Unmasking TeamPCP, King of Software Supply Chain Attacks
Brief
A walkthrough of the process of deanonymization
By Flare’s Emerging Threats Team
For five days in March 2026, a single stolen token let one group poison five software ecosystems including a package downloaded 95 million times a month. The attack started with a misconfigured GitHub Actions workflow, and ended with backdoored code sitting inside CI/CD pipelines around the world.
Today, two people behind this attack were arrested . TeamPCP , allegedly operated by these threat actors, started attacks in late 2025 running opportunistic cloud exploits, then pivoted in early 2026 to targeting the software supply chain itself.
