TeamPCP supply-chain credential and data leak
Data Leak
Summary
Hide ▲
Show ▼
A TeamPCP-linked supply-chain leak exposed half a million credentials and at least 300GB of data, putting over a thousand organizations worldwide at risk of downstream compromise. The exposure came from malicious code inserted into open-source repositories and then pulled into downstream applications used across government, academic, and private-sector environments. The stolen material included credentials, authentication secrets, and source code.
Related Happenings
Miasma source code leak on GitHub
Data Leak
H score32
First: 10.06.2026 23:27
Last: 10.06.2026 23:27
Sources 1
About this happening:
The Miasma source code was briefly leaked on GitHub, exposing malware framework code that could be copied, studied, and modified by other threat actors. The exposure repor...
Miasma source code leak on GitHub
Data LeakAbout this happening: The Miasma source code was briefly leaked on GitHub, exposing malware framework code that could be copied, studied, and modified by other threat actors. The exposure repor...
Nottingham University data publication on ShinyHunters leak site
Data Leak
H score68
First: 10.06.2026 21:31
Last: 10.06.2026 21:31
Sources 1
About this happening:
Nottingham University data was published on the ShinyHunters leak site after the group claimed access to the university’s student records system. The exposed material...
Nottingham University data publication on ShinyHunters leak site
Data LeakAbout this happening: Nottingham University data was published on the ShinyHunters leak site after the group claimed access to the university’s student records system. The exposed material...
Shai-Hulud public GitHub repository credential exposure
Data Leak
H score26
First: 18.05.2026 20:28
Last: 18.05.2026 20:28
Sources 1
About this happening:
Shai-Hulud stole developer credentials that were later exposed in public GitHub repositories, turning a theft phase into a public leak of access data. The exposed mate...
Shai-Hulud public GitHub repository credential exposure
Data LeakAbout this happening: Shai-Hulud stole developer credentials that were later exposed in public GitHub repositories, turning a theft phase into a public leak of access data. The exposed mate...
TeamPCP / Mini Shai-Hulud supply-chain campaign expands across multiple victims
Campaign
H score49
First: 15.05.2026 13:54
Last: 15.05.2026 13:54
Sources 1
How related:
TeamPCP is a hacking group known for widespread supply-chain attacks over the past year that targeted open-source software and developer platforms to steal credentials, authentication secrets, and source code.
About this happening:
The TeamPCP / Mini Shai-Hulud supply-chain campaign is a broad compromise of repository-hosted software and developer ecosystems. Reporting links the activity to packages and proj...
TeamPCP / Mini Shai-Hulud supply-chain campaign expands across multiple victims
CampaignHow related: TeamPCP is a hacking group known for widespread supply-chain attacks over the past year that targeted open-source software and developer platforms to steal credentials, authentication secrets, and source code.
About this happening: The TeamPCP / Mini Shai-Hulud supply-chain campaign is a broad compromise of repository-hosted software and developer ecosystems. Reporting links the activity to packages and proj...
Latest development: 27.08.2026 16:31
Australian authorities arrested and charged two men aged 21 and 23 in Cottesloe and Mandurah, western Australia, over alleged ties to TeamPCP. Investigators also seized electronic devices and other evidence for forensic analysis, and police allege the pair received cryptocurrency payments for involvement in TeamPCP operations.
Mistral AI internal repositories and source code leak
Data Leak
H score35
First: 15.05.2026 01:50
Last: 15.05.2026 01:50
Sources 1
About this happening:
A TeamPCP forum post claims Mistral AI source code and internal repositories were stolen and are now being offered for sale, creating a risk of public release. The alleged...
Mistral AI internal repositories and source code leak
Data LeakAbout this happening: A TeamPCP forum post claims Mistral AI source code and internal repositories were stolen and are now being offered for sale, creating a risk of public release. The alleged...
Timeline
-
27.08.2026 16:31 2 articles · 6h ago
TeamPCP malicious code compromises over a thousand organizations worldwide
Campaign Scope UpdateAustralian authorities said malicious code distributed by TeamPCP had potentially compromised over a thousand organizations worldwide after being injected into open-source repositories and incorporated into downstream applications used across government, academic, and private-sector environments, enabling the theft of half a million credentials and exfiltration of at least 300GB of data.
Show sources
- Australia arrests alleged TeamPCP hackers behind supply-chain attacks — www.bleepingcomputer.com — 27.08.2026 16:31
- Australia arrests alleged TeamPCP hackers behind supply-chain attacks — www.bleepingcomputer.com — 27.08.2026 16:31