TeamPCP is not winning with a clever new exploit. It is turning maintainer and CI trust into a distribution channel, so malicious code can ride out as if it were legitimate and reach downstream automation at ecosystem scale. That breaks the normal dependency-review assumption that the package name and upstream source are enough to trust.
In less than four months, the group compromised and injected malicious code into more than 1,000 open-source packages, starting with Trivy. The campaign lands through the publishing workflow and then spreads through build systems, package managers, and AI tools that auto-install dependencies with little or no human review.
The risk now sits in the intake path, not just in the code you control. If your pipelines accept public packages on trust, a clean-looking upstream release can still become a compromised input to your builds.