Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Security researchers Socket and StepSecurity identified a new variant, CanisterSprawl, that retained the ICP blockchain C2 architecture while adding cross-ecosystem propagation logic.
21 distinct techniques documented for this family, organized by ATT&CK tactic.
...injecting them with the malicious script and republishing them using the victim’s stolen npm credentials. Additionally, the script attempts to spread the attack to the Python Package Index (PyPI) when the necessary credentials are available...
The worm operated autonomously, stealing npm authentication tokens from compromised environments, resolving which packages each token could publish, incrementing patch version numbers to trigger routine update workflows, and republishing poisoned copies while preserving original READMEs to avoid raising maintainer suspicion.
TeamPCP, formally designated UNC6780 by Google's Threat Intelligence Group, has executed at least three distinct supply chain campaign waves between March 19 and May 20, 2026, compromising security scanners, AI gateways, package managers, and — most recently — GitHub's own internal infrastructure.
The group's March campaign exploited mutable GitHub Actions version tags in Aqua Security's Trivy scanner (CVE-2026-33634, CVSS 9.4) to deploy the SANDCLOCK credential stealer across an estimated 10,000-plus CI/CD pipeline runs, subsequently cascading to Checkmarx KICS, LiteLLM, and the Telnyx Python SDK.
Its corresponding GitHub Action — aquasecurity/trivy-action — was referenced by downstream workflows using mutable version tags rather than pinned commit hashes, meaning that any attacker who could push a new commit and update those tags would instantly reach every pipeline that ran a Trivy scan on subsequent executions.
The worm executes via npm postinstall hook... Trojanized cx-dev-assist ... silently downloaded a second-stage mcpAddon.js payload ... and executed it via the Bun runtime without integrity verification.
If the infected environment contained PyPI publish credentials, CanisterSprawl would generate Python .pth file payloads — entries in the site-packages directory that execute automatically at Python interpreter startup — to infect Python packages via a mechanism the target organization might not associate with an npm-channel infection.
Trojanized cx-dev-assist (versions 1.17.0 and 1.19.0) and ast-results (versions 2.63.0 and 2.66.0) VS Code and Open VSX extensions were also identified, which silently downloaded a second-stage mcpAddon.js payload from a backdated commit in the official Checkmarx GitHub repository and executed it via the Bun runtime without integrity verification.
SANDCLOCK scraped secrets from CI runner memory and transmitted AWS keys, GitHub tokens, Kubernetes configurations, and SSH private keys to attacker-controlled infrastructure.
The malicious postinstall script observed in this compromise works to harvest secrets from the victim’s environment by searching environment variables for names associated with tokens, credentials, cloud providers, CI/CD systems, registries, LLM platforms and other secrets. It also targets sensitive local system files including .npmrc, .git-credentials, .netrc, .env files, database password files, and files storing SSH keys and cloud credentials.
The payload swept AWS credentials, Google Cloud configurations, Kubernetes tokens, environment variables, SSH keys, API keys, and database credentials, exfiltrating to hxxps://whereisitat[.]lucyatemysuperbox[.]space/.
the xinference PyPI package — a framework for running open-source LLMs in research and production environments — was poisoned with an expanded credential harvester that added cryptocurrency wallet data (MetaMask, Phantom, and Solana wallet files) to its exfiltration targets alongside standard developer credentials
The worm operated autonomously, stealing npm authentication tokens from compromised environments, resolving which packages each token could publish, incrementing patch version numbers to trigger routine update workflows, and republishing poisoned copies while preserving original READMEs to avoid raising maintainer suspicion.
The worm operated autonomously, stealing npm authentication tokens from compromised environments, resolving which packages each token could publish, incrementing patch version numbers to trigger routine update workflows, and republishing poisoned copies while preserving original READMEs to avoid raising maintainer suspicion.
The payload swept AWS credentials, Google Cloud configurations, Kubernetes tokens, environment variables, SSH keys, API keys, and database credentials... The malicious payload ... exfiltrated GitHub tokens, npm tokens, SSH material, AWS/GCP/Azure secrets, GitHub Actions secrets, and AI tooling configuration files.
The malicious payload contained the string "Shai-Hulud: The Third Coming" ... and exfiltrated GitHub tokens, npm tokens, SSH material, AWS/GCP/Azure secrets, GitHub Actions secrets, and AI tooling configuration files to public GitHub repositories created under victim accounts.
7 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A variant of CanisterWorm that preserves ICP blockchain-based C2 while adding cross-ecosystem propagation from npm into PyPI via Python .pth payloads for automatic execution at interpreter startup.
A self-propagating npm supply chain worm that executes via npm postinstall hooks, harvests roughly 40 credential categories, exfiltrates data to dual-channel infrastructure including an Internet Computer Protocol canister, and can jump from npm to PyPI when it finds a PyPI publish token.
A self-propagating npm supply chain worm that executes via postinstall, steals a broad set of credentials, exfiltrates data using ICP canister-based infrastructure, and can jump from npm to PyPI when publish tokens are found.
A self-propagating npm supply chain worm that executes via postinstall, steals a broad set of credentials, exfiltrates data using dual-channel infrastructure including an ICP canister, and can jump from npm to PyPI when publish tokens are found.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.