PCP, also referred to as Team PCP, is a threat actor associated with software supply-chain compromises targeting developer tooling and package ecosystems. The group is known for compromising Aqua Security’s trivy-action and the Python litellm package in 2026. These operations were designed to propagate malicious code through CI/CD workflows, local developer environments, and downstream software dependencies. In the trivy-action incident, PCP compromised a widely used GitHub Action in a manner that exposed repositories that referenced affected tags and executed workflows during the compromise window. The operation used an infostealer tailored for CI runners, and reporting also identified a more generic endpoint-focused infostealer associated with the broader campaign. In the litellm incident, PCP poisoned a Python package so that dependent environments could retrieve and execute a malicious version through normal dependency resolution. That package compromise was assessed as primarily targeting local environments, although it also created downstream risk through direct and optional dependencies in other packages. PCP’s observed tradecraft centers on initial access through trusted software distribution channels rather than direct intrusion into victim networks. The actor’s capabilities include supply-chain initial access, credential and secret theft from developer and CI environments, exfiltration of collected data, and post-exploitation activity on compromised hosts. The campaigns demonstrate an emphasis on abusing ecosystem trust relationships to achieve broad reach across software development pipelines. High-profile organizations were identified among potentially affected users of the compromised software, but the actor’s targeting in these incidents is best characterized as opportunistic and ecosystem-wide rather than narrowly sector-specific. Available information directly supports financially motivated theft-oriented activity, but does not support attribution to a nation-state or a specific country of origin at high confidence.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
1 indicator attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Conducted supply chain attacks by compromising AquaSecurity's trivy-action and poisoning the Python litellm package, causing malicious code execution in CI/CD workflows and local/developer environments.
Named in the React2Shell threat-actor list; no additional context provided.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.