Story perspectives
TeamPCP Hijacks 5,500 GitHub Repos, Steals Cloud Credentials
5/25/2026
1 of 2
TeamPCP Compromises GitHub
- On May 18, 2026, U.S. threat group TeamPCP compromised 5,561 public GitHub repositories.
- Attackers injected CI/CD workflows that exfiltrated cloud credentials, SSH keys and tokens to 216.126.225[.]129:8443.
- Two workflow variants appeared: SysDiag on every push/pull and Optimize-Build on manual dispatch.
- Attackers pushed 5,718 malicious commits via forged bot IDs and Polymarket-impersonating npm packages with post-install hooks, prompting SafeDep to release a CSV of the repos after wiper malware hit Iran and Israel.
1 / 2
