From Cryptojacking to AI-Powered Chaos: TeamPCP’s Hidden Five-Year Evolution Reveals a New Supply Chain Warfare + Video

Listen to this Post

Featured ImageIntroduction: The Open-Source Threat That Was Growing in the Shadows

The cybersecurity world is facing a new generation of threats where attackers no longer rely only on traditional malware campaigns. Instead, they are building long-term ecosystems that combine cloud abuse, open-source compromise, stolen credentials, AI infrastructure exploitation, and automated attacks.

A newly published investigation by Oligo Security has revealed that the group known as TeamPCP, responsible for major supply chain attacks targeting developer tools in March, may not be a newly formed threat actor. Evidence suggests the operation has roots stretching back to 2020, with connections to previous campaigns involving cryptojacking, cloud infrastructure abuse, GitHub Actions attacks, and even one of the first known self-propagating botnets built from compromised AI infrastructure.

The investigation, conducted with support from Mandiant and GitLab, paints a disturbing picture: TeamPCP appears to be part of a continuously evolving criminal ecosystem that has spent years improving its methods, expanding its infrastructure, and targeting the foundations of modern software development.

The Hidden Connection Between TeamPCP and Earlier Cyber Operations

For months, TeamPCP attracted attention after launching cascading supply chain attacks against open-source developer tools. However, researchers now believe the group’s activities are connected to a much older operation tracked as TA-NATALSTATUS, which was active between 2020 and August 2025.

According to Oligo Security, the connection was discovered through overlapping infrastructure, malware delivery methods, domain usage, and backend systems. Rather than appearing suddenly, TeamPCP seems to represent the continuation of years of experimentation and operational growth.

The research suggests that the attackers gradually moved from simple cryptojacking campaigns into highly advanced operations targeting software supply chains, cloud platforms, AI workloads, and enterprise development environments.

A Five-Year Infrastructure Trail Left Behind by Attackers

One of the strongest indicators linking these campaigns is the domain masscan[.]cloud, which appeared repeatedly throughout different stages of the group’s operations.

The infrastructure was associated with TA-NATALSTATUS activity, later appeared during the ShadowRay 2.0 campaign, and eventually became linked to TeamPCP. Certificate transparency records show that the domain infrastructure existed before TeamPCP became publicly known.

Researchers also discovered that TeamPCP’s own GitHub presence listed the domain as its official website, creating one of the strongest technical connections between the older and newer campaigns.

The attackers also reused the same deployment framework for years. This included recognizable directory structures, staging scripts, and malware delivery methods that remained largely unchanged despite the evolution of their targets.

ShadowRay 2.0: The AI Infrastructure Attack That Changed the Game

One of the most significant discoveries involves ShadowRay 2.0, a campaign targeting exposed Ray clusters.

Ray is an open-source distributed computing framework commonly used for artificial intelligence and machine learning workloads. Because many organizations deploy Ray clusters with powerful computing resources, they have become attractive targets for attackers looking to steal processing power, data, and access credentials.

Oligo previously linked ShadowRay 2.0 to an actor known as IronErn440. The new investigation suggests that the same infrastructure later became part of TeamPCP operations.

A compromised Ray cluster downloaded malicious files from the same infrastructure on July 26, 2025, months before TeamPCP gained public attention.

This discovery highlights a major shift in cybercrime: attackers are increasingly targeting AI infrastructure because it provides enormous computational value.

The GitLab Evidence That Strengthened the Investigation

The strongest operational evidence came from activity connected to GitLab accounts.

Researchers identified an IP address that received reverse shell connections from a compromised Ray cluster between October 15 and November 2.

After those shells stopped, the same IP address was used shortly afterward by the IronErn440 GitLab account to authenticate and access campaign-related tools.

This overlap does not prove absolute ownership of every operation, but it demonstrates a strong relationship between the infrastructure, tooling, and individuals involved.

GitLab later banned the accounts associated with the activity following the investigation.

From Cryptocurrency Mining to Supply Chain Destruction

The evolution of this threat actor shows a dramatic transformation.

Early operations focused heavily on cryptojacking, where attackers secretly used compromised machines to mine cryptocurrency.

Over time, the group expanded into:

Automated exploitation of internet-facing services.

Worm-like malware propagation.

GitHub Actions abuse.

Cloud credential theft.

Open-source ecosystem manipulation.

AI infrastructure attacks.

Destructive payload deployment.

