← Back to Pulse Feed
PULSE DETAIL
PULSE NAME
The Worm That Keeps on Digging: TeamPCP Hits @antv in Latest Wave
TeamPCP has reemerged as a threat actor involved in a multi-ecosystem supply chain compromise affecting open-source software components, specifically targeting GitHub, NPM packages, and a VSCode extension. The campaign, which was observed on May 19th, uses distributed malware designed to extract credentials, exfiltrate sensitive information, and ensure continued access to infected systems. This malware primarily targets the npm packages within the
@antv namespace, GitHub Actions like actions-cool/issues-helper, and the nrwl.angular-console VSCode extension.
MITRE ATT&CK & Malware Families
Indicators of Compromise (1 / 5 total)
| TYPE | INDICATOR | DESCRIPTION | CREATED | |
|---|---|---|---|---|
| FileHash-MD5 | b06b126b9e26af03a7ef2f8b8e90d446 | — | 2026-05-21 |