TeamPCP is a threat actor associated with a multi-stage software supply chain compromise targeting Aqua Security’s Trivy ecosystem in March 2026. The operation affected the Trivy scanner as well as the aquasecurity/trivy-action and aquasecurity/setup-trivy GitHub Actions, and leveraged retained access from an earlier incompletely contained incident. The actor used spoofed commits, malicious releases, and force-moved GitHub Action tags to distribute credential-stealing payloads through trusted developer and CI/CD channels. The group demonstrated strong post-compromise tradecraft in software development environments. Its malicious GitHub Actions payloads harvested secrets from runner memory and from numerous filesystem locations, including cloud credentials, SSH material, Kubernetes tokens, and cryptocurrency wallet data. Stolen data was encrypted prior to exfiltration, and fallback exfiltration mechanisms abused victim GitHub accounts by creating repositories to store stolen data. The compromised Trivy binary executed legitimate functionality in parallel with malicious code, collected environment and host data, and attempted persistence on developer machines through a user-level systemd-backed Python dropper that polled for follow-on payloads. TeamPCP also compromised internal Aqua resources, including a service account, and used that access to push malicious workflows to additional repositories. The intrusion extended beyond source repositories to published release channels, including container registries, and exposed internal repositories publicly, indicating sustained access and broad abuse of the victim’s software supply chain. Reported related activity also linked TeamPCP to expansion into the npm ecosystem via CanisterWorm. Known aliases in the available reporting include TeamPCP and megagame10418. The actor’s observed behavior is consistent with financially motivated theft of credentials and other sensitive data obtained through supply chain compromise, credential harvesting, persistence, and exfiltration.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
2 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as the actor involved in an earlier, separate incident affecting Trivy, exploiting a PWN request.
Referenced only as the actor involved in a separate earlier incident distinct from the main Trivy compromise discussed here.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.