PULSE NAME
The Worm That Keeps on Digging: TeamPCP Hits @antv in Latest Wave
WHITE Teampcp PetrP.73 2026-05-21 Modified: 2026-05-22
5
IOCs
LOW VOLUME
TeamPCP has reemerged as a threat actor involved in a multi-ecosystem supply chain compromise affecting open-source software components, specifically targeting GitHub, NPM packages, and a VSCode extension. The campaign, which was observed on May 19th, uses distributed malware designed to extract credentials, exfiltrate sensitive information, and ensure continued access to infected systems. This malware primarily targets the npm packages within the @antv namespace, GitHub Actions like actions-cool/issues-helper, and the nrwl.angular-console VSCode extension.
Indicators of Compromise (1 / 5 total)
All FileHash-MD5 FileHash-SHA1 FileHash-SHA256 IPv4 domain
TYPEINDICATORDESCRIPTIONCREATED
FileHash-MD5 b06b126b9e26af03a7ef2f8b8e90d446 2026-05-21