TeamPCP is a financially motivated, cloud-native cybercriminal operation that in 2026 ran what several vendors independently describe as the most consequential open-source software supply chain campaign of the year (Flare, Feb 2026; SocRadar, 2026). Rather than attacking victims directly, the group compromises the trusted upstream software — security scanners, AI gateways, SDKs — that thousands of organizations pull into their build pipelines, converting a single maintainer's stolen credential into a cascading compromise of everyone downstream. Its defining trait is not technical novelty: initial access, credential theft, and typosquatting are all long-understood techniques. The distinguishing feature is industrialized scale — automated worm-driven scanning of exposed Docker APIs, Kubernetes clusters, and CI/CD endpoints, chained across five separate software ecosystems (GitHub Actions, Docker Hub, PyPI, npm, and OpenVSX) in a matter of weeks (Bitsight, Jul 2026).
TeamPCP matters right now because its trajectory illustrates where financially motivated cybercrime is heading: from a Telegram-based stolen-data brokerage in mid-2025 into a full-spectrum initial-access-broker-plus-ransomware operation. The group's March 2026 compromise of Aqua Security's Trivy, Checkmarx's KICS, and BerriAI's LiteLLM — an AI gateway with over 95 million monthly downloads — rippled outward to breach the European Commission's AWS environment (roughly 500,000 credentials and 300+ GB exfiltrated, per CERT-EU/The Record, 2026) and to touch automotive manufacturers including BMW, Audi, Honda, Mercedes-Benz, Volvo, and Toyota through their software supply chains (TechCrunch, Aug 2026).
Within the current eCrime landscape, TeamPCP sits at the convergence point of two trends analysts have flagged as accelerating through 2026: supply-chain compromise as a scalable initial-access vector, and the blurring line between access brokers and ransomware operators. Since a formal partnership announced in late March 2026, TeamPCP supplies stolen cloud and CI/CD access to the Vect ransomware operation for encryption and extortion, while simultaneously running its own CipherForce extortion brand for direct operations — a dual-track monetization model that maximizes return on every compromised credential (Sophos, 2026; Hard2Bit, 2026).
The critical operational context as of this compile date is the August 27, 2026 arrest of two alleged members in Western Australia and a parallel U.S. federal indictment (DOJ, N.D. Cal.) — a meaningful law-enforcement milestone, but one researchers assess as only partial disruption. TeamPCP is widely characterized as a loose confederation drawing from multiple cybercriminal circles rather than a single hierarchical cell (BleepingComputer, Aug 2026), and its decentralized, blockchain-backed C2 infrastructure was explicitly engineered for resilience against takedown.
[HIGH] that the "TeamPCP" brand/cluster is responsible for the March–August 2026 supply-chain campaign: independently corroborated by Wiz, Unit 42, KELA (as UNC6780), Bitsight, and CrowdStrike (as Altered Spider) via consistent C2 infrastructure, malware, and TTPs, and reinforced by the August 2026 criminal indictment. [MEDIUM] on precise group structure and full membership — researchers describe TeamPCP as an amalgamation of individuals from multiple cybercriminal circles rather than one hierarchical group (BleepingComputer, Aug 2026); the two Telegram admin personas identified ("DMT"/BulkDMT and PersyPCP, ages ~20–21) are consistent with, but not conclusively matched to, the ages of the two individuals arrested (21 and 23). This would be upgraded to [HIGH] on structure with confirmed persona-to-defendant mapping from unsealed court filings.
TeamPCP's entry point is almost never the eventual victim organization — it is a trusted upstream maintainer or CI/CD credential. The group has repeatedly exploited incomplete credential rotation and stale GitHub Personal Access Tokens tied to security-tooling maintainers, most notably against the Aqua Security Trivy project (Unit 42, Apr 2026), alongside opportunistic exploitation of CVE-2025-55182 ("React2Shell"), a CVSS 10.0 unauthenticated RCE in React Server Components, to gain footholds in exposed cloud-hosted applications. Reconnaissance is largely automated and worm-driven, scanning for exposed Docker APIs, Kubernetes clusters, and CI/CD endpoints at internet scale (Flare, Feb 2026).
Once inside a maintainer's account or pipeline, the group force-pushes malicious commits across historical release tags — in the Trivy compromise, 76 of 77 version tags on aquasecurity/trivy-action were overwritten, alongside every tag on aquasecurity/setup-trivy, so any downstream consumer pinning to a "stable" tag silently pulled trojanized code (Unit 42, Apr 2026). A parallel technique injects malicious pre/post-install scripts into package.json across dozens of npm packages and drops .pth files into Python packages for automatic execution at interpreter startup — the mechanism used to trojanize LiteLLM (95M+ monthly downloads) and the Telnyx SDK. Persistence inside compromised infrastructure is sustained through CanisterWorm, a self-propagation module spreading laterally across the npm/PyPI ecosystem, and kube.py, a secondary-stage payload deployed as a Kubernetes DaemonSet that masquerades as systemd or a PostgreSQL monitor (pgmon) process.
