TeamPCP is a financially motivated cybercrime group that emerged in late 2025 and became prominent for large-scale software supply-chain compromises across open-source and developer ecosystems. The actor is also tracked as UNC6780 and has been associated with aliases including deadcatx3, pcpcat, persypcp, shellforce, storm_2999, team_pcp, and teampcp_unc6780. TeamPCP is closely linked to the Shai-Hulud malware family and related variants such as Mini Shai-Hulud, CanisterWorm, SANDCLOCK, and ChainDrop. The group specializes in compromising trusted build and release paths rather than directly targeting end victims. Its operations have included abuse of CI/CD pipelines, theft of maintainer and publishing credentials, poisoning of package registries, malicious modification of GitHub Actions and release tags, and downstream propagation through npm, PyPI, Docker Hub, OpenVSX, VS Code extensions, and internal source repositories. A major 2026 campaign chained the compromise of Aqua Security’s Trivy ecosystem into malicious LiteLLM releases, resulting in broad exposure of secrets from automated build environments. Reporting also links TeamPCP to compromises involving KICS, Telynx, and other open-source packages. TeamPCP’s malware and tradecraft center on credential theft and exfiltration at scale. Collected data has included repository tokens, cloud credentials, SSH material, Kubernetes secrets, package publishing credentials, environment variables, AI-provider keys, database credentials, and other CI/CD secrets. The actor has used automatic execution mechanisms such as Python startup hooks, malicious package lifecycle hooks, and worm-like propagation logic to spread through developer environments and republish trojanized packages using stolen tokens. Some TeamPCP tooling has also established persistence and, in certain campaigns, used compromised GitHub accounts and repositories as exfiltration channels or dead-drop infrastructure. The group has demonstrated advanced post-exploitation and defense-evasion capability in some intrusions. Malware attributed to TeamPCP has used process injection, APC-based execution, reflective loading via Donut, dynamic API resolution, ETW suppression, AMSI and WLDP bypasses, and syscall-based user-mode EDR evasion. In Windows-focused payload chains, TeamPCP has delivered remote-access tooling identified as an AdaptixC2 variant. Other campaigns have included Linux-focused credential stealers that harvested secrets from runner memory and attempted persistence through system services. Victimology indicates broad, opportunistic targeting driven by access value rather than a narrow vertical focus. Exposed organizations have spanned technology, financial services, health care, manufacturing, retail, professional services, government, cybersecurity, and cryptocurrency-related entities. TeamPCP’s activity is best characterized as cybercriminal supply-chain exploitation for monetizable access, credential theft, and follow-on abuse of trusted software distribution channels.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
44 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
30 malware families attributed to this actor across reporting.
25 additional families tracked in Mallory.
7 CVEs this actor has used in observed campaigns. 7 of them exploited in the wild.
The earlier stage targeted Trivy, Aqua Security’s widely used vulnerability scanner. On March 19, attackers used compromised credentials to publish a malicious Trivy v0.69.4 release, force-push malicious changes to 76 of 77 affected trivy-action version tags and replace the affected setup-trivy tags. The incident is tracked as CVE-2026-33634, which NIST’s National Vulnerability Database classifies as a known exploited vulnerability and which CISA added to its Known Exploited Vulnerabilities catalog.
That progression ran through PCPcat, which peaked around Christmas 2025 against React2Shell targets and exposed Docker APIs.
The tracking identifier is CVE-2026-45321 (CVSS 9.6 per The Hacker News; advisory GHSA-g7cv-rxg3-hmpx per Snyk).
Analysis of react.py This script is clearly set to exploit CVE-2025-29927, also known as React2Shell. ... This script implements a fully automated React/Next.js exploitation pipeline centered on abusing CVE-2025-29927 to achieve remote command execution at scale.
The four CVEs associated with this campaign are CVE-2026-33634, CVE-2026-48027, CVE-2026-45321, and CVE-2025-55182.
2 more CVEs tied to this actor tracked in Mallory.
567 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Conducted a supply-chain attack against LiteLLM by compromising maintainer credentials and publishing malicious PyPI package versions that exposed credentials across CI/CD environments and repositories.
Conducted a large-scale software supply chain attack beginning with compromise of the Aqua Trivy VS Code extension, then abused stolen write-capable credentials to tamper with Trivy GitHub Actions tags and release a trojanized Trivy scanner. The embedded infostealer harvested secrets from CI/CD runners and enabled follow-on compromises including Docker Hub, Checkmarx GitHub Actions, the npm ecosystem, and malicious LiteLLM packages on PyPI.
Conducting open source software supply chain attacks that began with a compromised Trivy build and propagated downstream into packages such as LiteLLM, using worm-like malware to steal credentials, tokens, API keys, and other secrets and to push further malicious package versions.
Conducted a chained software supply-chain attack by backdooring the Trivy GitHub Action, stealing LiteLLM PyPI publishing tokens, publishing malicious LiteLLM packages, and harvesting secrets from compromised GitHub Actions / CI-CD runners at scale.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.