MEDIUMSupply Chain
Global

TeamPCP Supply Chain Campaign: Activity Through 2026-05-24, (Mon, May 25th)

·Source: SANS ISC

Updated:

Executive Summary

TeamPCP now operates across three package ecosystems in parallel, it reached GitHub&&#x23&#x3b;x26&#x3b;&#x23&#x3b;39&#x3b;s own internal codebase, it trojanized an officially Microsoft-published Python SDK, and it appears to have open-sourced its own framework on GitHub.

Analysis

TeamPCP now operates across three package ecosystems in parallel, it reached GitHub&&#x23&#x3b;x26&#x3b;&#x23&#x3b;39&#x3b;s own internal codebase, it trojanized an officially Microsoft-published Python SDK, and it appears to have open-sourced its own framework on GitHub.
Source Attribution

Originally published by SANS ISC on May 25, 2026.

Related Threats