This progression demonstrates how cybercriminal groups are becoming more similar to professional organizations, maintaining infrastructure, improving tools, and reusing successful techniques across multiple campaigns.

The PCPcat Campaign and Developer Ecosystem Attacks

One important stage in this evolution was PCPcat, a campaign that targeted vulnerable systems around Christmas 2025.

The attackers focused on exposed Docker APIs and vulnerable environments connected to React2Shell-related targets.

Instead of attacking individual companies directly, the group increasingly focused on software ecosystems where one successful compromise could impact thousands of developers and organizations.

This strategy mirrors modern supply chain attacks, where attackers seek maximum impact by compromising trusted tools rather than isolated systems.

March Supply Chain Attacks: The Turning Point

In March 2026, TeamPCP launched attacks affecting major developer security tools, including:

Trivy.

Checkmarx KICS.

LiteLLM.

These attacks demonstrated the danger of compromising software used throughout enterprise environments.

A single malicious modification inside a trusted developer tool can provide attackers with access to countless organizations that unknowingly download and deploy compromised components.

The campaign showed that open-source security has become one of the most important challenges in modern cybersecurity.

The Expansion Beyond Malware: Phishing, Fraud, and Impersonation

Researchers discovered that the infrastructure used by TeamPCP was not limited to malware distribution.

Additional subdomains supported:

Credential phishing campaigns.

Payment fraud operations.

Zendesk impersonation attacks.

Social engineering activities.

This suggests the attackers developed a broader criminal ecosystem rather than relying on one attack method.

Modern threat groups increasingly combine technical exploitation with human-focused attacks to increase success rates.

The Destructive Payload Hidden Inside Kubernetes Attacks

One of the most alarming discoveries involved a second-stage Kubernetes payload containing destructive capabilities.

The script checked whether the victim system was configured for Iran’s timezone.

If the condition matched, the malware could deploy a destructive workload designed to erase filesystems and reboot affected machines.

However, Oligo researchers noted that Iranian connectivity disruptions during the period limited visibility into whether the destructive feature was ever successfully activated.

The existence of such a capability shows that the group was not only interested in financial gain but also possessed tools capable of causing operational damage.

Deep Analysis: How TeamPCP Represents the Future of Cyber Threats

1. The Rise of Long-Term Cyber Ecosystems

TeamPCP demonstrates that modern threat actors are no longer temporary hacking groups.

They build infrastructure that survives for years.

Domains, scripts, malware loaders, and deployment frameworks are reused across campaigns.

This reduces development costs and increases attack efficiency.

  1. AI Infrastructure Has Become a Prime Target

Attackers are now looking beyond traditional servers.

AI clusters contain:

Powerful GPUs.

Sensitive models.

Valuable datasets.

Cloud credentials.

A compromised AI environment can become both a financial resource and an intelligence target.

3. Open Source Is Becoming a Battlefield

The software industry depends heavily on open-source projects.

Attackers understand that compromising one trusted package can provide access to thousands of organizations.

Supply chain attacks are becoming more attractive because they offer scale.

4. Cloud Environments Are Difficult to Defend

Cloud systems often expose APIs, containers, and automated pipelines.

Attackers exploit misconfigurations because cloud environments provide rapid expansion after initial compromise.

5. Automation Makes Attacks Faster

The use of worm-like techniques allows malware to spread without constant human control.

Automation enables attackers to scan, exploit, deploy, and maintain access at unprecedented speed.

6. Developer Tools Are Becoming Strategic Targets

Security tools themselves are now attractive targets.

Organizations trust these tools deeply, making them powerful entry points.

A compromised scanner or dependency manager can bypass traditional security defenses.

7. Attribution Remains Difficult

Although infrastructure overlaps are significant, researchers warn against making absolute claims.

Shared tools, reused servers, or stolen infrastructure can create misleading connections.

Cyber attribution requires careful analysis.

8. Criminal Groups Are Becoming More Professional

The operational maturity shown by TeamPCP resembles advanced threat groups.

They maintain infrastructure.

They develop reusable frameworks.

They monitor victims.

They adapt quickly.

  1. AI Will Increase Both Defense and Attack Capabilities

AI systems will help defenders detect threats faster.

However, attackers are also using AI infrastructure as a target and potentially as a weapon.

The cybersecurity battle is entering an AI-driven era.

10. The Biggest Risk Is Trust

The greatest weakness exposed by TeamPCP is not a technical vulnerability.

It is trust.

Organizations trust:

Open-source packages.

Developer tools.

Cloud platforms.

Automation systems.

