TeamPCP is a financially motivated cybercriminal threat actor known for large-scale compromises of cloud-native infrastructure and the open-source software supply chain. The group has been publicly active since late 2025 and is assessed by some researchers to have operational history reaching back to at least 2020. Known aliases include deadcatx3, pcpcat, persypcp, shellforce, storm_2999, team_pcp, teampcp_unc6780, and unc6780. TeamPCP has also been linked to activity clusters referred to as IronErn, ShadowRay 2.0, TA-NATALSTATUS, and Operation PCPcat. TeamPCP initially focused on opportunistic exploitation of exposed or misconfigured internet-facing services, including Docker, Kubernetes, Redis, Ray, and React or Next.js-related weaknesses. Early operations included credential theft, cryptocurrency mining, botnet-style propagation, and compromise of AI-related infrastructure. The actor has repeatedly used automated and wormable exploitation to scale intrusions, and has shown a pattern of rapidly adapting payloads and infrastructure. In 2026, TeamPCP became especially notable for aggressive software supply-chain attacks affecting widely used developer and security tooling. High-confidence reporting links the group to compromises involving Trivy, Checkmarx KICS, LiteLLM, the Telnyx Python SDK, and broad npm package poisoning campaigns. TeamPCP abused stolen GitHub and npm credentials, misconfigured CI/CD workflows, mutable release tags, and trusted publishing paths to distribute credential-stealing malware through legitimate package and release channels. Malware associated with the group, including Shai-Hulud and Mini Shai-Hulud lineages, harvested cloud credentials, GitHub tokens, SSH keys, Kubernetes secrets, Terraform data, Vault tokens, and CI/CD secrets from developer workstations and build environments, then used stolen publish credentials to republish additional malicious packages and expand laterally across maintainers and ecosystems. The actor’s tradecraft includes initial access through exposed services and CI/CD workflow abuse, persistence via user-level services and backdoors, credential theft from disk and process memory, exfiltration using encrypted archives, decentralized or resilient command-and-control mechanisms, and self-propagating worms across package ecosystems and Kubernetes environments. TeamPCP has also demonstrated destructive capability: newer malware variants reportedly included wiper-like logic that selectively targeted systems associated with Iran, while deploying alternate backdoor or worm functionality elsewhere. TeamPCP’s operations have had substantial downstream impact on enterprise SaaS and cloud environments because the group targeted foundational developer dependencies and security tools embedded in automated pipelines. The actor has also been linked to ransomware monetization and extortion through cooperation with Vect, and reporting indicates use of stolen access and data to support double-extortion activity. Overall, TeamPCP is characterized by rapid, noisy, high-scale campaigns that prioritize credential theft, propagation, and monetization over stealth.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
51 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
32 malware families attributed to this actor across reporting.
27 additional families tracked in Mallory.
7 CVEs this actor has used in observed campaigns. 7 of them exploited in the wild.
19 mars 2026 : Compromission de Trivy (scanner de vulnérabilités Aqua Security) via un tag malveillant v0.69.4 ( CVE-2026-33634 , CVSS v4 : 9.4). Propagation via GitHub Releases, Docker Hub, AWS ECR et GitHub Container Registry en ~4 heures.
The tracking identifier is CVE-2026-45321 (CVSS 9.6 per The Hacker News; advisory GHSA-g7cv-rxg3-hmpx per Snyk).
Their December 2025 "React2Shell" campaign exploited CVE-2025-55182 to target exposed Docker APIs, Kubernetes clusters, Ray dashboards, and Redis servers, deploying a worm-driven botnet that peaked around December 25 before going quiet [2].
Analysis of react.py This script is clearly set to exploit CVE-2025-29927, also known as React2Shell. ... This script implements a fully automated React/Next.js exploitation pipeline centered on abusing CVE-2025-29927 to achieve remote command execution at scale.
The four CVEs associated with this campaign are CVE-2026-33634, CVE-2026-48027, CVE-2026-45321, and CVE-2025-55182.
2 more CVEs tied to this actor tracked in Mallory.
564 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Compromising internet-facing infrastructure and later expanding into software supply chain attacks, including poisoning open-source libraries, targeting cloud-native and Kubernetes environments, exfiltrating data, deploying ransomware, conducting extortion, mining cryptocurrency, and using wormable/self-propagating techniques.
Referenced as the group potentially behind the Shai-Hulud toolchain lineage that ChainDrop appears to reuse, but the content explicitly says attribution to TeamPCP is unconfirmed.
Threat group behind the Shai-Hulud infostealer and associated variants used in repeated supply-chain campaigns against npm/software repositories, including credential theft, exfiltration to GitHub, and worm-like propagation via compromised maintainer/package publish tokens.
Conducting a large-scale npm supply chain attack via a compromised GitHub maintainer account, publishing poisoned package versions, stealing developer and cloud credentials, and using worm-like propagation to compromise additional maintainer accounts and packages.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.