TeamPCP’s Reach Extends Into AI Infrastructure

TeamPCP is not a one-off package vandal. Oligo’s timeline shows the same operator set has been active since 2020 and can move from open-source package injections into AI infrastructure, which widens the threat model from noisy software abuse to systems that can spread compromise on their own. Oligo tied the recent package campaign to older activity using the same infrastructure, including IPs, domains, and servers that trace back to 2020. The same research also links TeamPCP to a late-2025 ShadowRay exploit that produced the first self-propagating botnet on hijacked AI infrastructure, showing the actor can pivot between software supply chains and runtime systems that host AI workloads. That means a trusted package path or a single exposed AI host can become a launch point for broader compromise, not just an isolated incident.

Part of the PlainSec briefing for 2026-08-06

Every edition of this story: TeamPCP’s Reach Extends Into AI Infrastructure

Sources