TeamPCP is a financially motivated cybercrime group associated with large-scale open-source software supply-chain compromises and the self-propagating Shai-Hulud worm. The group emerged in late 2025 and initially conducted opportunistic intrusion activity against exposed cloud services, including container-management and other internet-facing services. It deployed compromised infrastructure for scanning, proxy activity, and Monero mining, and monetized stolen data and access. In 2026, TeamPCP was linked to supply-chain compromises involving the Trivy vulnerability scanner and LiteLLM AI middleware. These operations abused compromised development and CI/CD environments to introduce credential-stealing malware into legitimate software releases. The malware harvested source-control, package-registry, cloud, CI/CD, Kubernetes, SSH, and other developer secrets, exfiltrated collected data, and used recovered publishing credentials to tamper with additional repositories and packages. TeamPCP also used Python path-configuration-file execution for persistence in the LiteLLM compromise. Australian Federal Police, working with the U.S. Federal Bureau of Investigation and Western Australia Police Force, charged two Western Australian men in August 2026 as alleged TeamPCP members. Authorities alleged that the group's activity affected more than 1,000 organizations globally, enabled theft of more than 500,000 credentials, and exfiltrated at least 300 GB of data. The group has been associated with the aliases DeadCatx3, PCPcat, Persy_PCP, ShellForce, UNC6780, and Storm-2999. Shai-Hulud source code was subsequently made publicly available, enabling copycat and independent supply-chain activity; later campaigns using related malware have not been conclusively attributable to TeamPCP.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
38 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
29 malware families attributed to this actor across reporting.
24 additional families tracked in Mallory.
7 CVEs this actor has used in observed campaigns. 7 of them exploited in the wild.
The chain that reached the widest set of victims ran through Trivy into LiteLLM... The ecosystem flaw is tracked as CVE-2026-33634 and was added to CISA’s Known Exploited Vulnerabilities catalog on 26 March 2026.
That progression ran through PCPcat, which peaked around Christmas 2025 against React2Shell targets and exposed Docker APIs.
The tracking identifier is CVE-2026-45321 (CVSS 9.6 per The Hacker News; advisory GHSA-g7cv-rxg3-hmpx per Snyk).
Analysis of react.py This script is clearly set to exploit CVE-2025-29927, also known as React2Shell. ... This script implements a fully automated React/Next.js exploitation pipeline centered on abusing CVE-2025-29927 to achieve remote command execution at scale.
The four CVEs associated with this campaign are CVE-2026-33634, CVE-2026-48027, CVE-2026-45321, and CVE-2025-55182.
2 more CVEs tied to this actor tracked in Mallory.
584 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Cybercrime group associated with earlier software supply-chain attacks and opportunistic operations involving exposed-service scanning, container deployment, cryptocurrency mining, and theft of credentials from build-pipeline and software-development environments.
Alleged cybercriminal group whose operations involved creating and distributing open-source malware to compromise organizations and steal data. The reported impact includes more than 1,000 organizations compromised globally, over 500,000 credentials stolen, and at least 300 GB of data exfiltrated.
Mentioned solely as unconfirmed contextual background; the content does not attribute Trinitite to TeamPCP or describe TeamPCP activity in this incident.
Mentioned only as unconfirmed contextual background to the Trinitite/Mini Shai-Hulud npm supply-chain incident; the activity is not conclusively attributed to TeamPCP.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.