DMZ//THREAT INTEL
FEED ACTIVELAST SYNC: 06:13:27ZSOURCES: 14CRITICAL: 30
⚠ ACTIVE ALERTS
@FalconFeedsio CRITICAL — 🚨 Ransomware Alert: The Gentlemen RaaS group continues active DLS postings. Now at 478… /// @DarkWebInformer CRITICAL — 🚨 ServiceNow discloses June 5 security update tied to anomalous activity — KB3067321.… /// @MsftSecIntel CRITICAL — MSTIC analysis of The Gentlemen ransomware (tracked internally): self-propagating… /// @GossiTheDog CRITICAL — ServiceNow KB3067321 situation is worse than the vendor comms suggest. Advisory was gated… /// @AlvieriD CRITICAL — The '340M OnlyFans' listing on the leak forum is a compiled corpus — seller confirmed to…
30Critical Threats
15Active CVEs
1IOCs Tracked
14New Advisories
TLP:WHITETHREAT ACTOR DOSSIER // TEAMPCPFIRST SEEN: SEP 2025

TEAMPCPCP

ALSO KNOWN AS: TeamPCP
FROM:DMZ INTELLIGENCE DESK
ORIGIN:Unknown (code includes logic excluding Russian-language environments suggesting non-CIS operator)
ATTRIBUTION:ORGANIZED CRIME
STATUS:ACTIVE
FIRST OBSERVED:SEP 2025
TECHNICALRESOURCESPERSISTENCESTEALTHIMPACT
TECHNICAL85/100
RESOURCES85/100
PERSISTENCE88/100
STEALTH80/100
IMPACT94/100

TeamPCP is a highly sophisticated criminal threat actor responsible for the ongoing Shai-Hulud supply chain worm campaign, the most technically advanced open-source supply chain attack series documented to date. The May 2026 'Mini Shai-Hulud' wave compromised 172+ npm and PyPI packages across 518 million cumulative downloads—including TanStack, Mistral AI, UiPath, OpenSearch, and OpenAI packages—by defeating SLSA Build Level 3 provenance attestations through GitHub Actions CI cache-poisoning rather than signature forgery. The group has confirmed partnerships feeding harvested credentials to the Vect RaaS operation and LAPSUS$ extortion group, and on May 13, 2026 open-sourced the Shai-Hulud worm on BreachForums, transforming into a platform operation with affiliate contest mechanics targeting the AI developer toolchain.

Financial gain via large-scale developer and cloud credential theft fed into downstream ransomware (Vect RaaS) and extortion (LAPSUS$) monetization pipelines

T1195.001 Compromise Software Dependencies (npm/PyPI poisoning), T1552.001 Credentials in Files (CI/CD secret harvesting), T1528 Steal Application Access Token (OIDC token extraction from GitHub Actions runner memory), T1053 Scheduled Task Persistence (.claude/settings.json hooks, VS Code tasks, system daemons), T1071 C2 via HTTPS (git-tanstack[.]com), T1027 Obfuscated Payload (SLSA attestation abuse), T1119 Automated Collection, T1567 Exfiltration to C2

SOFTWARE SUPPLY CHAIN
DEVELOPER TOOLING
CLOUD INFRASTRUCTURE
AI/ML TOOLING
CI/CD PIPELINES
OPEN SOURCE ECOSYSTEMS

Shai-Hulud / Mini Shai-Hulud self-propagating worm (npm+PyPI), GitHub Actions cache-poisoning exploit chain, OIDC token exchange abuse, Claude Code startup hook persistence, git-tanstack[.]com C2 domain, Hugging Face malicious model distribution, ClawHub AI agent registry poisoning (341 entries), Vect RaaS partnership, LAPSUS$ EaaS partnership; ~300 GB credentials + 500,000+ cloud tokens exfiltrated in prior waves

FILE DATE: SEP 2025
Shai-Hulud v1 – Initial Supply Chain Campaign
First wave of npm/PyPI supply chain poisoning targeting developer credentials and cloud tokens; linked to Trivy and Checkmarx breaches.
FILE DATE: MAY 2026
Mini Shai-Hulud – TanStack/AI Ecosystem Wave
Compromised 172 packages across 518M cumulative downloads including TanStack, Mistral AI, ██████████████████ packages by defeating SLSA Build Level 3 attestations via CI cache poisoning; first documented SLSA bypass in a live attack.
FILE DATE: MAY 2026
AntV Ecosystem Compromise
Published 300+ malicious package versions across 323 AntV data visualization packages (~16M weekly downloads) in a 22-minute automated burst on May 19, 2026 via compromised npm maintainer account.
FILE DATE: MAY 2026
Shai-Hulud Open-Source Release
On May 13, 2026 TeamPCP open-sourced the Shai-Hulud 3.0 worm on BreachForums/GitHub and launched a public affiliate contest, democratizing the attack tooling and enabling third-party ██████████████████████ days.
SHARE BRIEF:✕ Post on Xin Share on LinkedIn