TeamPCP infiltrated open-source packages as early as 2020
The methodology hasn't changed since 2020. AI-accelerated payload evolution turned quiet persistence into a supply-chain wrecking ball.
TL;DR
TeamPCP has been active since at least 2020 (not late 2025 as previously believed) according to research Oligo Security shared exclusively with CyberScoop. The group's infrastructure links its recent high-profile package compromises to a 2025 ShadowRay campaign that spawned the first self-propagating botnet on hijacked AI infrastructure, and to earlier activity tracked as TA-NATALSTATUS and IronErn. The methodology hasn't changed: exploit the open-source trust model. What changed is AI-driven payload evolution that adapts mid-campaign at speeds defenders aren't used to seeing. The group's GitHub profile publicly contained one of the domains Oligo flagged. "They're not even trying to hide their identity," one researcher said.
The timeline revision matters for threat hunters. If TeamPCP was active in 2020, its compromises predate most organizations' current detection windows. The group spent five years operating quietly under multiple aliases before emerging as a brand in late 2025 and shifting to high-volume, noisy campaigns.
Oligo's researchers traced the lineage through IP addresses, domain registrations, and command-and-control infrastructure. One domain, identified in July 2025, sat in the profile of TeamPCP's official GitHub account, publicly visible. The earlier activity was tracked by other firms as TA-NATALSTATUS and IronErn, but the infrastructure ties it together. "They're not even trying to hide their identity," said Avi Lumelsky, an AI security researcher at Oligo.
What AI changed
The methodology across all campaigns is consistent: exploit the open-source trust model, poison packages that CI/CD pipelines ingest automatically, and move laterally through developer credentials. None of this is novel. What distinguishes the 2026 campaigns is payload evolution speed.
"The scariest thing in this campaign is the speed at which the payloads evolved and changed and adapted to the environment they run in," said Uri Katz, Oligo's director of research. "We saw changes in the speed that we're not used to seeing in these kinds of attacks. This was clearly with the help of AI."
The ShadowRay 2.0 campaign, which Oligo now links to TeamPCP, produced the first self-propagating botnet running on hijacked AI infrastructure. That campaign bridged the group's quieter early years to the noisy, brand-conscious campaigns of 2026.
The trust model hasn't moved
TeamPCP's persistence underscores an uncomfortable fact: the open-source trust model, where developers pull dependencies they haven't vetted and CI/CD pipelines build and ship without human review, hasn't been fixed. AI has widened the gap. Developers are in a race to adopt AI because they're afraid their business will die, said Gal Elbaz, Oligo's co-founder and CTO. "If you don't really have visibility in what's going on there or how it behaves, that's exactly what attackers are after."
Five years of the same basic exploit, accelerating only with better automation. The defenders haven't caught up.
Published ·Updated ·Deep Fathom