TLP:CLEAR
⚠ ECRIME · INDEPENDENT · AU/ZA NEXUS
// Threat Actor Profile — Cloud-Native Software Supply Chain Compromise & Ransomware-Enabled Extortion

TEAMPCP

PROFILE COMPILED: 2026-08-30  |  SOURCES: Unit 42, Wiz, KELA, Bitsight, Malpedia, Krebs on Security, U.S. DOJ, FBI/IC3, TechCrunch, BleepingComputer, The Record, SOCRadar, Sophos, SANS ISC + 6 more (see §10)
Status: ACTIVE — PARTIALLY DISRUPTED
Threat Level: CRITICAL
Primary Motive: Financial Gain
Active Since: Mid-2025
MITRE ATT&CK: No G-ID Assigned
⚡ AFP / FBI JOINT ACTION — 2026-08-27
Two Alleged TeamPCP Operators Arrested and Federally Indicted in Australia
On August 27, 2026, the Australian Federal Police and Western Australia Police Force — supported by the FBI — executed search warrants in Cottesloe, Hamilton Hill, and Mandurah, WA, and arrested Ruben Ian Thomson (21, AU/ZA national) and Louis Michael Gaebler (23) on a combined 14 cybercrime charges (TechCrunch, Aug 27 2026; Krebs on Security, Aug 2026). A parallel U.S. federal indictment out of the Northern District of California charges Thomson with conspiracy to violate the Computer Fraud and Abuse Act (DOJ USAO-NDCA, Aug 2026). Both remain in custody pending a September 18, 2026 court appearance. Analysts caution this action addresses only a subset of a larger, Telegram-coordinated crew — active CipherForce/Vect extortion operations are not confirmed halted.
500K+
Credentials Stolen (EU Commission Breach Alone)
2,500+
Organizations Compromised via LiteLLM Alone
10.0
CVSS — CVE-2025-55182 "React2Shell" Exploited for Access
3,800+
GitHub Repositories Compromised
00
Overview

TeamPCP is a financially motivated, cloud-native cybercriminal operation that in 2026 ran what several vendors independently describe as the most consequential open-source software supply chain campaign of the year (Flare, Feb 2026; SocRadar, 2026). Rather than attacking victims directly, the group compromises the trusted upstream software — security scanners, AI gateways, SDKs — that thousands of organizations pull into their build pipelines, converting a single maintainer's stolen credential into a cascading compromise of everyone downstream. Its defining trait is not technical novelty: initial access, credential theft, and typosquatting are all long-understood techniques. The distinguishing feature is industrialized scale — automated worm-driven scanning of exposed Docker APIs, Kubernetes clusters, and CI/CD endpoints, chained across five separate software ecosystems (GitHub Actions, Docker Hub, PyPI, npm, and OpenVSX) in a matter of weeks (Bitsight, Jul 2026).

TeamPCP matters right now because its trajectory illustrates where financially motivated cybercrime is heading: from a Telegram-based stolen-data brokerage in mid-2025 into a full-spectrum initial-access-broker-plus-ransomware operation. The group's March 2026 compromise of Aqua Security's Trivy, Checkmarx's KICS, and BerriAI's LiteLLM — an AI gateway with over 95 million monthly downloads — rippled outward to breach the European Commission's AWS environment (roughly 500,000 credentials and 300+ GB exfiltrated, per CERT-EU/The Record, 2026) and to touch automotive manufacturers including BMW, Audi, Honda, Mercedes-Benz, Volvo, and Toyota through their software supply chains (TechCrunch, Aug 2026).

Within the current eCrime landscape, TeamPCP sits at the convergence point of two trends analysts have flagged as accelerating through 2026: supply-chain compromise as a scalable initial-access vector, and the blurring line between access brokers and ransomware operators. Since a formal partnership announced in late March 2026, TeamPCP supplies stolen cloud and CI/CD access to the Vect ransomware operation for encryption and extortion, while simultaneously running its own CipherForce extortion brand for direct operations — a dual-track monetization model that maximizes return on every compromised credential (Sophos, 2026; Hard2Bit, 2026).

