TeamPCP (UNC6780)
Criminal threat actor (Eastern Europe assessed) · Financial -- credential theft and extortion
Tactics, Techniques & Procedures (TTPs)
- GitHub Actions OIDC token abuse via pull_request_target workflow misconfiguration
- Build cache poisoning for trusted npm package publication under legitimate maintainer identity
- Mini Shai-Hulud self-propagating npm worm targeting JavaScript ecosystem
- Credential sweep covering 130 file paths (SSH keys, cloud credentials, API tokens, kubeconfigs)
- Open-source worm publication and BreachForums contest to enable copycat campaigns
- Python backdoor polling GitHub repository for signed C2 messages
- Extortion demands post-compromise
Known Targets
Analyst Notes
Responsible for the Mini Shai-Hulud npm supply chain campaign, May 2026 -- one of the most consequential developer supply chain attacks on record. The attack chain (GitHub Actions misconfiguration → build cache poisoning → OIDC token extraction → trusted npm publication) required no stolen credentials. CISA issued three CVEs with expedited remediation deadlines. The open-sourcing of the worm under MIT licence, combined with a $1,000 BreachForums contest for copycat attacks, transforms this from a targeted campaign into proliferating infrastructure. Derivative campaigns targeting PyPI, Go modules, and NuGet are a material near-term risk.
Also Known As