TeamPCP (Miasma variant)
Criminal threat actor — derived from TeamPCP (UNC6780) tooling, assessed as semi-independent · Financial — supply chain compromise and credential theft
Tactics, Techniques & Procedures (TTPs)
- Miasma self-replicating supply chain worm — derived from Mini Shai-Hulud, released as open-source by TeamPCP (UNC6780) on BreachForums
- Targeting of GitHub repositories via retained developer credentials from the May 2026 TeamPCP compromise
- Compromise of core Azure SDK repositories including durabletask, Azure Functions, and AI integration packages
- Credential theft from compromised developer environments for subsequent repository access
- Worm propagation across connected repository ecosystems without requiring direct exploitation
Known Targets
Analyst Notes
The Miasma variant emerged after TeamPCP (UNC6780) publicly released the Mini Shai-Hulud worm source code on BreachForums in mid-May 2026, inviting copycat use. The June 2026 compromise of 73 Microsoft GitHub repositories — including core Azure SDK components — represents the proliferation risk that open-sourcing the worm created. The re-compromise of the durabletask repository (also affected in May) indicates Microsoft did not fully rotate credentials from the initial breach. Operating semi-independently of the original TeamPCP operation; the worm's open-source status means attribution to a specific actor becomes increasingly difficult as derivative campaigns multiply across PyPI, Go modules, and NuGet ecosystems.
Also Known As