Open-source software’s archenemy TeamPCP goes back further than anyone thought

2026-08-05T14:51:41Z8d91b36955024b74f8b0dbecec56ba03f32581471ade52d6af9ad9f294839429
AI model hackingAI securityINC ransomwareMini Shai-HuludSonicWallTeamPCPcyber policydata theftextortionidentity theftnpm packagesprivacyself-replicating malwaresoftware supply chain attackzero-day exploitation

What happened

CyberScoop coverage highlights TeamPCP’s long-running activity and its suspected role in a major software supply-chain attack affecting 440 packages with self-replicating Mini Shai-Hulud malware. It also reports INC ransomware exploitation of SonicWall zero-day vulnerabilities, plus policy and research developments involving AI security, model hacking, election information, privacy, and cyber-risk disclosure.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
cyberscoop
Record identifier
8d91b36955024b74f8b0dbecec56ba03f32581471ade52d6af9ad9f294839429
Enrichment time
2026-08-05T14:51:41Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.