Attackers are increasingly exploiting that trust.

Deep Analysis: Security Commands and Defensive Checks

Check Suspicious Network Connections

netstat -tunap

or:

ss -tunap

These commands help identify unexpected outbound connections from servers.

Search Running Processes

ps aux --sort=-%cpu

Look for unusual processes consuming high CPU resources, especially on cloud machines.

Check Docker Exposure

docker ps

Review running containers and confirm that Docker APIs are not publicly exposed.

Audit Kubernetes Workloads

kubectl get pods --all-namespaces

Unexpected workloads should be investigated immediately.

Review Git Authentication Activity

git log --all --decorate --oneline

Organizations should monitor suspicious commits and unauthorized changes.

Scan Open Ports

nmap -sV target-ip

Exposed services should be minimized.

What Undercode Say:

TeamPCP represents a major warning sign for the cybersecurity industry.

The most important lesson is that cybercriminal groups are no longer measured by individual attacks.

They are measured by their ability to maintain ecosystems.

The transition from cryptojacking to AI infrastructure attacks shows how quickly attackers adapt.

Five years ago, stolen computing power was mainly used for cryptocurrency mining.

Today, the same concept applies to AI workloads.

A compromised AI cluster can provide enormous value.

Attackers can steal models.

They can access sensitive data.

They can use expensive GPU resources.

They can manipulate development pipelines.

The TeamPCP investigation also exposes a weakness in modern software supply chains.

Organizations increasingly depend on thousands of external components.

A single compromised dependency can become a global security event.

The open-source community must improve transparency.

Package verification.

Developer identity protection.

Automated security testing.

All of these areas require stronger investment.

Another important factor is attacker patience.

The group appears to have operated quietly for years before becoming publicly visible.

This proves that many cyber campaigns are discovered only after significant damage has already occurred.

Security teams must focus on threat hunting rather than waiting for alerts.

AI infrastructure deserves special attention.

Many companies rushed to deploy AI systems without applying traditional security principles.

Publicly exposed AI services.

Weak authentication.

Poor network segmentation.

These mistakes create attractive targets.

The future of cybersecurity will depend on protecting both traditional infrastructure and AI-powered environments.

TeamPCP is not just another malware campaign.

It represents the convergence of cloud attacks, supply chain compromise, AI exploitation, and automated cyber operations.

The next generation of attackers will likely continue combining these techniques.

Organizations that ignore this shift may discover that their most trusted tools become their biggest vulnerabilities.

✅ Confirmed: TeamPCP has infrastructure links to older cyber activity.
Oligo Security identified overlapping domains, malware deployment methods, and backend infrastructure connecting TeamPCP with TA-NATALSTATUS-related operations.

✅ Confirmed: ShadowRay 2.0 targeted exposed AI infrastructure.
The investigation linked TeamPCP-related infrastructure with campaigns targeting Ray clusters, highlighting growing attacks against AI computing environments.

✅ Confirmed: The group targeted open-source supply chains.
The March attacks affecting developer tools demonstrated the increasing danger of software ecosystem compromises.

❌ Not Confirmed: TeamPCP and older groups are definitively the same organization.
Researchers stated that the evidence shows operational continuity but cannot prove whether this represents a direct rebrand, collaboration, or shared operators.

Prediction

(+1) Positive Prediction:

Cybersecurity companies will accelerate investment in AI infrastructure protection, open-source security monitoring, and automated supply chain verification.

Organizations will increasingly adopt stronger software identity systems, dependency scanning, and cloud security controls.

The lessons from TeamPCP may push the industry toward a more secure software ecosystem.

(-1) Negative Prediction:

Attackers will continue targeting AI platforms, developer tools, and open-source projects because these environments provide massive opportunities.

Future campaigns may combine AI exploitation, automated malware deployment, and supply chain attacks at a scale larger than anything previously seen.

Without stronger security practices, similar groups may remain hidden for years before being discovered.

▶️ Related Video (78% Match):

🕵️‍📝Let’s dive deep and fact‑check.

🎓 Live Courses & Certifications:

Join Undercode Academy for Verified Certifications

🚀 Request a Custom Project:

Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands

References:

Reported By: www.infosecurity-magazine.com
Extra Source Hub (Possible Sources for article):
https://www.medium.com
Wikipedia
OpenAi & Undercode AI

Image Source:

Unsplash
Undercode AI DI v2

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow UndercodeNews & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin | 🦋BlueSky | 🐘Mastodon | 📺Youtube