The critical operational context as of this compile date is the August 27, 2026 arrest of two alleged members in Western Australia and a parallel U.S. federal indictment (DOJ, N.D. Cal.) — a meaningful law-enforcement milestone, but one researchers assess as only partial disruption. TeamPCP is widely characterized as a loose confederation drawing from multiple cybercriminal circles rather than a single hierarchical cell (BleepingComputer, Aug 2026), and its decentralized, blockchain-backed C2 infrastructure was explicitly engineered for resilience against takedown.

01
Identity & Attribution
Primary NameTeamPCP
Sponsor / ParentNone identified — independent criminal enterprise
Actor TypeCloud-native eCrime / Initial Access Broker + Ransomware Operator
Primary MotivationFinancial gain — credential monetization, extortion, ransomware-as-a-service partnerships
Active SinceMid-2025 (Telegram stolen-data brokerage); operationally visible as a supply-chain actor late 2025
Last ObservedAug 2026 (active dual-track CipherForce/Vect extortion at time of arrests)
MITRE G-IDNot assigned — emerging actor, not yet catalogued in ATT&CK Groups as of 2026-08-30
Legal StatusINDICTED — 2 alleged members charged & in custody (AU), federal CFAA conspiracy indictment (DOJ, N.D. Cal.), as of 2026-08-27; additional members assessed at large
Tracking Aliases
TeamPCP UNC6780 (Mandiant/Google Cloud) Altered Spider (CrowdStrike) PCPcat ShellForce DeadCatx3 PersyPCP
Attribution Confidence

[HIGH] that the "TeamPCP" brand/cluster is responsible for the March–August 2026 supply-chain campaign: independently corroborated by Wiz, Unit 42, KELA (as UNC6780), Bitsight, and CrowdStrike (as Altered Spider) via consistent C2 infrastructure, malware, and TTPs, and reinforced by the August 2026 criminal indictment. [MEDIUM] on precise group structure and full membership — researchers describe TeamPCP as an amalgamation of individuals from multiple cybercriminal circles rather than one hierarchical group (BleepingComputer, Aug 2026); the two Telegram admin personas identified ("DMT"/BulkDMT and PersyPCP, ages ~20–21) are consistent with, but not conclusively matched to, the ages of the two individuals arrested (21 and 23). This would be upgraded to [HIGH] on structure with confirmed persona-to-defendant mapping from unsealed court filings.

02
Campaign & Operational Timeline
MID 2025
Telegram Stolen-Data Brokerage
TeamPCP surfaces as a Telegram-based broker of stolen data and access, run by admin personas "DMT"/BulkDMT and PersyPCP. No supply-chain activity yet observed at this stage (KELA Cyber, 2026).
DEC 2025
React2Shell (CVE-2025-55182) Disclosed & Exploited
A CVSS 10.0 unauthenticated RCE in React Server Components is disclosed and rapidly exploited in the wild by multiple threat clusters (Zscaler ThreatLabz, Microsoft, AWS, Dec 2025); TeamPCP later leverages it for cloud-hosted application access ahead of its 2026 campaign.
FEB 2026
Emerging Force — Cloud Scanning Campaigns
Flare publishes the first dedicated threat alert describing TeamPCP as "an emerging force in the cloud native and ransomware landscape," documenting large-scale automated scanning of exposed Docker APIs, Kubernetes clusters, and CI/CD pipelines (Flare, Feb 2026).
MAR 19–27, 2026
Cascading Supply Chain Compromise
Exploiting incomplete credential rotation, TeamPCP force-pushes malicious code to 76 of 77 tags on aquasecurity/trivy-action (Mar 19), poisons all tags of aquasecurity/setup-trivy (Mar 19), compromises Checkmarx KICS's GitHub Action (Mar 23), trojanizes BerriAI's LiteLLM PyPI packages v1.82.7–8 (Mar 24), and poisons the Telnyx Python SDK v4.87.1–2 (Mar 27) — ultimately touching 66+ npm packages and 3,800+ GitHub repositories (Unit 42, Apr 2026; TechCrunch, Aug 2026).
LATE MAR 2026
European Commission Breach & Vect Partnership
CERT-EU attributes a breach of over 1,000 SaaS environments, ~500,000 stolen credentials, and 300+ GB of exfiltrated data to TeamPCP (The Record, 2026). In parallel, TeamPCP and the Vect ransomware operation announce a formal partnership — TeamPCP supplies stolen access, Vect handles encryption and BreachForums-affiliate extortion (Sophos, 2026).
MAR 30, 2026
Disputed Secondary Victim Claims
Claims circulate of Databricks and AstraZeneca compromise tied to the campaign; Databricks states it "found nothing" after investigation and requested further evidence, and the AstraZeneca leak (~3 GB, released for free after a failed sale) is separately linked by some researchers to LAPSUS$ rather than TeamPCP directly — both should be treated as [LOW] confidence pending independent confirmation (SANS ISC, Mar 2026; Cybersecurity News, 2026).
AUG 27, 2026
Arrests & Federal Indictment
AFP and Western Australia Police Force, supported by the FBI, arrest Ruben Ian Thomson (21) and Louis Michael Gaebler (23) in Perth on 14 combined charges; the DOJ (N.D. Cal.) unseals a federal indictment charging Thomson with CFAA conspiracy (Krebs on Security, TechCrunch, DOJ USAO-NDCA, Aug 2026).
03
Attack Lifecycle Supply Chain Compromise → Cloud Credential Harvesting → Dual-Track Extortion

