INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
GitHub Investigating TeamPCP for Breach of ~4,000 Internal Repositories
| 2026-05-20 04:01 LOW HIGH DATA BREACH
Executive Summary
AI-generated
On May 20, 2026, TeamPCP claimed to have breached approximately 4,000 internal GitHub repositories. The threat actor listed the platform's source code and internal organizations for sale on a cybercrime forum at an asking price of no less than $50,000. Three malicious package versions (1.4.1, 1.4.2, and 1.4.3) have been identified, which embed a dropper that fetches and runs a second-stage payload from the external server "[IOC HIDDEN • LOGIN REQUIRED]-service[.]com". The malware is an evolution of the payload deployed in connection with the compromise of the guardrails-ai package last week, designed to activate a full-featured infostealer capable of harvesting credentials associated with major cloud providers.
Technical Mitigations AI-generated
• Patch the durabletask PyPI package versions 1.4.1, 1.4.2, and 1.4.3 to prevent malware propagation.
• Block or hunt for the "<a href="/auth/login?next=/detail/KtTrQ54BGrn1nGIcDwOY" class="ioc-censored-pill text-decoration-none" title="Protected IoC: Sign in to view" data-bs-toggle="tooltip"><span class="badge bg-black text-warning border border-warning border-opacity-75 font-monospace ioc-lock-tag align-middle"><i class="bi bi-lock-fill me-1"></i>[IOC HIDDEN • LOGIN REQUIRED]</span></a>-service[.]com" domain to detect second-stage payload downloads.
• Use a technique like FIRESCALE to identify backup C2 addresses in GitHub's public commit messages.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected
Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.
hu•••••.io
ch•••••.git
ro•••••.pyz
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Shai-HuludShai-Hulud
Target & Sectors
IL
IR
technologytechnology
Incident Timeline
May 20, 2026
Threat actors released a 28KB Python stealer package that targets Linux systems, which attempts to access various sensitive data and executes a second-stage payload from an external server.
Click on any entity below to view its context and source!
infrastructure
1.4.1
Three malicious package versions have been identified: 1.4.1, 1.4.2, and 1.4.3.
infrastructure
1.4.2
Three malicious package versions have been identified: 1.4.1, 1.4.2, and 1.4.3.
infrastructure
1.4.3
Three malicious package versions have been identified: 1.4.1, 1.4.2, and 1.4.3.
infrastructure
Linux
It's worth noting that the stealer is configured to execute only on Linux systems.
Tactical Metrics
Metrics
infrastructure
1.4.1
Software Version
Click for context!
Three malicious package versions have been identified: 1.4.1, 1.4.2, and 1.4.3.
Metrics
infrastructure
1.4.2
Software Version
Three malicious package versions have been identified: 1.4.1, 1.4.2, and 1.4.3.
Metrics
infrastructure
1.4.3
Software Version
Three malicious package versions have been identified: 1.4.1, 1.4.2, and 1.4.3.
Metrics
infrastructure
Linux
Affected Product
It's worth noting that the stealer is configured to execute only on Linux systems.
Intelligence Sources
The Hacker News
2026-05-20
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-10-07T11:03
Comprehensive Tactical Telemetry
Highly Correlated Entities
12x
organisation
Identified Entity
SendCommand
entity
3x
timeline
Temporal Reference
May 20, 2026
date
3x
infrastructure
Software Version
1.4.1
version
2x
target region
Target Country
Israel
country
2x
tactic
MITRE ATT&CK Technique
T1588.001 - Malware
technique
Contextual Telemetry
Context Block
7 METRICS
infrastructure
Affected Product
Linux
software
general metric
In-6
1
in-6
general metric
Other Ec2 Instances
5
other ec2 instances
malware
Malware Payload
Shai-Hulud
tool
general metric
Python Stealer
28
python stealer
general metric
Repositories
4,000
repositories
general metric
Downloads / Installs
417,000
downloads
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.