Find notable cyber news and cases, enriched with sources, timelines, and signals.

TeamPCP supply-chain credential and data leak

Data Leak
First reported
Last updated
Happening score
H score 59
1 unique sources, 1 articles

Summary

Hide ▲

A TeamPCP-linked supply-chain leak exposed half a million credentials and at least 300GB of data, putting over a thousand organizations worldwide at risk of downstream compromise. The exposure came from malicious code inserted into open-source repositories and then pulled into downstream applications used across government, academic, and private-sector environments. The stolen material included credentials, authentication secrets, and source code.

Related Happenings

Miasma source code leak on GitHub

Data Leak
H score32 First: 10.06.2026 23:27 Last: 10.06.2026 23:27 Sources 1

About this happening: The Miasma source code was briefly leaked on GitHub, exposing malware framework code that could be copied, studied, and modified by other threat actors. The exposure repor...

Nottingham University data publication on ShinyHunters leak site

Data Leak
H score68 First: 10.06.2026 21:31 Last: 10.06.2026 21:31 Sources 1

About this happening: Nottingham University data was published on the ShinyHunters leak site after the group claimed access to the university’s student records system. The exposed material...

Shai-Hulud public GitHub repository credential exposure

Data Leak
H score26 First: 18.05.2026 20:28 Last: 18.05.2026 20:28 Sources 1

About this happening: Shai-Hulud stole developer credentials that were later exposed in public GitHub repositories, turning a theft phase into a public leak of access data. The exposed mate...

TeamPCP / Mini Shai-Hulud supply-chain campaign expands across multiple victims

Campaign
H score49 First: 15.05.2026 13:54 Last: 15.05.2026 13:54 Sources 1

How related: TeamPCP is a hacking group known for widespread supply-chain attacks over the past year that targeted open-source software and developer platforms to steal credentials, authentication secrets, and source code.

About this happening: The TeamPCP / Mini Shai-Hulud supply-chain campaign is a broad compromise of repository-hosted software and developer ecosystems. Reporting links the activity to packages and proj...

Latest development: 27.08.2026 16:31

Australian authorities arrested and charged two men aged 21 and 23 in Cottesloe and Mandurah, western Australia, over alleged ties to TeamPCP. Investigators also seized electronic devices and other evidence for forensic analysis, and police allege the pair received cryptocurrency payments for involvement in TeamPCP operations.

Mistral AI internal repositories and source code leak

Data Leak
H score35 First: 15.05.2026 01:50 Last: 15.05.2026 01:50 Sources 1

About this happening: A TeamPCP forum post claims Mistral AI source code and internal repositories were stolen and are now being offered for sale, creating a risk of public release. The alleged...

Timeline

  1. 27.08.2026 16:31 2 articles · 6h ago

    TeamPCP malicious code compromises over a thousand organizations worldwide

    Campaign Scope Update

    Australian authorities said malicious code distributed by TeamPCP had potentially compromised over a thousand organizations worldwide after being injected into open-source repositories and incorporated into downstream applications used across government, academic, and private-sector environments, enabling the theft of half a million credentials and exfiltration of at least 300GB of data.

    Show sources