TeamPCP's entry point is almost never the eventual victim organization — it is a trusted upstream maintainer or CI/CD credential. The group has repeatedly exploited incomplete credential rotation and stale GitHub Personal Access Tokens tied to security-tooling maintainers, most notably against the Aqua Security Trivy project (Unit 42, Apr 2026), alongside opportunistic exploitation of CVE-2025-55182 ("React2Shell"), a CVSS 10.0 unauthenticated RCE in React Server Components, to gain footholds in exposed cloud-hosted applications. Reconnaissance is largely automated and worm-driven, scanning for exposed Docker APIs, Kubernetes clusters, and CI/CD endpoints at internet scale (Flare, Feb 2026).

Once inside a maintainer's account or pipeline, the group force-pushes malicious commits across historical release tags — in the Trivy compromise, 76 of 77 version tags on aquasecurity/trivy-action were overwritten, alongside every tag on aquasecurity/setup-trivy, so any downstream consumer pinning to a "stable" tag silently pulled trojanized code (Unit 42, Apr 2026). A parallel technique injects malicious pre/post-install scripts into package.json across dozens of npm packages and drops .pth files into Python packages for automatic execution at interpreter startup — the mechanism used to trojanize LiteLLM (95M+ monthly downloads) and the Telnyx SDK. Persistence inside compromised infrastructure is sustained through CanisterWorm, a self-propagation module spreading laterally across the npm/PyPI ecosystem, and kube.py, a secondary-stage payload deployed as a Kubernetes DaemonSet that masquerades as systemd or a PostgreSQL monitor (pgmon) process.

TeamPCP's primary payload, the "kamikaze.sh" cloud stealer, bypasses GitHub's secret-masking controls by reading CI runner process memory directly (/proc/<pid>/mem) to recover plaintext tokens, then harvests AWS/GCP/Azure credentials via cloud Instance Metadata Service abuse, plus Kubernetes secrets, SSH keys, CI/CD tokens, and LLM API keys. Command and control is deliberately resilient: primary infrastructure includes typosquatted domains such as scan.aquasecurtiy[.]org and a decentralized Internet Computer Protocol (ICP) blockchain "canister" acting as a tamper-proof dead drop, backstopped by hidden GitHub repositories created inside victim organizations (e.g., docs-tpcp) as a fallback channel engineered to survive infrastructure takedown.

