TeamPCP is a cloud-native information-stealer and supply-chain malware operation, also tracked as DeadCatx3, PCPcat, ShellForce, and CanisterWorm. It has been embedded in compromised developer, security-scanning, package-management, and AI-infrastructure tooling to harvest credentials and sensitive data from developer workstations, CI/CD runners, containers, Kubernetes clusters, and cloud environments. A prominent campaign compromised Trivy container artifacts and associated CI/CD infrastructure, exposing pipeline secrets, repository credentials, cloud credentials, build artifacts, and Kubernetes identities.
TeamPCP performs host and environment reconnaissance, searches configuration and environment data for secrets, accesses SSH material and developer authentication tokens, and targets Docker and Kubernetes credentials. Where available, it abuses cloud credentials to enumerate and retrieve secrets from AWS services. Collected data is compressed, protected using campaign-specific encryption or obfuscation, and exfiltrated over HTTPS. The malware has used persistence mechanisms, command-and-control fallback mechanisms, Kubernetes-aware discovery, and cloud-oriented lateral movement. Related activity includes self-propagating package ecosystem worms, cryptomining, ransomware-associated operations, and destructive payloads targeting Kubernetes environments. Public reporting has linked TeamPCP credential theft and data exfiltration activity with Vect ransomware deployment infrastructure.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
A new analysis, published on March 22 by Socket researchers, showed both images contained indicators of compromise (IOC) associated with the TeamPCP infostealer previously observed in the campaign.
9 distinct techniques documented for this family, organized by ATT&CK tactic.
57 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
16 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Supply-chain-focused malware/campaign used to compromise trusted tooling, harvest non-human credentials, steal data, and generate access later monetized through extortion or ransomware deployment.
Previously present malware or infection set in compromised cloud environments whose processes, services, files, containers, and persistence artifacts are removed by PCPJack before PCPJack takes over the host.
A supply-chain-delivered credential stealer/loader that performs host reconnaissance, harvests secrets from files and cloud environments, abuses live AWS APIs such as Secrets Manager and SSM to enumerate and retrieve secrets, compresses stolen data into trin.tar.gz, exfiltrates it over HTTPS using a custom header, and cleans up artifacts while leaving a persistence marker.
A credential-harvesting malware/toolset associated with a supply-chain compromise of the Trivy vulnerability scanner, used to steal credentials and enable pivoting to higher-value targets.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.