As cited
Copy frozen at (site build).
threat intel
Open-source software’s archenemy TeamPCP goes back further than anyone thought
Oligo Security research reveals that TeamPCP, the threat actor responsible for compromising over 1,000 open-source packages in 2025, has been active since at least 2020 under various tracked names including TA-NATALSTATUS and IronErn. The group has leveraged artificial intelligence to rapidly evolve malware payloads and orchestrate attacks across hijacked infrastructure, including a late 2025 campaign that created a self-propagating botnet targeting AI systems. TeamPCP's shift to high-volume, publicly visible campaigns coincided with widespread AI adoption, exploiting security gaps in developers' increasing reliance on automated deployment systems and open-source components.
Why it matters: Developers and security teams managing open-source dependencies face ongoing risk from a sophisticated, AI-augmented threat actor with a five-year operational history and demonstrated ability to compromise software supply chains at scale; immediate visibility into third-party package integrity and infrastructure behavior is critical to prevent code injection attacks.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
threat intel
Open-source software’s archenemy TeamPCP goes back further than anyone thought
Oligo Security research reveals that TeamPCP, the threat actor responsible for compromising over 1,000 open-source packages in 2025, has been active since at least 2020 under various tracked names including TA-NATALSTATUS and IronErn. The group has leveraged artificial intelligence to rapidly evolve malware payloads and orchestrate attacks across hijacked infrastructure, including a late 2025 campaign that created a self-propagating botnet targeting AI systems. TeamPCP's shift to high-volume, publicly visible campaigns coincided with widespread AI adoption, exploiting security gaps in developers' increasing reliance on automated deployment systems and open-source components.
Why it matters: Developers and security teams managing open-source dependencies face ongoing risk from a sophisticated, AI-augmented threat actor with a five-year operational history and demonstrated ability to compromise software supply chains at scale; immediate visibility into third-party package integrity and infrastructure behavior is critical to prevent code injection attacks.
- Source published
- First seen by Cybersecurity Tracker