PCP, also referred to in the content as the PCP Team, is a threat actor associated with supply chain attacks that compromised AquaSecurity’s trivy-action and the Python litellm package. The reported activity targeted two parts of the software development ecosystem: CI/CD workflows via the trivy-action compromise and local developer environments via the litellm compromise. According to the content, the trivy-action payload was split into a CI runner-dedicated infostealer and a more generic endpoint infostealer, while the poisoned litellm package contained only the CI runner-dedicated infostealer payload. The content states that these attacks propagated through software dependencies and workflow execution, with exposure depending on use of compromised versions and dependency resolution behavior. PCP is explicitly listed among threat actors in the provided content. No nation-state attribution, sub-groups, or additional aliases beyond PCP/PCP Team are directly supported by the content.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
1 indicator attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Conducted supply chain attacks by compromising AquaSecurity's trivy-action and poisoning the Python litellm package, causing malicious code execution in CI/CD workflows and local/developer environments.
Named in the React2Shell threat-actor list; no additional context provided.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.