Stolen data is encrypted client-side with AES-256-CBC under an embedded 4096-bit RSA public key, then smuggled out via WAV-file steganography (hangup.wav on Windows, ringtone.wav on Linux) before landing on TeamPCP-controlled infrastructure. From there the group monetizes on two parallel tracks: direct extortion under its own CipherForce leak-site brand, and — since the March 2026 partnership — supplying stolen access to the Vect ransomware operation for encryption and BreachForums-affiliate-driven extortion, functioning as a de facto initial-access broker for a second criminal ecosystem.

04
TTPs — MITRE ATT&CK Mapping ENTERPRISE — 14 techniques mapped; ICS/ATLAS not applicable
Reconnaissance
T1593
Search Open Websites/Domains
[HIGH] Worm-driven, automated internet-scale scanning for exposed Docker APIs, Kubernetes clusters, and CI/CD endpoints (Flare, Feb 2026).
Initial Access
T1190
Exploit Public-Facing Application
[HIGH] Exploitation of CVE-2025-55182 "React2Shell" (CVSS 10.0) in React Server Components for RCE against cloud-hosted apps (Zscaler ThreatLabz, Dec 2025).
Initial Access
T1199
Trusted Relationship
[HIGH] Abuse of stale GitHub PATs / PyPI publishing credentials tied to trusted upstream maintainers (Trivy) to poison downstream consumers (Unit 42, Apr 2026).
Execution
T1059
Command and Scripting Interpreter
[HIGH] Malicious install/pre-post-install scripts (kamikaze.sh) executed via npm/PyPI package lifecycle hooks.
Persistence
T1053.003
Scheduled Task/Job: Cron
[MEDIUM] kube.py secondary-stage payload establishes scheduled/recurring execution within compromised Kubernetes clusters.
Persistence
T1554
Compromise Client Software Binary
[HIGH] Force-pushed/re-tagged trojanized releases of Trivy, KICS, LiteLLM, and Telnyx SDK so pinned "stable" versions serve malicious code (Unit 42, Apr 2026).
Defense Evasion
T1036.005
Masquerading: Match Legitimate Name or Location
[HIGH] kube.py payload masquerades as systemd or a PostgreSQL monitor (pgmon) process inside compromised clusters.
Defense Evasion
T1027
Obfuscated Files or Information
[HIGH] Exfiltrated payloads hidden via WAV-file steganography (hangup.wav / ringtone.wav) and double base64-encoded secret-sweeper scripts.
Credential Access
T1003.007
OS Credential Dumping: Proc Filesystem
[HIGH] Reads CI runner process memory via /proc/<pid>/mem to bypass GitHub's secret-masking and recover plaintext tokens (Unit 42, Apr 2026).
Credential Access
T1552.005
Unsecured Credentials: Cloud Instance Metadata API
[HIGH] IMDS abuse to harvest AWS/GCP/Azure credentials from compromised CI/CD and cloud-hosted workloads.
Lateral Movement
T1021.007
Remote Services: Cloud Services
[MEDIUM] Pivots into victim AWS/GCP/Azure/Kubernetes environments using harvested cloud credentials and Kubernetes secrets.
Command & Control
T1102
Web Service
[HIGH] Decentralized Internet Computer Protocol (ICP) blockchain "canister" used as a tamper-proof C2 dead drop; hidden GitHub repos (e.g. docs-tpcp) as fallback channel.
Exfiltration
T1567
Exfiltration Over Web Service
[HIGH] AES-256-CBC/RSA-4096-encrypted data staged and exfiltrated over ICP canister and hidden-repository channels.
Impact
T1486
Data Encrypted for Impact
