kamikazesh is an iteratively developed follow-on payload used by the threat actor TeamPCP during the 2026 compromise of Aqua Security’s Trivy ecosystem and related software supply chain activity. It was delivered through an Internet Computer Protocol canister polled by a persistent Linux backdoor installed on affected developer systems, and was updated rapidly across multiple versions during active operations.
The payload family was associated with post-compromise activity on Linux systems, particularly in Kubernetes-oriented environments. Reported capabilities included deployment as a Kubernetes DaemonSet, host escape from containers, establishment of systemd-based persistence, and destructive wiping behavior targeted at systems associated with Iran, including checks tied to Tehran timezone or Persian locale before executing destructive actions. The broader TeamPCP toolchain around this payload also supported credential collection, secret theft, encrypted exfiltration, and propagation across cloud-native and developer environments.
kamikazesh formed part of a larger multi-stage intrusion chain in which compromised Trivy artifacts and poisoned GitHub Actions were used to steal secrets and implant persistence. On developer machines, the malicious Trivy component installed a systemd-backed Python dropper that periodically polled attacker-controlled ICP infrastructure for follow-on payloads such as kamikazesh. The malware therefore functioned as a modular second-stage capability within a supply-chain-driven campaign affecting Linux developer hosts and Kubernetes-connected environments.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
On March 22, TeamPCP rotated through six payload versions in approximately five hours via the ICP canister, each one picked up by every infected machine on its next poll: Time (UTC) Version Capability ~11:45 v1 Monolithic K8s DaemonSet with host escape, systemd persistence, Iran-targeted wiper.
26 distinct techniques documented for this family, organized by ATT&CK tactic.
Wiz Research, in concert with other industry parties, identified a multi-faceted supply chain attack targeting Aqua Security's Trivy. The attack compromised multiple components of the Trivy project: the core scanner, the trivy-action GitHub Action, and the setup-trivy GitHub Action.
The attacker force-pushed 110+ version tags across aquasecurity/trivy-action, aquasecurity/setup-trivy, Checkmarx/kics-github-action, and Checkmarx/ast-github-action, replacing them with malicious commits containing a three-stage credential stealer... Stolen npm tokens then fuelled CanisterWorm...
Version 1 - Monolithic Architecture : A 150-line bash script focused on environment fingerprinting and immediate credential harvesting... Version 2 also introduced a self-deletion command rm – “$0” to remove itself after execution.
By March 22, the ICP-hosted fallback C2 was actively serving an iteratively developed payload designated kamikaze.sh.
the malware attempts to create persistence by writing a python script as ~/.config/systemd/user/sysmon.py... sysmon.py initially sleeps for five minutes and then polls https://tdtqy-oyaaa-aaaae-af2dq-cai.raw.icp0.io/
On Kubernetes clusters, the kamikaze.sh payload deployed privileged DaemonSets with hostPath: / mounts in the kube-system namespace. Standard backdoor deployments used the host-provisioner-std DaemonSet name. Iranian-targeted nodes received host-provisioner-iran instead.
It bypassed GitHub’s secret masking by reading the runner.worker process memory directly via /proc/<pid>/mem to extract plaintext tokens.
The files carried authentic RIFF headers and presented as legitimate 8-bit mono audio at 44100 Hz to file type detection systems.
Version 3.3 introduced the most technically notable technique: Python payloads embedded as base64-encoded data inside valid WAV audio files.
On compromised hosts, TeamPCP installed systemd services named pgmon.service, pgmonitor.service, or internal-monitor.service with Restart=always, masquerading as PostgreSQL monitoring tooling.
It bypassed GitHub’s secret masking by reading the runner.worker process memory directly via /proc/<pid>/mem to extract plaintext tokens.
It bypassed GitHub’s secret masking by reading the runner.worker process memory directly via /proc/<pid>/mem to extract plaintext tokens.
sysmon.py initially sleeps for five minutes and then polls https://tdtqy-oyaaa-aaaae-af2dq-cai.raw.icp0.io/.
3 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
Other indicator types observed in public reporting.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.