Oligo Security has linked TeamPCP to ShadowRay 2.0 and to cryptojacking infrastructure dating back to 2020

New research indicates that TeamPCP, a group recently implicated in a series of supply chain attacks on open-source developer tools, has been active since at least 2020, sharing infrastructure and tactics with earlier cryptojacking operations. Oligo Security, in collaboration with Mandiant and GitLab, published findings on August 5, 2026, linking TeamPCP to activities previously tracked as TA-NATALSTATUS, which spanned from 2020 to August 2025. GitLab confirmed the investigation and has banned the accounts identified as involved.
The investigation established a strong link between TeamPCP and the ShadowRay 2.0 campaign, which targeted exposed Ray clusters in November 2025. Oligo Security had initially attributed ShadowRay 2.0 to an actor named IronErn440, but now assesses that TeamPCP was responsible. The primary infrastructural connection identified across TA-NATALSTATUS, ShadowRay 2.0, and TeamPCP operations is the domain masscan[.]cloud, which certificate transparency records show was registered on May 11, 2025. TeamPCP's own GitHub account later listed this domain as its official website.
Further evidence of continuity includes the reuse of a distinctive deployment framework. This framework, characterized by a specific directory path and a set of staging scripts, was documented in earlier TA-NATALSTATUS campaigns and appeared unchanged in TeamPCP payloads. A compromised Ray cluster was observed downloading from this infrastructure on July 26, 2025, several months before the TeamPCP name became publicly known.
Direct evidence from GitLab further solidified the connection. An IP address received reverse shells from a compromised Ray cluster between October 15 and November 2. All these shell sessions ceased on November 2. Subsequently, between November 2 and November 4, the ironern440 account authenticated to GitLab from the same IP address, which was also hosting the campaign's tooling.
Oligo's timeline suggests that the operators began exploiting internet-facing infrastructure as early as 2020, often employing automated and wormable techniques, primarily for cryptojacking. Their activities then expanded to include GitHub Actions abuse and token theft. This progression led to campaigns like PCPcat, which peaked around Christmas 2025, targeting React2Shell vulnerabilities and exposed Docker APIs. These activities then evolved into the March 2026 compromises of Trivy, Checkmarx's KICS, and LiteLLM.
Beyond exploitation, the infrastructure also broadened to support other malicious activities, with subdomains observed facilitating credential phishing, payment fraud, and Zendesk impersonation. In late March, a second-stage Kubernetes payload developed a destructive capability. This script was designed to check if the victim system's timezone was set to Iran. If so, it would deploy a destructive workload that deleted filesystems and rebooted the machine. Oligo noted that Iranian internet connectivity was significantly disrupted at the time, which may have limited visibility into whether this destructive payload was ever successfully executed.
While the evidence strongly suggests operational continuity, Oligo Security cautioned against definitive attribution regarding the exact nature of the relationship. It remains uncertain whether the continuity reflects a direct rebrand, a shared set of operators, or close collaboration between related actors. However, the research clearly indicates that TeamPCP is not a newly formed group that emerged in late 2025, but rather a continuation of an established operational ecosystem.

Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5. Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4. "Sansec is publishing early

Attackers are exploiting two new PaperCut flaws to steal credentials and gain privileged access in education-sector attacks across the U.S. and Europe. Attackers are exploiting two recelty disclosed PaperCut flaws, CVE-2026-81578 and CVE-2026-82078, in attacks targeting schools and other education organizations in the U.S. and Europe, as reported by TheHackerNews. Arctic Wolf researchers observed

JetBrains is urging Cadence users to revoke and rotate all credentials following a security incident last month in which unidentified threat actors exploited a recently disclosed critical vulnerability in TeamCity to breach its own environment. "Cadence users should immediately revoke or rotate all credentials and secrets that may have been used to run their Cadence executions," JetBrains said.

Broadcom has released security updates for two security flaws impacting VMware Workstation and Fusion, including one critical bug that could result in arbitrary code execution under certain conditions. The vulnerability, tracked as CVE-2026-59346 (CVSS score: 9.3), is an integer-overflow vulnerability that a local attacker with elevated privileges can exploit to run arbitrary code. "A

A massive cybercriminal operation is leveraging thousands of compromised small-business websites to deliver ClickFix payloads stored in smart contracts on the BNB Smart Chain (BSC). [...]

Hardware wallet manufacturer Trezor on Friday disclosed that another 67,000 customers from the U.S. have been impacted in a breach at its shipping provider ShipMonk. The exposed information includes customer names, email addresses, phone numbers, shipping addresses, and order numbers between November 2019 and August 2021. The breach does not affect the security of the company's hardware wallets