How TeamPCP’s Bounty Competition Resulted in a GitHub Breach

Most software supply-chain attacks do not involve an entry requirement or a financial prize. However, the campaign launched by TeamPCP against GitHub repositories in May 2026 included both. What began as a forum announcement promising a $1,000 Monero reward developed into a coordinated competition targeting the software supply chain. The organizers published formal rules, supplied the necessary tools, and even provided a self-propagating worm at no additional cost. By the end of the operation, approximately 3,800 private GitHub repositories had reportedly been offered for sale.

Executive Summary

In May 2026, TeamPCP collaborated with BreachForums administrators to launch what the organizers described as a “Supply Chain Competition.” The initiative was deliberately structured to encourage and crowdsource attacks against software supply chains. To attract as many participants as possible, the organizers released the source code of the Shai Hulud worm, distributed it through the forum’s own content delivery network, and required every contestant to use it.

Several weeks later, the same group claimed to have obtained GitHub source code and access to approximately 4,000 private repositories. The stolen information was offered for sale at a starting price of $50,000. GitHub subsequently confirmed that around 3,800 internal repositories had been compromised. The company traced the initial intrusion to an employee who installed a malicious release of the Nx Console extension, which had been compromised as part of an npm supply-chain attack. Although the two incidents occurred several weeks apart, they form a single narrative demonstrating how rapidly and inexpensively the open-source ecosystem can be turned into an attack vector.

The Competition: Crowdsourcing Software Compromise

Most software supply-chain attacks are conducted by an individual threat actor or a single organized group. TeamPCP reversed this conventional model by inviting anyone with internet access and minimal ethical restraint to participate. By supplying both a monetary reward and the specific tools required to conduct the attacks, the organizers eliminated almost every technical and financial barrier to participation.

The competition followed a straightforward structure:

  • A financial reward: A prize of $1,000 in Monero was offered to the participant who compromised the packages with the highest download numbers. This approach directly rewarded both the scale and potential impact of the attack.
  • Required attack tooling: Every participant had to use the “Shai Hulud” worm. The malware was distributed through the forum’s own CDN, allowing all contestants to operate with the same capable and standardized attack mechanism.
  • Support from the forum’s administration: The competition was jointly organized with BreachForums administrators, giving it greater visibility and perceived legitimacy within the cybercriminal community.

Instead of relying on a single group to compromise the software supply chain, TeamPCP effectively assembled a volunteer attack force. Every participant received the same weapon and was simultaneously directed toward the broader open-source ecosystem.

The Consequences: Examining the GitHub Breach

On May 19, TeamPCP claimed to have accessed approximately 4,000 private repositories. The stolen data was listed for sale on an underground forum, with prices beginning at $50,000. GitHub later confirmed that roughly 3,800 internal repositories had been compromised. The attack chain developed as follows:

  1. An upstream npm supply-chain compromise affecting TanStack: The initial intrusion affected dozens of npm packages. One of those packages was used by a widely adopted Visual Studio Code extension.
  2. A compromised version of the Nx Console extension: A GitHub employee installed the trojanized version of the extension. This provided the attackers with an initial foothold on an internal device.
  3. Compromised CI/CD credentials: The attackers then used stolen continuous-integration and deployment credentials to move into additional projects. This significantly expanded the impact beyond the originally compromised package.

GitHub responded by removing the malicious extension from the Visual Studio Marketplace and securing the affected device. However, these actions came after the compromise had already occurred. The operation progressed from a poisoned npm package to the extraction of thousands of private repositories. TeamPCP’s competition therefore accomplished its stated objective: compromising the open-source software pipeline on a large scale.

Why Open-Source Ecosystems Have Become Major Targets

GitHub was not the campaign’s only target. RubyGems, the primary package-management platform for Ruby, temporarily disabled new account registrations during the previous month after detecting a coordinated malicious campaign. Automated bot accounts uploaded more than 500 malicious or low-quality packages. At the same time, researchers identified a previously unseen campaign known as “GemStuffer,” which exploited the registry as a dead-drop channel for data exfiltration. Instead of using the packages to distribute malware, GemStuffer relied on malicious Ruby gems to store information collected from local council portals operated by the U.K. government. This technique completely eliminated the need to maintain dedicated command-and-control infrastructure.

The actors and techniques differ, but the broader pattern remains consistent. Threat actors are finding increasingly creative ways to weaponize the open-source ecosystems on which the software industry relies. These environments may serve as malware distribution channels, mechanisms for extracting stolen information, or, as demonstrated by TeamPCP, arenas for crowdsourced competitions designed to cause the greatest possible damage.

Key Lessons for Security Teams

Software supply chains should be treated as targets of deliberate and continuous campaigns rather than as systems exposed only to occasional opportunistic attacks. The existence of financial bounties for poisoning software packages represents a fundamental change in the threat model. Security planning must therefore account for coordinated and financially incentivized operations, not only isolated compromises.

CI/CD credentials should be protected as some of the organization’s most sensitive assets. The GitHub incident expanded through stolen continuous-integration and deployment credentials. Such credentials should be rotated frequently, restricted to the minimum required permissions, and continuously monitored for unusual or unauthorized activity.

Developer tools must be evaluated as potential supply-chain risks. In this incident, a single compromised code-editor extension provided the initial point of access. Organizations should maintain a controlled inventory of approved IDE and editor extensions. Developer workstations should also be treated as high-value security targets.

The integrity of dependencies and software registries must be continuously monitored. Package registries are increasingly being exploited for both malware delivery and data exfiltration. The origin and integrity of every downloaded package should therefore be verified. Trust in a package registry should not automatically be extended to every package available through that platform.

TeamPCP’s bounty initiative represents only one of several software supply-chain incidents examined in this month’s report. The complete May 2026 Cyber Threat Intelligence Report provides a detailed analysis, information about related incidents, and the relevant indicators required by security teams.

Cynet is an XDR platform that combines EDR, EPP, NDR, ITDR, SOAR, email protection, SaaS and cloud security, mobile security, and many other capabilities within a single solution. Organizations interested in evaluating the platform and obtaining a trial version can submit their contact information using the form below.

Get Cynet Demo



    Subscribe to news