Video summary
In May 2026, the cybersecurity landscape was shaken by a massive wave of software supply chain attacks orchestrated by a hacker group known as Team PCP. This threat actor gained significant notoriety after compromising GitHub itself; an internal developer installed a malicious Visual Studio Code extension that allowed attackers to access thousands of repositories within the platform's private network. The attack utilized a "worm-like" propagation method, where infecting one package or library enabled the group to compromise other dependencies and packages maintained by various users on platforms like NPM and PyPI. This incident highlighted how easily legitimate software updates can be backdoored with malicious payloads, turning routine maintenance into a constant security fire that requires immediate attention from organizations relying on open-source ecosystems.
The operational style of Team PCP has been characterized by high-profile stunts designed to generate maximum media exposure rather than traditional financial extortion. In a move that blurred the lines between cybercrime and meme culture, the group openly released their malware, dubbed "Shai Halud," as an open-source project on GitHub while adopting cat-themed personas and reggae fusion soundtracks in their communications. They even attempted to co-own Breach Forums before internal conflicts led to public feuds with former associates who accused them of scamming customers and mishandling stolen data. Despite the chaotic nature of these activities, which included posting threats about leaking GitHub source code on dark web forums like LimeWire, the group's primary goal appears to be establishing a lasting presence in the cybercrime scene through sheer volume and visibility rather than quiet infiltration.
For security professionals overwhelmed by the constant stream of alerts and headlines, distinguishing genuine threat intelligence from noise is critical for effective defense. The video emphasizes that while much of Team PCP's activity resembles "cybercrime high school drama," it provides valuable signals regarding active intrusion techniques, tactics, procedures, and indicators of compromise (IOCs). To manage this influx of data effectively, the presenter highlights the utility of identity-first threat intelligence platforms like Flare, which can synthesize information from dark web sources, Telegram chats, and leak sites to provide actionable context. By integrating such tools with local open-source frameworks like OpenCTI using STIX/TAXII standards, organizations can centralize their defense posture, filter out irrelevant chatter, and focus on real-world threats that directly impact their specific environments without getting lost in the overwhelming sea of global cybercrime news.
Read the full video transcript
In May of 2026 and some time leading up
to it, the cybersecurity industry has
seen an absolute rampage of software
supply chain attacks. There was a recent
news article and headline from Wired
that says a hacker group is poisoning
open source code at an unprecedented
scale. And this hacker group is called
Team PCP. One of their most recent
attacks actually affected GitHub
themself, but I'm sure you have seen the
headlines. You've heard the news.
Software supply chain attacks are super
duper sinister because the threat actor
is taking legitimate software,
applications, and programs that you
might already use or depend on for
software that you write in your
organization, and they inject their own
malware. You can think of some very
well-known incidents in the past, like
SolarWinds or 3CX or Axios that we saw
just recently, when there is a new
version of some software application or
even library or dependency, there's an
update that's available that is actually
backdoored with a payload. And
traditionally, this didn't used to
happen all that often, but Team PCP is
turning this into a pretty constant
fire. The most recent incident last
month in May that got the most headlines
and alarm bells and sirens going off was
when the supply chain attack affected
GitHub. An internal GitHub developer
installed a poisoned or that backdoored
and malicious VS Code extension or
Visual Studio Code extension, and Team
PCP, the threat actors behind it, said,
"Hey, out of the 4,000 GitHub internal
repositories, they've seen at least
3,800 compromised repositories." This
specific instance of the NX Console VS
Code extension was covered really well
by Step Security, so we'll have links to
all of these down below in the video
description. But the gist is here. This
compromise occurred due to a recent
supply chain attack via Team PCP that
scraped one of our contributors GitHub
tokens. Now, this has a ripple effect,
right? This is downstream. The dominoes
can fall because this developer for the
NX software package and library, now
that they're compromised, maybe the
adversary could make changes to other
things like the VS Code extension that
other individuals, like some internal
worker at GitHub, could pull down,
install, and now they're infected. Team
PCP really likes to have some sort of
worm effect where other packages are
affected based off of other things that
might be installed or available within
their GitHub repositories or other
libraries or packages that they
maintain. So, whether you realize it or
not, you probably have heard of Team PCP
and their escapades. In the first half
of the year, they compromised Trivy,
they compromised KICS, they compromised
light LLM, Telnyx, and they've been
beating up NPM, the Node Package
Manager, and PyPI, the Python Package
Index. While there have been so many of
these software supply chain attacks
nearly every other week, it's hard to
keep up with for the security teams
fighting fires all the time, and you
kind of have to wonder, how does Team
PCP do this? And I have to think to some
extent, it's really their style, like
their tradecraft, but their persona,
their mentality in all this. Look, you
can see some comments here. They're
definitely going for big exposure. They
really care about getting big attention.
