Advertisement
Advertisement
Advertisement
5 August 2026·5 min read·By Sloane Meyer

What TeamPCP Really Means for Buyers

The threat actor TeamPCP has been active since 2020. Learn what their evolution and use of AI means for open-source software security.

What TeamPCP Really Means for Buyers

TeamPCP is a long-standing threat to your digital security

TeamPCP is not a new arrival in the world of cyber threats. While many hunters only caught on to this group recently, new evidence shows they have been active since 2020. They are not just random hackers. They are a persistent force that has spent years targeting open-source software and your infrastructure.

What the history of TeamPCP reveals

You might think of cyber threats as sudden, explosive events. But for this group, it has been a slow and steady climb. They spent years building their presence, eventually moving into high-speed, noisy campaigns.

Market Context: According to SentinelOne, weekly volumes of cyber attacks hit an average of 1,968 per week in 2026, highlighting an 18% year-over-year increase from 2025, and a 70% hike since 2023.
They are not trying to hide their identity anymore. In fact, they have used their own official GitHub profile to list domains linked to their operations.

The group operates under various names to mask its long-term activity. It’s a simple trick, but it works. Researchers have linked this actor to several identities, including TA-NATALSTATUS and IronErn, and they’ve consistently recycled the same infrastructure to conduct their work, which includes a familiar set of tools and tactics that security teams have seen before. So don’t expect the names to change the game. They don’t.

  • IP addresses used across multiple years of attacks
  • Domain names that link current campaigns to older ones
  • Shared file servers for storing malicious payloads
  • Command-and-control servers used to direct their botnets

The rise of automated attacks

The most alarming shift is how fast these attackers move today. In late 2025, the group exploited a ShadowRay vulnerability to launch the first self-propagating botnet on hijacked AI infrastructure. The payloads these attackers use now change in real time to adapt to the environments they enter. This is not a manual process. It is the result of using AI to automate the chaos.

red padlock on black computer keyboard

Uri Katz, a director of research, noted the shift in tactics:

The scariest thing in this campaign is the speed at which the payloads evolved and changed and adapted to the environment they run in. We saw changes in the speed that we're not used to seeing in these kinds of attacks. They're usually slow, careful. This was clearly with the help of AI , the payloads changed rapidly to adjust and change to the environment that they were trying to attack.

What this means for your workflow

If you rely on open-source software, you need to pay attention. Most modern AI infrastructure depends on these open-source frameworks because they are faster and cheaper than building from scratch. This creates a massive trust gap. Developers often grab these tools without realizing the security burden falls entirely on them. If you do not have visibility into how these tools behave, you are leaving the door wide open.

The reality of AI-driven threats

Businesses are currently in a race to adopt AI. The fear of being left behind is driving this speed. Attackers know this and are using the exact same technology to exploit the gaps in your deployment systems. They are not just breaking code. They are breaking the frameworks that support the code.

Gal Elbaz, a co-founder and CTO, highlighted the risk of this race:

All of the companies in the world are in this race to adopt AI because they are afraid their business will die, and they understand, of course, the opportunity. But it's also what gives the attacker this power to go into it. If you don't really have visibility in what's going on there or how it behaves, that's exactly what attackers are after.

Why your security strategy must change

TeamPCP has already compromised more than 1,000 software packages in less than four months. This is not just a statistical anomaly. It is a sign of a shift in how attackers view open-source trust. They are no longer looking for one lucky break. They are looking to wreck the entire foundation of the software you trust.

The threat is likely bigger than what has been caught so far. That's the most important thing to understand. There's a high probability that other attacks are currently active or remain completely undetected, so if you're using automated systems to deploy code, you need to verify exactly what is running inside those containers, and you can't assume your tools are safe just because they're popular. But don't stop there. Check every layer.

The era of slow, manual security checks is over. It's dead. These attackers are using AI to pivot, change, and hide, and they're doing it at machine speed, which means they can rewrite their tactics in the time it takes you to finish your coffee and re-read a single alert. But if your security visibility can't match that speed, you're already behind. So don't wait.

Frequently Asked Questions

What is TeamPCP and how long have they been active according to the article?

TeamPCP is a cyber threat group that has been active since 2020. The article says they are a persistent force that has spent years targeting open-source software and infrastructure.

Why are TeamPCP's attacks considered a shift in how attackers view open-source trust?

TeamPCP has compromised over 1,000 software packages in less than four months, indicating they are no longer looking for a lucky break but aiming to wreck the foundation of trusted software. The article states this is a sign of a shift in how attackers view open-source trust.

How have TeamPCP's tactics evolved in late 2025, according to the article?

In late 2025, TeamPCP exploited a ShadowRay vulnerability to launch the first self-propagating botnet on hijacked AI infrastructure. Their payloads now change in real time using AI, adapting quickly to environments, which was noted as alarming and fast.

When did TeamPCP start their activities, and what does the article say about their identity masking?

TeamPCP has been active since 2020, though many only recently caught on. They operate under various names like TA-NATALSTATUS and IronErn, and they've recycled the same infrastructure to mask long-term activity.

Who are the researchers quoted in the article, and what do they say about TeamPCP's speed and the AI race?

Uri Katz, a director of research, noted the scariest thing is the speed of payload evolution, aided by AI. Gal Elbaz, co-founder and CTO, highlighted that the race to adopt AI gives attackers power, especially when there's no visibility into what's happening.

Sloane Meyer
Written by
Cybersecurity Editor

Sloane Meyer covers cybersecurity, privacy and the threats facing individuals and organisations online. She explains how attacks happen and what can be done to stay protected.

💬 Comments (0)

Sign in to leave a comment.

No comments yet. Be the first!

Advertisement