[MEDIUM] Ransomware deployment on harvested access via the CipherForce brand and, since Mar 2026, the partnered Vect ransomware locker.
05
Targeting Profile
Sector Targeting
Software Supply Chain / DevSecOps Tooling
PRIMARY
Cloud & SaaS Infrastructure
HIGH
Automotive & Manufacturing (Downstream)
MED
Government / Public Sector (EU Commission)
MED
Pharma / Healthcare (Contested Attribution)
LOW
GeographiesGlobal via downstream dependency exposure; direct confirmed activity in EU (European Commission), automotive OEMs headquartered in Germany/Japan/Sweden; operator base in Australia; earlier reconnaissance activity noted in Kenya, Somalia, South Africa (KELA, 2026)
Victim ProfileAny organization integrating open-source or commercial DevSecOps/AI tooling into CI/CD — victimization is largely indirect/downstream via poisoned dependencies rather than direct targeting
Preferred EntryExposed Docker APIs, Kubernetes clusters, CI/CD pipelines; stale/incompletely-rotated GitHub PATs and PyPI publishing tokens; CVE-2025-55182 (React2Shell) RCE
Target DoctrineOpportunistic, scale-over-precision — one compromised dependency can cascade to thousands of downstream consumers (Bitsight, Jul 2026)
06
Tools, Malware & Infrastructure
KAMIKAZE.SH ("TeamPCP Cloud Stealer") STEALER · CUSTOM · Unit 42
Primary credential-harvesting payload deployed via poisoned packages; at least 3 documented versions. Reads CI runner process memory via /proc/<pid>/mem to bypass GitHub secret masking, then extracts AWS/GCP/Azure tokens, SSH keys, Kubernetes configs, CI/CD secrets, and LLM API keys from .env files. Output is encrypted (AES-256-CBC/RSA-4096) before exfiltration. Detection artifact: outdated git/2.43.0 client and TruffleHog secret-validation signatures in outbound CI traffic.
CANISTERWORM WORM / C2 · CUSTOM · Unit 42
Self-propagating module that spreads laterally across the npm and PyPI package ecosystems. Its distinguishing architecture element is use of a decentralized Internet Computer Protocol (ICP) blockchain "canister" (tdtqy-oyaaa-aaaae-af2dq-cai.raw.icp0[.]io) as a tamper-proof C2 dead drop, making primary infrastructure resistant to conventional domain/IP takedown.
KUBE.PY LOADER / SECONDARY STAGE · CUSTOM · Unit 42
Kubernetes-focused secondary payload deployed as a DaemonSet for cluster-wide reach. Masquerades as systemd or a PostgreSQL monitor (pgmon) process to evade casual process review; used for scheduled re-execution and Kubernetes secrets harvesting.
NORD STREAM LOLBIN / OFFENSIVE TOOLING (REPURPOSED) · OSS · Wiz
Publicly available GitHub-exploitation/red-team framework repurposed to create and manipulate malicious GitHub Actions workflows at scale; observed with the tool's default branch-naming pattern (dev_remote_ea5Eu/test/v1) left unmodified in victim repositories — a useful detection artifact.
CIPHERFORCE RANSOMWARE / EXTORTION LOCKER · CUSTOM · Sophos / Hard2Bit
Proprietary data-leak and extortion brand operated directly by TeamPCP, run in parallel with the Vect affiliate program. TeamPCP has publicly stated it uses only CipherForce for its own encryption operations, distancing itself from a documented flaw in Vect's locker.
VECT RANSOMWARE RAAS · THIRD-PARTY PARTNER · Sophos / Jumpsec
External ransomware-as-a-service TeamPCP formally partnered with in late March 2026, supplying stolen access in exchange for BreachForums-affiliate-driven encryption and extortion at scale. Jumpsec (Apr 2026) documented a critical implementation flaw in Vect's locker that permanently destroys, rather than encrypts, files larger than 128KB.
07
Indicators of Compromise All IPs and domains defanged
⚠ IOC HANDLING — All IPs and domains in this table are defanged. Reconstruct before use in detection tooling. Reference URLs in Section 10 are NOT defanged.
Type Value / Description Source Date
IP105.245.181[.]120 (Vodacom) — TruffleHog secret validationWiz2026-03-19
IP138.199.15[.]172 (Datacamp/Mullvad exit) — GitHub exfil, AWS reconWiz2026-03-19–25
IP154.47.29[.]12 (Datacamp/Mullvad exit) — secret validation, AWS reconWiz2026-03-21–23
IP193.32.126[.]157 (31173 Services AB/Mullvad exit) — GitHub exfiltrationWiz2026-03-20
IP209.159.147[.]239 (InterServer VPS) — TruffleHog validationWiz2026-03-20–23
DOMAINscan.aquasecurtiy[.]org — typosquat of aquasecurity[.]com, staging/C2Unit 422026-03
DOMAINcheckmarx[.]zone — staging/C2Unit 422026-03
DOMAINmodels.litellm[.]cloud — staging/C2Unit 422026-03
DOMAINtdtqy-oyaaa-aaaae-af2dq-cai.raw.icp0[.]io — ICP canister dead-drop C2Unit 422026-03
FILEkamikaze.sh — cloud credential stealer payloadUnit 422026-03
FILEkube.py — Kubernetes secondary-stage payloadUnit 422026-03
FILEtpcp.tar[.]gz — payload archiveUnit 422026-03
FILEsession.key, payload.enc — exfiltration artifactsUnit 422026-03
FILEhangup.wav (Windows) / ringtone.wav (Linux) — steganographic exfil carriersUnit 422026-03
MALWARELiteLLM PyPI package v1.82.7–1.82.8 (trojanized)Unit 42 / TechCrunch2026-03-24
MALWARETelnyx Python SDK v4.87.1–4.87.2 (trojanized)Unit 422026-03-27
REGISTRYaquasecurity/trivy-action — 76 of 77 GitHub release tags force-pushed with malicious codeUnit 422026-03-19
REGISTRYaquasecurity/setup-trivy — all tags poisonedUnit 422026-03-19
CVECVE-2025-55182 ("React2Shell") — unauthenticated RCE in React Server Components, CVSS 10.0/9.3, exploited for initial accessZscaler ThreatLabzDisclosed 2025-12-03
PROTOCOLBranch name pattern dev_remote_ea5Eu/test/v1 (Nord Stream tool default) left in poisoned workflowsWiz2026-03
MESSAGEUser-agent indicators: git/2.43.0 (outdated), Boto3/1.42.73 with Kali Linux default signaturesWiz2026-03
NOTE24 malicious file SHA256 hashes catalogued by Unit 42 (Apr 2026); values not reproduced in this table — consult source report directly for hash-based detection.Unit 422026-08-30 (accessed)
08
Analyst Assessment
Overall Threat LevelCRITICAL
Attribution ConfidenceHIGH (campaign/brand) · MEDIUM (full structure)
TrajectoryDegrading but not neutralized — 2 members charged; core admin infrastructure and broader confederation likely persist
Most Dangerous CapabilityCascading software supply-chain compromise — single dependency access → thousands of downstream victims
Primary Intel GapFull membership roster/hierarchy; disputed secondary victim claims (Databricks, AstraZeneca)
Ecosystem / Affiliated Groups
Vect Ransomware (RaaS partner) CipherForce (own brand) BreachForums (affiliate recruitment) UNC6780 (Mandiant tracking) Altered Spider (CrowdStrike tracking)

