← Back to feed
Threat Actors & CampaignsEmerging1 sourceAug 27, 2026 · 11:26via Flare

Unmasking TeamPCP, King of Software Supply Chain Attacks

Brief

A walkthrough of the process of deanonymization

By Flare’s Emerging Threats Team

For five days in March 2026, a single stolen token let one group poison five software ecosystems including a package downloaded 95 million times a month. The attack started with a misconfigured GitHub Actions workflow, and ended with backdoored code sitting inside CI/CD pipelines around the world.

Today, two people behind this attack were arrested . TeamPCP , allegedly operated by these threat actors, started attacks in late 2025 running opportunistic cloud exploits, then pivoted in early 2026 to targeting the software supply chain itself.

Read more on Flare