AuraTracer智迹闻
中文

EVENT DOSSIER

“The story of TeamPCP, the king of software supply chain attacks, getting caught”

2026-09-02 08:00 Cybersecurity 🔥 28.9 heat score
1sources
1days unfolding
28.9heat score
8mentions
SummaryAI generated

The Chinese police successfully uncovered a software supply chain attack case, identifying and capturing the overseas hacker group TeamPCP. This group implanted malicious code through the supply chain to attack multiple software products, affecting various industries. The police have initially identified their attack methods and tactics, and relevant technical details are being further analyzed.

Related eventsRELATED EVENTS
Key entitiesKEY ENTITIES
Aqua SecurityFBIFlareGitHubLiteLLMRuben ThomsonTeamPCPTrivy

Coverage · reports per dayLANGUAGE SPLIT

Entity relations
Aqua Security × FBI1Aqua Security × Flare1Aqua Security × GitHub1Aqua Security × LiteLLM1Aqua Security × Ruben T…1FBI × Flare1

SignalsSIGNALS

Keyword heat
  • TeamPCP1
  • FBI1
  • GitHub1
  • Aqua Security1
  • Trivy1
  • LiteLLM1
  • Flare1
  • Ruben Thomson1

All reports (1)SOURCES

安全内参 zh 2026-09-02 08:00

The Case of TeamPCP, King of Software Supply Chain Attacks

# The Story of TeamPCP, the King of Software Supply Chain Attacks In just five days in March 2026, a stolen service account token allowed a hacker group to contaminate five software ecosystems simultaneously. One of the infected packages had as many as 95 million downloads per month. The attack started with a poorly configured GitHub Actions workflow, and its end result was backdoored code scattered across global CI/CD pipelines. Recently, the two core members behind this attack were arrested by Australian police. A detailed investigation report fully explains how they used seemingly ordinary aliases, publicly available information, leaked credentials, and cross-platform account associations to anonymize the core members of TeamPCP, who were known as the king of software supply chain attacks. Many people think that hackers can hide behind fake internet names and become impossible to track, but the case of TeamPCP shows that as long as attackers leave traces on multiple platforms, reuse avatars, usernames, passwords, or domain names, security researchers can piece together these fragments like a puzzle to form a complete picture...