TeamPCP is a cloud-native malware family and associated threat activity cluster active in 2025 and 2026, also tracked under aliases including DeadCatx3, PCPcat, ShellForce, and CanisterWorm. It is best known for software supply-chain compromises affecting developer and security tooling, especially Aqua Security’s Trivy ecosystem, where malicious artifacts were used to steal credentials and sensitive data from developer workstations, CI/CD pipelines, containers, and cloud-connected environments. TeamPCP activity has also been linked to downstream compromise of package ecosystems and to later-stage monetization including extortion and ransomware operations through reported collaboration with Vect.
The malware’s core behavior is credential harvesting and data theft. Observed payloads perform broad host and environment reconnaissance, enumerate environment variables, search recursively for secrets in common configuration formats, access Kubernetes secrets, inspect developer tooling authentication state, and review system and network context. In cloud environments, TeamPCP has been observed abusing ambient or stolen AWS credentials to make live authenticated API calls to enumerate and retrieve secrets from AWS Secrets Manager and Systems Manager Parameter Store. Kubernetes-aware variants detect whether they are running inside a cluster, branch into cluster-specific execution paths, and deploy specialized components to harvest service account tokens, discover resources through the Kubernetes API, and support privilege expansion within containerized environments.
TeamPCP has used multiple implementation styles across campaign waves. Reported variants include JavaScript executed through the Bun runtime, Python startup-hook payloads, Python-based cluster tooling, and worm-capable components. The malware collects stolen material into compressed archives and exfiltrates it over HTTPS, while some related TeamPCP-linked operations used encrypted exfiltration and fallback recovery mechanisms through attacker-controlled code-hosting infrastructure. Artifact cleanup and limited persistence have also been observed, indicating an emphasis on stealth and reuse of stolen access rather than long-term noisy residence.
Beyond information theft, TeamPCP has been associated with self-propagating worm behavior, exploitation of Docker and Kubernetes environments, and destructive or monetization-focused follow-on actions. Reported TeamPCP-linked campaigns included propagation through compromised npm packages using stolen publish tokens, Kubernetes-focused payloads that enumerate cluster resources and execute across workloads, and operations that deployed cryptomining or destructive components in some environments. Public reporting also describes TeamPCP as part of a credential-theft-to-extortion pipeline in which compromised trusted software is used to harvest reusable non-human credentials that are later monetized through downstream intrusion, data theft, and ransomware deployment.
Primary targets include Linux-based container workloads, Kubernetes clusters, CI/CD systems, developer environments, and cloud infrastructure where secrets, tokens, and service-account credentials are exposed to build or runtime contexts. Industries are not narrowly constrained, but the malware is especially relevant to organizations relying on cloud-native development, DevSecOps tooling, package registries, and automated deployment pipelines.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
A new analysis, published on March 22 by Socket researchers, showed both images contained indicators of compromise (IOC) associated with the TeamPCP infostealer previously observed in the campaign.
9 distinct techniques documented for this family, organized by ATT&CK tactic.
A supply chain attack against Aqua Security’s open-source Trivy vulnerability scanner has led to the distribution of malicious artifacts via Docker Hub... On March 22, new malicious versions of Trivy, specifically 0.69.4, 0.69.5, and 0.69.6, were pushed to Docker Hub without corresponding GitHub releases or tags.
57 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
15 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Supply-chain-focused malware/campaign used to compromise trusted tooling, harvest non-human credentials, steal data, and generate access later monetized through extortion or ransomware deployment.
Previously present malware or infection set in compromised cloud environments whose processes, services, files, containers, and persistence artifacts are removed by PCPJack before PCPJack takes over the host.
A supply-chain-delivered credential stealer/loader that performs host reconnaissance, harvests secrets from files and cloud environments, abuses live AWS APIs such as Secrets Manager and SSM to enumerate and retrieve secrets, compresses stolen data into trin.tar.gz, exfiltrates it over HTTPS using a custom header, and cleans up artifacts while leaving a persistence marker.
A credential-harvesting malware/toolset associated with a supply-chain compromise of the Trivy vulnerability scanner, used to steal credentials and enable pivoting to higher-value targets.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.