Researchers linked TeamPCP to multiple interconnected intrusion campaigns spanning web application exploitation, software supply-chain abuse, and infrastructure hijacking. Reporting on the Operation PCPcat and React2Shell activity said attackers exploited vulnerable Next.js deployments and compromised roughly 59,000 servers, using them to steal credentials and build follow-on access. Separate investigations into the CanisterWorm campaign found dozens of malicious npm packages carrying hidden postinstall scripts that stole npm tokens from .npmrc, /etc/npmrc, and environment variables, then republished trojanized updates through victims’ own publisher accounts. The malware also established Linux persistence with a masqueraded user-level systemd service named pgmon and fetched later-stage payloads through Internet Computer canister infrastructure, complicating takedown efforts.
Additional reporting tied the broader operation to compromised CI/CD ecosystems, residential proxy building, and ransomware monetization. An investigation into the Xygeni GitHub Action compromise found the same custom ShadowLink backdoor protocol used in malware that exploited TP-Link and ASUS routers, including abuse of CVE-2024-21833 to install microsocks and maintain SOCKS5 proxy persistence via cron, rc.local, and NVRAM changes; researchers said this strongly links the router campaign to the Xygeni intrusion, while overlap with TeamPCP remains partly circumstantial. By late March, defenders reported TeamPCP had slowed new package compromises and shifted toward monetization through harvested credentials and dual ransomware tracks, including its own CipherForce operation and activity aligned with the Vect ransomware ecosystem; related fallout included ownCloud disclosing build infrastructure exposure through CVE-2026-33634 associated with the Trivy compromise.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
10 events from the most recent confirmed update back to the earliest known activity.
Researchers published an investigation connecting the March 3 Xygeni GitHub Action compromise to a campaign exploiting TP-Link and ASUS routers to build a residential proxy network. The link was based on a shared custom backdoor protocol, ShadowLink, including identical registration paths, polling logic, and authentication secret.
An update assessed that TeamPCP had moved into monetization through direct credential exploitation, a proprietary CipherForce ransomware operation, and a separate partnership with the Vect ransomware ecosystem. The report also noted release of a 3 GB AstraZeneca data archive allegedly connected to related criminal activity.
ownCloud said its build infrastructure was affected by CVE-2026-33634 associated with the Trivy compromise, while stating that no customer data or source code was impacted. The disclosure added another downstream victim to the broader TeamPCP supply-chain story.
On March 30, Databricks' newly confirmed @DatabricksSec account said an internal investigation found nothing related to alleged TeamPCP-linked compromise and asked for more information. The statement responded to claims that TeamPCP-harvested credentials may have affected the company.
By March 27, researchers assessed that TeamPCP had stopped introducing new package compromises and shifted focus toward monetization of harvested access and credentials. This marked a transition from expansion of the supply-chain campaign to follow-on exploitation.
Follow-on reporting attributed CanisterWorm to TeamPCP and identified newly compromised packages, including multiple @emilgroup SDKs. The update emphasized that the campaign hijacked legitimate publisher accounts and weaponized trusted packages for automated propagation.
Researchers revealed a malicious npm package campaign dubbed CanisterWorm that used hidden postinstall scripts to steal npm tokens, deploy a Python backdoor, and self-propagate by republishing infected packages from compromised publisher accounts. The malware also established Linux persistence via a masqueraded user-level systemd service named pgmon and used Internet Computer infrastructure for next-stage retrieval.
Xygeni’s GitHub Action was compromised in a supply-chain incident later linked by researchers to a separate router-based proxy campaign through a shared ShadowLink backdoor protocol. This compromise became a key pivot point in later attribution analysis.
A large-scale exploitation campaign targeting Next.js/React-based servers resulted in roughly 59,000 compromised systems. The activity established the baseline for what was later tracked as Operation PCPcat.
A report documented a Next.js exploit campaign dubbed Operation PCPcat, describing credential theft and broad server compromise tied to the earlier React2Shell activity. The publication provided technical analysis of the campaign affecting tens of thousands of servers.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
6 references tracked. Mallory keeps watching after this page renders.
ctrlaltintel.com
Open sourceisc.sans.edu
Open sourcegbhackers.com
Open sourceendorlabs.com
Open sourcebeelzebub.ai
Open sourcecyberpress.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.