TeamPCP is a financially motivated cybercriminal group that emerged in late 2025 and specializes in software supply-chain compromise, developer credential theft, and follow-on intrusions. It is also tracked as UNC6780, Storm-2999, and ShellForce; associated aliases and handles include Team_PCP, deadcatx3, pcpcat, and persypcp. Its operations target open-source maintainers, developer workstations, package registries, source-code repositories, and corporate CI/CD infrastructure, with downstream exposure across technology, telecommunications, financial services, and government organizations. During 2026, TeamPCP conducted interconnected compromises affecting Aqua Security’s Trivy, Checkmarx tooling, LiteLLM, Telnyx’s Python SDK, and TanStack packages. Its attack model uses stolen service-account and package-publishing credentials to distribute malicious software, harvest additional secrets from downstream environments, and compromise further projects. Techniques include modifying existing GitHub Actions version tags, poisoning build and release artifacts, abusing package installation and Python interpreter startup mechanisms, and distributing self-propagating malicious package updates. Harvested material includes cloud credentials, source-control tokens, SSH keys, Kubernetes secrets, registry authentication, and AI-service API keys. Malware associated with TeamPCP includes CanisterWorm, SANDCLOCK, Mini Shai-Hulud, and Miasma. Its payloads perform encrypted exfiltration, use victim-controlled GitHub repositories as alternative collection channels, install persistent backdoors, and retrieve secondary payloads. Kubernetes-capable payloads enumerate secrets and can deploy privileged pods to implant backdoors on cluster nodes when existing permissions allow. TeamPCP also uses obfuscation and infrastructure impersonating legitimate software vendors. It adopted the Shai-Hulud name for its 2026 operations and publicly released worm code; the original 2025 Shai-Hulud campaigns have not been definitively attributed to the group. TeamPCP has collaborated with other cybercriminal groups, including ShinyHunters and Vect, to monetize stolen credentials and facilitate extortion. Australian authorities arrested two Western Australian men in August 2026 over alleged principal roles in TeamPCP; those allegations remain unproven. The group’s stolen credentials can support additional intrusions after malicious packages have been removed.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
58 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
23 malware families attributed to this actor across reporting.
18 additional families tracked in Mallory.
7 CVEs this actor has used in observed campaigns. 7 of them exploited in the wild.
The chain that reached the widest set of victims ran through Trivy into LiteLLM... The ecosystem flaw is tracked as CVE-2026-33634 and was added to CISA’s Known Exploited Vulnerabilities catalog on 26 March 2026.
During February, the group expanded its exploitation to include CVE-2025-29927 and CVE-2025-55182. In December 2025, TeamPCP's PCPcat operation targeted React2Shell-vulnerable applications and exposed Docker APIs with ransomware.
The tracking identifier is CVE-2026-45321 (CVSS 9.6 per The Hacker News; advisory GHSA-g7cv-rxg3-hmpx per Snyk).
During February, masscan[.]cloud again resolved to 44.252.85.168 and 67.217.57.240. During this period, the group expanded its exploitation to include CVE-2025-29927 and CVE-2025-55182, targeting a broad range of internet-facing technologies including AWS, Anyscale’s Ray, Docker, Kubernetes, Linux, Meta React, Microsoft Azure, Redis, and Vercel Next.js.
The four CVEs associated with this campaign are CVE-2026-33634, CVE-2026-48027, CVE-2026-45321, and CVE-2025-55182.
2 more CVEs tied to this actor tracked in Mallory.
612 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Identified as the group behind Shai-Hulud's origins, with members reportedly arrested in August. The article does not attribute the tensorlake compromise to TeamPCP; it suggests an independent actor or copycat may be reusing the malware and name.
A cybercriminal group cited as an example of AI-related supply-chain risk. The article describes TeamPCP targeting LiteLLM package versions used to build AI-powered applications, resulting in widespread credential theft.
A supply-chain-focused criminal group that compromises software publishers and CI/CD infrastructure, steals credentials, distributes malicious package updates and self-propagating worms, conducts data theft and extortion, and uses stolen access to enable follow-on attacks. The group published an open-source Mini Shai-Hulud variant and reportedly partnered with other extortion and ransomware groups.
An upstart cybercrime group reported to have compromised global code supply chains with malicious software and stolen credentials, which were subsequently used in extortion activity.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.