel=\"category tag\">supply chain<\/a> <a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/supply-chain-attacks\/\" rel=\"category tag\">supply chain attacks<\/a> <a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/supply-chain-security\/\" rel=\"category tag\">supply chain security<\/a> <a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/tanstack\/\" rel=\"category tag\">TanStack<\/a> <a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/teampcp\/\" rel=\"category tag\">TeamPCP<\/a> <a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/telnyx\/\" rel=\"category tag\">Telnyx<\/a> <a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/threats\/\" rel=\"category tag\">Threats<\/a> <a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/trivy\/\" rel=\"category tag\">Trivy<\/a> <a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/uipath\/\" rel=\"category tag\">UiPath<\/a> <a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/vect\/\" rel=\"category tag\">Vect<\/a> <a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/wiz\/\" rel=\"category tag\">Wiz<\/a>","tag_info":"Wiz","comment_count":"0","jetpack_featured_media_url":"","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/8756","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/users\/11"}],"replies":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/comments?post=8756"}],"version-history":[{"count":0,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/8756\/revisions"}],"wp:attachment":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media?parent=8756"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/categories?post=8756"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/tags?post=8756"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}