CYBERSECURITYTRACKER
TRACKING7,159 stories in this site build1,507 vulnerability news stories in this site build
Permanent story citation

Open-source software’s archenemy TeamPCP goes back further than anyone thought

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 3896

As cited

Copy frozen at (site build).

threat intel

Open-source software’s archenemy TeamPCP goes back further than anyone thought

Oligo Security research reveals that TeamPCP, the threat actor responsible for compromising over 1,000 open-source packages in 2025, has been active since at least 2020 under various tracked names including TA-NATALSTATUS and IronErn. The group has leveraged artificial intelligence to rapidly evolve malware payloads and orchestrate attacks across hijacked infrastructure, including a late 2025 campaign that created a self-propagating botnet targeting AI systems. TeamPCP's shift to high-volume, publicly visible campaigns coincided with widespread AI adoption, exploiting security gaps in developers' increasing reliance on automated deployment systems and open-source components.

Why it matters: Developers and security teams managing open-source dependencies face ongoing risk from a sophisticated, AI-augmented threat actor with a five-year operational history and demonstrated ability to compromise software supply chains at scale; immediate visibility into third-party package integrity and infrastructure behavior is critical to prevent code injection attacks.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

Open-source software’s archenemy TeamPCP goes back further than anyone thought

Oligo Security research reveals that TeamPCP, the threat actor responsible for compromising over 1,000 open-source packages in 2025, has been active since at least 2020 under various tracked names including TA-NATALSTATUS and IronErn. The group has leveraged artificial intelligence to rapidly evolve malware payloads and orchestrate attacks across hijacked infrastructure, including a late 2025 campaign that created a self-propagating botnet targeting AI systems. TeamPCP's shift to high-volume, publicly visible campaigns coincided with widespread AI adoption, exploiting security gaps in developers' increasing reliance on automated deployment systems and open-source components.

Why it matters: Developers and security teams managing open-source dependencies face ongoing risk from a sophisticated, AI-augmented threat actor with a five-year operational history and demonstrated ability to compromise software supply chains at scale; immediate visibility into third-party package integrity and infrastructure behavior is critical to prevent code injection attacks.

VendorsGitHub
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary