Threat Actor Unknown origin

TeamPCP

Also known as: Altered Spider

TeamPCP is a threat actor that has executed a coordinated series of supply chain attacks, compromising widely-used open source tools such as Trivy, KICS, and LiteLLM to deploy credential-stealing malware. They employed techniques like credential harvesting, lateral movement within Kubernetes environments, and audio steganography to evade detection. The group has demonstrated the ability to leverage stolen credentials to propagate attacks across multiple ecosystems, including npm and PyPI, using a self-propagating worm known as CanisterWorm. Their operations have included the use of AES-256 encryption and RSA-4096 for exfiltration of sensitive data.

Indicators of Compromise 70

Domain audit[.]checkmarx[.]cx Domain checkmarx[.]cx Domain dht[.]transmissionbt[.]com Domain ethereum-rpc[.]publicnode[.]com Domain ipfs[.]io Domain relay[.]damus[.]io Domain relay[.]nostr[.]com Domain rentry[.]co Domain router[.]bittorrent[.]com Domain scan[.]aquasecurtiy[.]org Domain t[.]m-kosche[.]com Filename .claude/unicorn Filename .github/workflows/format-check.yml Filename Kamikaze Filename bw1.js Filename bw_setup.js Filename execution.js Filename kube.py Filename setup.mjs Filename sync.js GitHub Repo CNCF/backstage GitHub Repo TeamPCP/Shai-Hulud GitHub Repo helloworm00/hello-world GitHub Repo tj-actions/changed-files GitHub Repo zblgg/configuration GitHub User helloworm00 SHA-1 bc544f455d7c06c8a1f3446160a6d9a4a8236b11 SHA-256 082d733db0687dcd768104972b065d4b58cb1e6043688c6c20fa3702337f36ab SHA-256 167ce57ef59a32a6a0ef4137785828077879092d7f83ddbc1755d6e69116e0ad SHA-256 18f784b3bc9a0bcdcb1a8d7f51bc5f54323fc40cbd874119354ab609bef6e4cb SHA-256 22bf76fe317ea6769bd38619bd440e42d119bd6b SHA-256 34014776d3d3ff11bc4439b02fd7ac0f02a887eb3a052eeafff236e2f6db8ad1 SHA-256 3eab3ec9304aa26081358330491d3cfeb55cc245 SHA-256 4066781fa830224c8bbcc3aa005a396657f9c8f9016f9a64ad44a9d7f5f45e34 SHA-256 540028bbd229cc8ce0f531f84e11296870f9b54faa231abb6f5da8557ae3df31 SHA-256 6f933d00b7d05678eb43c90963a80b8947c4ae6830182f89df31da9f568fea95 SHA-256 73b44b8724d31f80859018c988e9b033155c5fd8225205a914eda1a11b78a841 SHA-256 9890950adcbc2478e7a080234f053214adbad44e SHA-256 9b2e65db653ca8575c9b10eefb9a80c6006404812c2ec212bf5675e3c690233b SHA-256 QmQobZSp1wRPrpSEQ56qnyq7ecZh5Bg5k1fnjt4SUwwHb9 SHA-256 Qmet4fhsAaWMBUxNDfREHwgiyDeSWy4YSYs9wiKUW5jGyf SHA-256 a7e18d96efd3cdb127ef4cdcad9e3ad26c482bf2 SHA-256 bfaeb987faa6de2b5a5eb63b1233d055215b09b0349a9394f2175fd7cdf385e4 SHA-256 c70e105e212ff3c1daa04bb2a62507717f296b0b SHA-256 c8cb3f6d5b90c46686d2bf531dc1a5786e27edc5 SHA-256 d425e4583cc6185d41e95c45eda00550045a5d1919b9a012236a4520d009dbd7 SHA-256 f35475829991b303c5efc2ee0f343dd38f8614e8b5e69db683923135f85cf60d SHA-256 f7367ce5509f536a406deecdbb577c60e8585cb2ab77058a86bde6188a609cfd SHA-256 ssl://0432fa4ba871877d94081fe83323fa24dfa1491e9de8725cbab7b734de9e9be3b233ef6742fd6264437c9532223d687b05fa540b70af6a516b8539af84d0eeb48e IP 45[.]148[.]10[.]212 IP 85[.]137[.]53[.]71 IP 91[.]195[.]240[.]123 IP 94[.]154[.]172[.]43 Package @asyncapi/[email protected] Package @asyncapi/[email protected] Package @asyncapi/[email protected] Package @asyncapi/[email protected] Package @asyncapi/[email protected] Package @bitwarden/[email protected] Package @cap-js/[email protected] Package @cap-js/[email protected] Package @cap-js/[email protected] Package @ctx/nightly-build Package @redhat-cloud-services/* Package cacheable Package keyv Package [email protected] Package [email protected] Package telnyx Registry User 148100

