PCP Team, also referenced as PCP, is a threat actor associated with software supply-chain compromises targeting developer tooling and package ecosystems. Known activity includes the compromise of Aqua Security's trivy-action and the Python litellm package in 2026. These operations were designed to propagate through CI/CD workflows, local developer environments, and transitive package dependencies, demonstrating a focus on upstream compromise rather than direct intrusion into end targets. In the trivy-action incident, the actor compromised a widely used GitHub Action and delivered a malicious payload to repositories that referenced affected versions and executed workflows during the compromise window. In the litellm incident, the actor poisoned a Python package so that downstream consumers could retrieve a malicious version through dependency resolution. Reporting on these incidents indicates the actor used infostealer functionality tailored to execution context, including a CI runner-focused payload and a more general endpoint infostealer. The litellm operation is specifically described as targeting local environments, while the trivy-action operation affected CI/CD runners. PCP Team's observed tradecraft centers on initial access through trusted software distribution channels, defense evasion through abuse of legitimate development infrastructure, and theft of sensitive data from compromised build or developer environments. The actor's operations also show an understanding of dependency graphs, optional and direct package relationships, and the amplification effects of transitive dependencies in modern software ecosystems. Public references also associate the name PCPcat with the broader PCP naming cluster, but the supplied facts do not establish a precise organizational relationship beyond that association.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
5 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
4 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Conducted supply chain attacks by compromising AquaSecurity's trivy-action and poisoning the Python litellm package, causing malicious code execution in CI/CD workflows and local/developer environments.
Named in the React2Shell threat-actor list; no additional context provided.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.