PULSE NAME
The Worm That Keeps on Digging: TeamPCP Hits @antv in Latest Wave
WHITE Teampcp PetrP.73 2026-05-21 Modified: 2026-05-22
5
IOCs
LOW VOLUME
TeamPCP has reemerged as a threat actor involved in a multi-ecosystem supply chain compromise affecting open-source software components, specifically targeting GitHub, NPM packages, and a VSCode extension. The campaign, which was observed on May 19th, uses distributed malware designed to extract credentials, exfiltrate sensitive information, and ensure continued access to infected systems. This malware primarily targets the npm packages within the @antv namespace, GitHub Actions like actions-cool/issues-helper, and the nrwl.angular-console VSCode extension.
Indicators of Compromise (1 / 5 total)
All FileHash-MD5 FileHash-SHA1 FileHash-SHA256 IPv4 domain
TYPEINDICATORDESCRIPTIONCREATED
FileHash-SHA256 fb5c97557230a27460fdab01fafcfabeaa49590bafd5b6ef30501aa9e0a51142 2026-05-21