Skip to content
← All Threat Actors
Cybercrime critical Unknown (Eastern Europe assessed)

TeamPCP (UNC6780)

Criminal threat actor (Eastern Europe assessed) · Financial -- credential theft and extortion

Reports 1
Active Since 2026
Last Reported 28 May 2026
Sectors Targeted communications, finance, critical-infrastructure

Tactics, Techniques & Procedures (TTPs)

  • GitHub Actions OIDC token abuse via pull_request_target workflow misconfiguration
  • Build cache poisoning for trusted npm package publication under legitimate maintainer identity
  • Mini Shai-Hulud self-propagating npm worm targeting JavaScript ecosystem
  • Credential sweep covering 130 file paths (SSH keys, cloud credentials, API tokens, kubeconfigs)
  • Open-source worm publication and BreachForums contest to enable copycat campaigns
  • Python backdoor polling GitHub repository for signed C2 messages
  • Extortion demands post-compromise

Known Targets

JavaScript npm ecosystem (TanStack, @antv namespace -- 16M+ weekly downloads)OpenAI (developer device compromise)Mistral AI (developer device compromise, extortion demand)Grafana LabsGitHub internal development environment (3,800+ repositories exfiltrated)

Analyst Notes

Responsible for the Mini Shai-Hulud npm supply chain campaign, May 2026 -- one of the most consequential developer supply chain attacks on record. The attack chain (GitHub Actions misconfiguration → build cache poisoning → OIDC token extraction → trusted npm publication) required no stolen credentials. CISA issued three CVEs with expedited remediation deadlines. The open-sourcing of the worm under MIT licence, combined with a $1,000 BreachForums contest for copycat attacks, transforms this from a targeted campaign into proliferating infrastructure. Derivative campaigns targeting PyPI, Go modules, and NuGet are a material near-term risk.

Also Known As

TeamPCPUNC6780