They want to make a little bit of a
storm. They want to make a stink. They
want to toot their own horn in sort of
this chest-thumping braggadocio way.
They're leaning into the meme with like
oh, Matrix-style cascading ones and
zeros, a reggae fusion soundtrack, and
Team PCP, a big banner, the cat's
hijacking your supply chain. With that,
Team PCP literally has been active on
Twitter or X. Like they created an
account and they want to hang out
amongst us normies. Of course, profile
picture is a cat, handle PCP Cats, and
say this account follows the Twitter
terms of service. I don't sell or
advertise any services here. I'm just a
silly cat having fun on the interwebs.
And last month, while they were
frolicking in the fields of the fire
that they've set to the software supply
chain, they went ahead and open-sourced
their Shai Halud worm. Now, I'm sure
you've heard the internet screaming and
shouting about the Shai Halud worm
because, right, I know the Dune joke
there about this sandworm, but that's
how they've been propagating across one
infected package or library or
dependency and now moving into to
compromise other installed packages or
dependencies that you might maintain
over on NPM or in your GitHub account.
The meme here is crazy. These GitHub
packages that were out and about to
include the Shai Halud malware and
campaign, I guess the caption was Shai
Halud open-sourcing the carnage. Is it
vibe-coded? Yeah. And you got to give
the devil his due here to a certain
extent, right? Does it work? Let the
results speak. Like, who cares if it's
vibe-coded if the effect is
accomplished? Love, Team PCP. Aux
Security had covered this, again link
below in the video description, but
here's the write-up. Shai Halud worm
goes open-source. Their malware, what
they wrote, they've just shared now on
the open internet. Accessible,
open-source on GitHub, funny enough now
a later victim of their escapades. But
the thing is that now anyone, like
whatever copycat or anyone that just
wanted to pull this off the shelf, could
do that same amount of damage. These
were the repositories, they aren't now
taken down. They're no longer online.
Some folks might have had a backup or
mirrored it, but here it is. Look, is it
vibe-coded? Yeah. Does it work? Yeah.
Who cares if it's AI slop? It gets the
job done. And they go through more of
the investigation, some more of the
details here. They're leaning into the
meme. Look, haha, heehee, all the folks.
They're alluding to cats. Here's a meow
for that user
boards and threads for cracking or
buying and selling services, hacker for
hire, data breaches, leaks, passwords,
blah blah blah. So, last month on Breach
Forums, Team PCP had posted. And they
say, "In a Team PCP partnership or forum
co-ownership thread, hello again Breach.
I hope everyone is well. We're proud to
announce the new team role as co-owners
of this platform. I guess they're
becoming co-owner, right? It's a
management and staff for Breach Forums.
