Skip to content

Details

Title: The Rise and Fall of TeamPCP: The most productive software supply chain threat actor ever - speaker Paul McCarty

Abstract:
TeamPCP is a financially motivated cybercrime group that emerged in late 2025 and became one of the most prolific actors targeting the open-source software supply chain. The group specializes in compromising developer accounts, GitHub repositories, CI/CD pipelines, and package-publishing infrastructure to inject credential-stealing malware into legitimate npm and PyPI packages. During 2026, TeamPCP dramatically scaled its operations through Mini Shai-Hulud, a self-propagating supply-chain worm that steals GitHub, package-registry, cloud, and developer credentials and then uses that access to compromise additional projects, creating cascading infections. Its campaigns have affected hundreds of packages and prominent developer and security tooling, while the group has also engaged in data theft, extortion, cryptocurrency theft, partnerships with other cybercriminal groups, and eventually released its own malware source code to encourage further supply-chain compromises.

This talk will dive into what made TeamPCP such a powerful milestone in the history of software supply chain attacks. Paul will share details about the case that have never been published before, as well as his own case notes and tracking.

Drinks are provided by our sponsor, Solis, and pizza is provided by Cyber Audit Team. As usual, our venue is sponsored by COHORT.

GC SecTalks maintains a strict Code of Conduct.

Related topics

Events in Southport
Application Security
Cloud Security
Cybersecurity
Web Application Security
Information Security

You may also like