The Case of TeamPCP, King of Software Supply Chain Attacks
# The Story of TeamPCP, the King of Software Supply Chain Attacks In just five days in March 2026, a stolen service account token allowed a hacker group to contaminate five software ecosystems simultaneously. One of the infected packages had as many as 95 million downloads per month. The attack started with a poorly configured GitHub Actions workflow, and its end result was backdoored code scattered across global CI/CD pipelines. Recently, the two core members behind this attack were arrested by Australian police. A detailed investigation report fully explains how they used seemingly ordinary aliases, publicly available information, leaked credentials, and cross-platform account associations to anonymize the core members of TeamPCP, who were known as the king of software supply chain attacks. Many people think that hackers can hide behind fake internet names and become impossible to track, but the case of TeamPCP shows that as long as attackers leave traces on multiple platforms, reuse avatars, usernames, passwords, or domain names, security researchers can piece together these fragments like a puzzle to form a complete picture...