They sign off all cutsey, best regards
to PCP Cats and Hassan Broker is going,
"Hey, welcome aboard." I guess he's now
exiled. We can chat a little bit more
about that. Everyone's like, "Hell yeah,
all right, brothers in arms,
cybercrime." And hey, the way that I'm
tracking down a lot of these dark web
posts and cybercrime shenanigans is
thanks to Flare. Flare is an
identity-first cyber threat intelligence
platform and solution, and they are
collapsing the gap between detection and
real remediation. They have a huge
amount of insight in the dark web and
the cybercrime ecosystem. Think
ransomware leak sites or Telegram chats
or infostealer malware logs. So, what
I've done is super simple. Honestly,
just logging into their platform,
hopping over to the events tab, and the
global search tab basically lets you
search for anything across their entire
data set. And here we can see some folks
screaming and shouting in the Jacuzzi
Telegram here. They give you the link
and the onion URLs if they're looking at
any of the dark websites. And while you
don't need to fire up the Tor browser or
actually connect to them, you could just
see what other shenanigans they're
sharing right in the platform. Oh, but
here's some more of the cybercrime
whining, right? Hassan says Team PCP has
been reselling some of the GitHub data
even after he said he sold it. He's
actively scamming his customers, and the
plot gets even worse. Picture here that
they include of Okay, yeah, the
authentic full GitHub Team PCP leak from
May 2026. Starting to ruffle some
feathers though with Hassan and Team PCP
not getting along. That brings us to the
today timeline. We're over on Breach
Forums just this past weekend on
Saturday, Team PCP posts another Oh,
signs of life amidst rumors while
they've seemingly been away. Hello,
Breach. I hope everyone is as It looks
like Team PCP will no longer be working
with Hassoun and instead continue
operating on this branch of the forums.
We observed him treat his staff very
badly and we watched him get fished,
lol.
Anyone who takes themselves seriously
and cares about their partners being
capable operators would think it's a
complete joke. Maybe he buys his own
database back, no hard feelings, but
this is just a neutral end of the Look,
okay, um this is just the threat actor
bickering that tends to happen, but it
has been difficult for me as facing
spokesperson to come online. Some people
have taken this leave of absence as a
sign that I or the team have been feted,
like arrested. This is simply untrue and
I have already checked in with partners
to resolve this. This is a sign of life
and I guess my way of clearing things.
So, they're still kicking. So, we got
the old sign off T from the PCP cats
says I should be much more capable of
responding now. And you see them
chirping, whatever they do. Hey, look
sexy Team PCP. It's just whatever. So,
here's the thing. You know I like to
make light of this, oh I don't know,
threat actors chirping, cybercrime high
school drama, stupid pictures of cats
doing whatever they do and their
shenanigans, but there is real value
amongst the noise for like genuine cyber
threat intelligence. Here's the threat
Oh, when they were selling the internal
GitHub source code. Like being able to
keep an eye on what these actors are up
to is genuinely valuable. They're
dropping these on LimeWire. What the
heck? But like there's some tactical
stuff here. A little bit of chest
thumping bravado. Oh, hey, this is not a
ransom. We don't care about extorting
GitHub. One buyer and then we shred the
data on our end. Apparently not
according to Hassoun, hence the crap. It
looks like our retirement is soon, so if
no buyer will leak it for free. Turn
offers like almost 100k, blah blah blah.
I guess they kicked it over to Lapsus,
so. Anyway, what I'm alluding to is that
look, there is some signal in the noise
about these threats, about these threat
actors, about this activity, about these
intrusions and malware that you probably
want to be tracking. I'm not going to
drag us down the rabbit hole of the step
security article, but I feel like this
is tactical and actionable because this
includes the real indicators of
compromise here. But between all the
news headlines and advisories and
reports and notifications and postmortem
write-ups and CVE details. I don't know
why they made a CVE for the supply chain
attack. People screaming and shouting,
regurgitating, rebroadcasting the same
stuff on Twitter, LinkedIn, I don't
know, cybercrime crap over on the dark
web. Look, the reality is you don't need
to care about all of the nonsense and
you really should just be looking for
like the signal to the noise, what
actually matters to you and in your
environment. And hey, Flare, you know I
love them. Look, they've got this
awesome setup with their threat flow
where they could provide to you some
sweet intelligence, tactical indicators
of compromise, real TTPs, the MITRE
attack mapping, the genuine signal to
noise here. You could create your own if
you ever wanted to based off of any sort
of time period. But I wanted to pull up
the one for Team PCP that they were
tracking just some time ago. Look, this
gives you I think the raw real facts.