TeamPCP represents the industrialization of software supply-chain compromise as a criminal business model rather than a technical leap forward. Every individual technique observed — RCE exploitation, PAT theft, typosquatting, package-lifecycle-hook abuse — is well-precedented; what sets the group apart is disciplined reuse of these techniques chained across five ecosystems (GitHub Actions, Docker Hub, PyPI, npm, OpenVSX) within a single multi-week campaign window, and a monetization structure (dual CipherForce/Vect tracks) built to extract value from every credential harvested, whether or not a given victim is worth a bespoke ransomware deployment.

The group's most dangerous capability is blast radius, not sophistication. The LiteLLM compromise alone touched a package with over 95 million monthly downloads; a single stolen maintainer credential compounded into confirmed or claimed impact against 2,500+ organizations, an EU institution, and multiple automotive OEMs. This dynamic — narrow initial access, broad downstream consequence — is structurally difficult for individual victim organizations to defend against, since the compromise arrives through a trusted update channel rather than a perimeter they control.

Attribution to the TeamPCP brand for the core March–August 2026 campaign is [HIGH] confidence, cross-corroborated by independent vendor telemetry (Wiz, Unit 42, KELA/UNC6780, CrowdStrike/Altered Spider) and now reinforced by criminal charges. Confidence on the group's internal structure remains [MEDIUM]: multiple outlets describe TeamPCP as a loose confederation of individuals drawn from several existing cybercriminal circles rather than a single hierarchical cell, which is consistent with an arrest netting only two individuals against a campaign of this scale. A competing hypothesis worth flagging explicitly: some claimed victims (Databricks, and possibly AstraZeneca — separately linked by some researchers to LAPSUS$) may reflect opportunistic claim-jacking on leak forums rather than confirmed TeamPCP operations, and should not be treated as confirmed without independent forensic corroboration. This assessment would move to [HIGH] on structure if unsealed court filings conclusively map the "DMT"/PersyPCP Telegram personas to the named defendants.

Forward risk trajectory: the August 2026 arrests are unlikely to fully neutralize the group given its loose, multi-member structure and infrastructure explicitly engineered for resilience — a decentralized ICP blockchain C2 channel and GitHub-repository fallback dead drops are both designed to survive conventional takedown. Expect continued targeting of security and DevSecOps tooling as a high-leverage vector (compromising the tools defenders trust is more efficient than defeating them), and continued Vect/BreachForums-affiliate monetization even if the CipherForce-specific operators identified in this action go dark.

09
Defensive Recommendations
01
Enforce short-lived, scoped GitHub PATs. Mandate fine-grained, repository-scoped tokens with mandatory rotation intervals; audit for stale or overly-broad tokens tied to release/publishing pipelines.
Counters: T1199 Trusted Relationship
02
Protect release tags. Require branch protection and mandatory code review on all release/version tags; alert on force-push or tag reassignment events on public-facing repositories.
Counters: T1554 Compromise Client Software Binary
03
Pin dependencies to immutable commit SHAs rather than mutable version tags in CI/CD and package manifests, and monitor upstream projects for unexpected tag reassignment.
Counters: T1554 Compromise Client Software Binary
04
Restrict CI runner process memory access. Isolate build steps and prevent arbitrary processes from reading /proc/<pid>/mem on shared runners to block secret-masking bypass.
Counters: T1003.007 OS Credential Dumping: Proc Filesystem
05
Enforce IMDSv2 with a hop-limit of 1 across all cloud compute (AWS/GCP/Azure) to close off Instance Metadata Service credential theft from compromised workloads or CI runners.
Counters: T1552.005 Unsecured Credentials: Cloud Instance Metadata API
06
Monitor CI/CD egress for TeamPCP tooling signatures — TruffleHog secret-validation traffic, outdated git/2.43.0 clients, and Boto3 calls carrying Kali Linux default user agents — and flag traffic to Mullvad/VPS-hosting ASNs (Datacamp, 31173 Services AB, InterServer).
Counters: T1102 Web Service; T1567 Exfiltration Over Web Service
07
Alert on unexpected private-repository creation within organizational GitHub accounts — the hidden fallback-C2 pattern (e.g., docs-tpcp) is a high-fidelity detection opportunity.
Counters: T1102 Web Service
08
Patch all React Server Components deployments against CVE-2025-55182 immediately if not already remediated, and treat any exposed instance as compromised pending forensic review.
Counters: T1190 Exploit Public-Facing Application
10
References URLs are NOT defanged — navigate directly
Wiz
Accessed: 2026-08-30
KELA Cyber
Accessed: 2026-08-30
Bitsight
Accessed: 2026-08-30
Malpedia (Fraunhofer FKIE)
Accessed: 2026-08-30
Cyble
Accessed: 2026-08-30
ThreatMon
Accessed: 2026-08-30
Krebs on Security
Accessed: 2026-08-30
SecurityWeek
Accessed: 2026-08-30
SOCRadar
Accessed: 2026-08-30
Hard2Bit
Accessed: 2026-08-30
Zscaler ThreatLabz
Accessed: 2026-08-30