MITRE ATT&CK TTPs 16

Source Articles

TeamPCP Linked To Redis Attacks Dating Back To 2020 And Later Supply Chain Campaign
TeamPCP, a threat actor active since at least 2020, has evolved from exploiting exposed Redis, Docker, Ray, and React infrastructure to conducting large-scale supply chain attacks. The group has used overlapping infrastructure and tradecraft across campaigns, including ShadowRay 2.0 (aka IronErn) and TA-NATALSTATUS, which targeted Redis servers to deploy cryptocurrency miners. More recently, TeamPCP has poisoned open-source libraries via GitHub Actions abuse and token theft, while also deploying destructive malware such as 'kube.py' that includes wiper functionality targeting Kubernetes clusters, particularly those in Iran.
hacker-news ·1w ago
Cloud Threat Highlights: H1 2026
In H1 2026, a surge in cloud-based threats was driven by aggressive software supply-chain attacks, particularly by the group TeamPCP, which compromised developer toolchains across npm, PyPI, and VSCode extensions to steal credentials and propagate across cloud environments. TeamPCP's malware evolved to exploit CI misconfigurations, extract OIDC tokens, and deploy wipers with Dune-themed taunts. North Korea's UNC1069 conducted parallel campaigns, trojanizing the axios package and compromising over 140 @mastra-related packages. The open-sourced Shai-Hulud worm enabled follow-on attacks like IronWorm, which used Rust-based binaries and eBPF rootkits for stealth. A new extortion group, JINX-0163, emerged, targeting cloud identities across AWS, Azure, and GCP to steal secrets and enable ransom threats via the alias 'FulcrumSec'.
wiz
The npm Threat Landscape: Attack Surface and Mitigations (Updated July 15)
The npm ecosystem has faced escalating supply chain attacks since the emergence of the Shai-Hulud worm in September 2025. These attacks have evolved into sophisticated, wormable campaigns that steal credentials, propagate across packages, and establish persistent access in CI/CD pipelines. Recent operations, including Mini Shai-Hulud and Miasma variants, have targeted major organizations like Red Hat and AsyncAPI, using novel initial access techniques and resilient C2 infrastructure. The public release of Mini Shai-Hulud tooling has increased the risk of copycat campaigns.
unit42 ·4w ago
The serpent’s tongue: Luring the Python out of its den
Threat actors are increasingly targeting Python developers through malicious packages and supply chain attacks, leveraging trusted ecosystems like PyPI to distribute payloads. These attacks exploit native Python features such as setup.py, .pth files, and site hooks to execute arbitrary code during installation or runtime, achieving persistence or conditional execution. Techniques include build hook abuses and package content manipulation, enabling adversaries to hijack legitimate binaries, override functions, or exfiltrate data. The blog highlights defensive strategies including dependency auditing, version pinning, and isolated build environments to mitigate these risks.
talos ·1mo ago
GitHub Secret Scanning Public Monitoring for Enterprises: Coverage and Gaps
Recent attacks like Sha1-Hulud and Megalodon have used public GitHub repositories to exfiltrate stolen credentials, leveraging random UUID-named repositories for rapid distribution. GitHub's new public monitoring feature helps detect such leaks by scanning public content across github.com, including repositories not owned by the enterprise. However, this detection occurs post-exposure and does not cover secrets exfiltrated to external attacker-controlled infrastructure or exposed through CI/CD logs. A layered defense combining detection and runtime egress control is recommended to prevent real-time exfiltration.
step-security ·1mo ago
10 Layers Deep: How StepSecurity Stops TeamPCP's Trivy Supply Chain Attack on GitHub Actions
In March 2026, the threat actor TeamPCP compromised 76 version tags of the aquasecurity/trivy-action GitHub Action by injecting a credential stealer, exploiting elevated privileges to harvest secrets from memory and exfiltrate them to a malicious domain. The same actor targeted other platforms including PyPI packages litellm and telnyx, and previously compromised the Checkmarx KICS GitHub Action using similar tactics. These supply chain attacks highlight a broader trend of targeting CI/CD pipelines to steal credentials and cloud tokens. The attacks leveraged typosquatted domains and memory scraping techniques, underscoring the need for layered defenses in GitHub Actions environments.
step-security ·1mo ago