Drooid Logo
Back to today’s briefing

Story perspectives

TeamPCP Hijacks 5,500 GitHub Repos, Steals Cloud Credentials

5/25/2026

26 2 Full Breakdown

1 of 2

TeamPCP Compromises GitHub
  • On May 18, 2026, U.S. threat group TeamPCP compromised 5,561 public GitHub repositories.
  • Attackers injected CI/CD workflows that exfiltrated cloud credentials, SSH keys and tokens to 216.126.225[.]129:8443.
  • Two workflow variants appeared: SysDiag on every push/pull and Optimize-Build on manual dispatch.
  • Attackers pushed 5,718 malicious commits via forged bot IDs and Polymarket-impersonating npm packages with post-install hooks, prompting SafeDep to release a CSV of the repos after wiper malware hit Iran and Israel.
1 / 2