TeamPCP is a financially motivated cybercriminal threat actor active since at least mid-2025 and prominent from late 2025 onward for large-scale software supply-chain compromises targeting open source ecosystems and cloud-native development workflows. The group is also tracked as UNC6780 and has been referred to by aliases including Storm-2999, ShellForce, deadcatx3, pcpcat, persypcp, and Team_PCP. TeamPCP is associated with malware and campaign names including Shai-Hulud, Mini Shai-Hulud, CanisterWorm, Sandclock, SANDCLOCK, ChainDrop, and Miasma. The actor specializes in compromising trusted developer infrastructure and abusing stolen CI/CD, package-publishing, cloud, and source-control credentials to propagate downstream across ecosystems such as GitHub Actions, npm, PyPI, Docker Hub, OpenVSX, VS Code extensions, and internal repositories. A defining campaign in March 2026 began with compromise of Aqua Security’s Trivy ecosystem through exploitation of a workflow misconfiguration and retained write-capable credentials after incomplete secret rotation. TeamPCP then poisoned Trivy releases and tags, harvested secrets from automated runners, and reused stolen credentials to compromise additional projects including LiteLLM, KICS, Telynx, and other packages. Operations attributed to TeamPCP consistently emphasize credential theft and automated propagation. Reported malware capabilities include collection of environment variables, repository tokens, SSH material, cloud credentials, Kubernetes secrets, package publishing credentials, database credentials, AI-provider keys, and other sensitive data from CI/CD runners and developer systems, including memory scraping on Linux runners. TeamPCP has also used exfiltration through attacker-controlled infrastructure and, in some campaigns, abused victim GitHub accounts to create repositories for staging stolen data. The group demonstrates strong post-exploitation and defense-evasion tradecraft. Windows payloads linked to the actor have used staged loaders, process injection into legitimate processes, APC-based execution, reflective loading via Donut, dynamic API resolution, ETW suppression, AMSI and WLDP bypasses, direct-syscall techniques such as Bouncy Gate, and anti-debugging logic. TeamPCP malware has also established persistence through mechanisms such as Python startup hooks, system services, hidden files, and developer-tool configuration abuse. Some variants have worm-like behavior that repackages and republishes accessible packages at scale using stolen maintainer tokens. TeamPCP’s targeting is broad and opportunistic, centered on organizations that rely on shared build tooling, AI infrastructure, package registries, and automated software delivery pipelines. Victim exposure has spanned thousands of organizations globally across technology, industrial, financial, government, and other sectors. The actor’s dominant objective is theft and monetization of access, credentials, and downstream compromise opportunities. Reporting in 2026 also linked TeamPCP-sourced credentials to at least one verified ransomware deployment by the Vect group, indicating that the actor’s stolen-access pipeline can support broader criminal monetization beyond pure data theft.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
44 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
31 malware families attributed to this actor across reporting.
26 additional families tracked in Mallory.
7 CVEs this actor has used in observed campaigns. 7 of them exploited in the wild.
The earlier stage targeted Trivy, Aqua Security’s widely used vulnerability scanner. On March 19, attackers used compromised credentials to publish a malicious Trivy v0.69.4 release, force-push malicious changes to 76 of 77 affected trivy-action version tags and replace the affected setup-trivy tags. The incident is tracked as CVE-2026-33634, which NIST’s National Vulnerability Database classifies as a known exploited vulnerability and which CISA added to its Known Exploited Vulnerabilities catalog.
That progression ran through PCPcat, which peaked around Christmas 2025 against React2Shell targets and exposed Docker APIs.
The tracking identifier is CVE-2026-45321 (CVSS 9.6 per The Hacker News; advisory GHSA-g7cv-rxg3-hmpx per Snyk).
Analysis of react.py This script is clearly set to exploit CVE-2025-29927, also known as React2Shell. ... This script implements a fully automated React/Next.js exploitation pipeline centered on abusing CVE-2025-29927 to achieve remote command execution at scale.
The four CVEs associated with this campaign are CVE-2026-33634, CVE-2026-48027, CVE-2026-45321, and CVE-2025-55182.
2 more CVEs tied to this actor tracked in Mallory.
567 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Conducted a large-scale software supply chain attack beginning with compromise of the Aqua Trivy VS Code extension, then abused stolen write-capable credentials to tamper with Trivy GitHub Actions tags and release a trojanized Trivy scanner. The embedded infostealer harvested secrets from CI/CD runners and enabled follow-on compromises including Docker Hub, Checkmarx GitHub Actions, the npm ecosystem, and malicious LiteLLM packages on PyPI.
Conducting open source software supply chain attacks that began with a compromised Trivy build and propagated downstream into packages such as LiteLLM, using worm-like malware to steal credentials, tokens, API keys, and other secrets and to push further malicious package versions.
Conducted a chained software supply-chain attack by backdooring the Trivy GitHub Action, stealing LiteLLM PyPI publishing tokens, publishing malicious LiteLLM packages, and harvesting secrets from compromised GitHub Actions / CI-CD runners at scale.
Associated actors are described as likely to continue abusing stolen credentials obtained via the March supply-chain compromise of malicious PyPI packages targeting LiteLLM build pipelines.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.