TeamPCP is a financially motivated cybercriminal threat actor active since at least late 2025 and widely tracked for large-scale software supply-chain intrusions, cloud credential theft, and follow-on extortion activity. Known aliases include DeadCatx3, PCPcat, Persy_PCP, ShellForce, Storm-2999, Team_PCP, and UNC6780. The group has also been associated with the Shai-Hulud campaign name and with the CanisterWorm propagation component used in parts of its operations. The actor initially drew attention through opportunistic exploitation of exposed or misconfigured cloud services, including Docker and Kubernetes environments, before evolving into a more consequential campaign centered on trusted developer tooling and CI/CD infrastructure. In March 2026, TeamPCP was linked to a cascading supply-chain operation that compromised multiple widely used projects and ecosystems, including Aqua Security Trivy, Checkmarx GitHub Actions and related components, and LiteLLM, with subsequent expansion into additional package ecosystems. A defining characteristic of this campaign was credential chaining: secrets stolen from one victim’s CI/CD environment were reused to compromise upstream maintainers, downstream projects, or adjacent software publishers, enabling rapid lateral expansion across trust relationships. TeamPCP’s tradecraft consistently emphasized credential harvesting from ephemeral build environments, developer systems, and cloud workloads. Observed payloads harvested GitHub and other CI/CD tokens, cloud provider credentials, SSH material, Kubernetes configuration and service-account data, package publishing credentials, environment files, database secrets, API keys, and other sensitive artifacts. The group repeatedly targeted security-adjacent and developer-centric tools because those products commonly execute in privileged environments with broad access to secrets and infrastructure. In CI/CD contexts, TeamPCP was observed abusing mutable release tags and poisoned package releases to execute malicious code while preserving normal workflow output, increasing dwell time and reducing immediate detection. A notable technical hallmark of TeamPCP operations is memory scraping of CI runner processes to recover secrets that would otherwise evade simple file-based collection. Additional recurring behaviors include broad filesystem credential discovery, encrypted staging of stolen data, fallback exfiltration through victim-controlled developer platforms, and persistence mechanisms on non-ephemeral Linux hosts using user-level service installation. Some reporting also links the actor to resilient command-and-control or dead-drop patterns leveraging decentralized infrastructure. Beyond credential theft, TeamPCP has been associated with worm-like propagation across software ecosystems and cloud-native environments. CanisterWorm, attributed in multiple reports to the group, used stolen package publishing credentials to spread malicious updates across npm and related environments. TeamPCP activity has also been tied to Kubernetes-focused post-compromise actions, including privileged workload deployment for persistence and lateral movement. Some reporting describes destructive functionality or locale-gated wiping behavior in certain campaign phases, indicating the actor’s operations can extend beyond espionage and theft into sabotage under selected conditions. The group’s operations have had significant downstream impact on enterprises and public-sector organizations because compromised tools were embedded in CI/CD pipelines and production workflows at scale. Public reporting has linked TeamPCP-enabled credential theft to major secondary breaches, including compromises of large SaaS and governmental environments. The actor has also been connected to data-only extortion and to monetization partnerships with ransomware or extortion actors, particularly Vect, suggesting an operational model in which supply-chain compromise and credential harvesting serve as scalable initial access for later extortion. Overall, TeamPCP is best characterized as a fast-moving, financially motivated intrusion set that operationalized software supply-chain compromise, CI/CD secret theft, and credential cascade effects into a broad access-and-extortion model. Its most distinctive features are sequential compromise of trusted developer infrastructure, aggressive reuse of stolen credentials across ecosystems, and targeting of cloud-native build and deployment environments where a single poisoned dependency can expose large numbers of downstream organizations.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
49 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
32 malware families attributed to this actor across reporting.
27 additional families tracked in Mallory.
7 CVEs this actor has used in observed campaigns. 7 of them exploited in the wild.
CVE-2026-33634 (CVSS 9.8 Critical) covers the Trivy binary and GitHub Actions compromise... The chain began in late February 2026, when a misconfigured GitHub Actions workflow in the Trivy repository allowed the hackerbot-claw bot to exploit a pull_request_target vulnerability, stealing a personal access token with write privileges.
The tracking identifier is CVE-2026-45321 (CVSS 9.6 per The Hacker News; advisory GHSA-g7cv-rxg3-hmpx per Snyk).
Initially gaining attention through the React2Shell campaign (CVE-2025-55182), which leveraged remote code execution against cloud endpoints.
Analysis of react.py This script is clearly set to exploit CVE-2025-29927, also known as React2Shell. ... This script implements a fully automated React/Next.js exploitation pipeline centered on abusing CVE-2025-29927 to achieve remote command execution at scale.
The four CVEs associated with this campaign are CVE-2026-33634, CVE-2026-48027, CVE-2026-45321, and CVE-2025-55182.
2 more CVEs tied to this actor tracked in Mallory.
553 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned as a comparison/possible false-flag reference; the article explicitly states the malware is not attributed to this campaign.
Named as part of the growing trend of data-only extortion without encryption.
Conducting the Shai-Hulud supply-chain campaign by sequentially compromising developer tooling and package ecosystems to steal credentials, backdoor packages, and spread downstream through CI/CD and package publishing infrastructure.
Mentioned only as part of prior campaigns that the malware may be trying to imitate; explicitly not attributed to the current incident.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.