INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

GitHub Investigating TeamPCP for Breach of ~4,000 Internal Repositories

| 2026-05-20 04:01 LOW HIGH DATA BREACH
Executive Summary
AI-generated
On May 20, 2026, TeamPCP claimed to have breached approximately 4,000 internal GitHub repositories. The threat actor listed the platform's source code and internal organizations for sale on a cybercrime forum at an asking price of no less than $50,000. Three malicious package versions (1.4.1, 1.4.2, and 1.4.3) have been identified, which embed a dropper that fetches and runs a second-stage payload from the external server "[IOC HIDDEN • LOGIN REQUIRED]-service[.]com". The malware is an evolution of the payload deployed in connection with the compromise of the guardrails-ai package last week, designed to activate a full-featured infostealer capable of harvesting credentials associated with major cloud providers.
Technical Mitigations AI-generated
• Patch the durabletask PyPI package versions 1.4.1, 1.4.2, and 1.4.3 to prevent malware propagation. • Block or hunt for the "<a href="/auth/login?next=/detail/KtTrQ54BGrn1nGIcDwOY" class="ioc-censored-pill text-decoration-none" title="Protected IoC: Sign in to view" data-bs-toggle="tooltip"><span class="badge bg-black text-warning border border-warning border-opacity-75 font-monospace ioc-lock-tag align-middle"><i class="bi bi-lock-fill me-1"></i>[IOC HIDDEN &bull; LOGIN REQUIRED]</span></a>-service[.]com" domain to detect second-stage payload downloads. • Use a technique like FIRESCALE to identify backup C2 addresses in GitHub's public commit messages.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected

Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.

hu•••••.io
ch•••••.git
ro•••••.pyz
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Shai-HuludShai-Hulud
Target & Sectors
IL IR
technologytechnology
Incident Timeline
‎May 20, 2026
Threat actors released a 28KB Python stealer package that targets Linux systems, which attempts to access various sensitive data and executes a second-stage payload from an external server.
infrastructure 1.4.1
infrastructure 1.4.2
infrastructure 1.4.3
infrastructure Linux
Tactical Metrics
Metrics
infrastructure
‎1.4.1
Software Version
Metrics
infrastructure
‎1.4.2
Software Version
Metrics
infrastructure
‎1.4.3
Software Version
Metrics
infrastructure
‎Linux
Affected Product
Intelligence Sources