It's synthesizing across what they're
tracking across those dark web locations
and actually getting what matters for
the domains, the IP addresses, the
hashes, file system artifacts that you
don't cover, MITRE attack techniques,
and the things that arm you and your
team to actually detect against the real
threat. The coolest thing is that this
is synthesizing all of these different
reports so you don't have to. And a
really awesome new thing that they've
cooked up here is their intelligence
solution. This basically lets you search
for anything and everything in a much
faster, better way. Let me go look for
Team PCP here to get a little bit more
tactical with what our conversation is.
And here you can see the chatter on XSS
when they open sourced the Shai Hulud.
They're automatically analyzing this,
getting the more tactical stuff like the
GitHub repositories that are pertinent.
And you can get a heck of a lot more
granular with this given their filters
where you can choose whether it's an
actor, an attack pattern, a campaign,
any specific thing like a vulnerability
or CVE itself, the time that you're
looking for, the metadata as to where
you're pulling these from. And if I
close out, I'll show you another one
here like the Team PCP entry notes that,
hey, we're actually synthesizing this
article from Wiz with a grade of like,
this is pretty reliable. These are all
part of the STIX and TAXII sort of like
protocols or standards or schemas that
are used for threat intelligence.
Pulling out some of the imagery, getting
the threat context, these become
actually actionable and valuable for
you. One cool thing I wanted to be sure
to mention is that they are partnering
with Sequoia to be able to provide of
these threat intelligence. So, big shout
out and love to Sequoia just as well.
Hey, Flare is the sponsor of this video,
so huge shout out and thank you to them
for their support. But hey, if you're
interested to kick the tires, see this
thing yourself, actually get access,
they do have a two-week free trial and
an awesome little exclusive here for us
to be able for you to see Threat Flow
and dive in and access all this just as
well. And that is not included in the
standard free trials. So, seriously,
genuinely, thank you so much for your
support, Flare. And I hope you go get a
chance to play with it and see your
organization's real exposure and their
identity-first threat intelligence
solution. Link below. With that, one
last little tidbit here for you. While
I'm on this train of actionable,
actually valuable cyber threat
intelligence, I know more often than not
all those STIX and TAXII like protocols
and things to collect indicators,
artifacts, evidence, more often than not
you funnel those into your tip or a
threat intelligence platform. Just to
see this all in action, I did stand up
my own little local interface for
OpenCTI or one open and accessible
threat intelligence platform. And we can
funnel in a lot of Flare's data there.
Let me go ahead and log in here and I'm
not going to spend too much time in
OpenCTI, but I wanted to show it to you
just because I know, look, this is very
likely what you are really doing in your
real environment. It doesn't have to be
OpenCTI. It could be any sort of tip or
threat intelligence platform, but look,
I'll show you in the data and ingestion
section here. Now, I'm able to go ahead
and connect Flare as its own connector
alongside Sekoya or any other connector
that we might like, but this is pretty
awesome because that will funnel in all
of those artifacts and everything that
Flare might give us. So, you don't have
to always be in that platform, but
realistically bring this into your own
dashboard and environment. Here are some
of those Sekoya entries. I want to track
down maybe some of the events here. You
can see incidents. Yeah, and a good many
of these like look-alike domains for my
own website. So, that's pretty cool to
see my own indicators now in action and
you could explore that for just about
anything. I'm just pretty happy to see a
actually centralized threat intelligence
platform now that CTI is just so
absolutely necessary for your security
posture and your organization. All
right, that's it. I've been rambling for
way too long, but look, seriously, I
hope there is some value in there in
trying to like pull you out of the
overwhelming sea of headlines and alerts
and notifications and just finding truly
the signal to noise for what matters to
you. There are going to be more of
these. There we saw a team PCP. Oh, the
cats are back in action. Look, don't let
yourself get caught up in the cycle.
Just stay smart and ahead of it with
real intel. Actionable, valuable that
matters to you.
Thanks so much for watching. See you in
the next video.