TeamPCP's primary payload, the "kamikaze.sh" cloud stealer, bypasses GitHub's secret-masking controls by reading CI runner process memory directly (/proc/<pid>/mem) to recover plaintext tokens, then harvests AWS/GCP/Azure credentials via cloud Instance Metadata Service abuse, plus Kubernetes secrets, SSH keys, CI/CD tokens, and LLM API keys. Command and control is deliberately resilient: primary infrastructure includes typosquatted domains such as scan.aquasecurtiy[.]org and a decentralized Internet Computer Protocol (ICP) blockchain "canister" acting as a tamper-proof dead drop, backstopped by hidden GitHub repositories created inside victim organizations (e.g., docs-tpcp) as a fallback channel engineered to survive infrastructure takedown.
Stolen data is encrypted client-side with AES-256-CBC under an embedded 4096-bit RSA public key, then smuggled out via WAV-file steganography (hangup.wav on Windows, ringtone.wav on Linux) before landing on TeamPCP-controlled infrastructure. From there the group monetizes on two parallel tracks: direct extortion under its own CipherForce leak-site brand, and — since the March 2026 partnership — supplying stolen access to the Vect ransomware operation for encryption and BreachForums-affiliate-driven extortion, functioning as a de facto initial-access broker for a second criminal ecosystem.
| Type | Value / Description | Source | Date |
|---|---|---|---|
| IP | 105.245.181[.]120 (Vodacom) — TruffleHog secret validation | Wiz | 2026-03-19 |
| IP | 138.199.15[.]172 (Datacamp/Mullvad exit) — GitHub exfil, AWS recon | Wiz | 2026-03-19–25 |
| IP | 154.47.29[.]12 (Datacamp/Mullvad exit) — secret validation, AWS recon | Wiz | 2026-03-21–23 |
| IP | 193.32.126[.]157 (31173 Services AB/Mullvad exit) — GitHub exfiltration | Wiz | 2026-03-20 |
| IP | 209.159.147[.]239 (InterServer VPS) — TruffleHog validation | Wiz | 2026-03-20–23 |
| DOMAIN | scan.aquasecurtiy[.]org — typosquat of aquasecurity[.]com, staging/C2 | Unit 42 | 2026-03 |
| DOMAIN | checkmarx[.]zone — staging/C2 | Unit 42 | 2026-03 |
| DOMAIN | models.litellm[.]cloud — staging/C2 | Unit 42 | 2026-03 |
| DOMAIN | tdtqy-oyaaa-aaaae-af2dq-cai.raw.icp0[.]io — ICP canister dead-drop C2 | Unit 42 | 2026-03 |
| FILE | kamikaze.sh — cloud credential stealer payload | Unit 42 | 2026-03 |
| FILE | kube.py — Kubernetes secondary-stage payload | Unit 42 | 2026-03 |
| FILE | tpcp.tar[.]gz — payload archive | Unit 42 | 2026-03 |
| FILE | session.key, payload.enc — exfiltration artifacts | Unit 42 | 2026-03 |
| FILE | hangup.wav (Windows) / ringtone.wav (Linux) — steganographic exfil carriers | Unit 42 | 2026-03 |
| MALWARE | LiteLLM PyPI package v1.82.7–1.82.8 (trojanized) | Unit 42 / TechCrunch | 2026-03-24 |
| MALWARE | Telnyx Python SDK v4.87.1–4.87.2 (trojanized) | Unit 42 | 2026-03-27 |
| REGISTRY | aquasecurity/trivy-action — 76 of 77 GitHub release tags force-pushed with malicious code | Unit 42 | 2026-03-19 |
| REGISTRY | aquasecurity/setup-trivy — all tags poisoned | Unit 42 | 2026-03-19 |
| CVE | CVE-2025-55182 ("React2Shell") — unauthenticated RCE in React Server Components, CVSS 10.0/9.3, exploited for initial access | Zscaler ThreatLabz | Disclosed 2025-12-03 |
| PROTOCOL | Branch name pattern dev_remote_ea5Eu/test/v1 (Nord Stream tool default) left in poisoned workflows | Wiz | 2026-03 |
| MESSAGE | User-agent indicators: git/2.43.0 (outdated), Boto3/1.42.73 with Kali Linux default signatures | Wiz | 2026-03 |
| NOTE | 24 malicious file SHA256 hashes catalogued by Unit 42 (Apr 2026); values not reproduced in this table — consult source report directly for hash-based detection. | Unit 42 | 2026-08-30 (accessed) |
TeamPCP represents the industrialization of software supply-chain compromise as a criminal business model rather than a technical leap forward. Every individual technique observed — RCE exploitation, PAT theft, typosquatting, package-lifecycle-hook abuse — is well-precedented; what sets the group apart is disciplined reuse of these techniques chained across five ecosystems (GitHub Actions, Docker Hub, PyPI, npm, OpenVSX) within a single multi-week campaign window, and a monetization structure (dual CipherForce/Vect tracks) built to extract value from every credential harvested, whether or not a given victim is worth a bespoke ransomware deployment.
The group's most dangerous capability is blast radius, not sophistication. The LiteLLM compromise alone touched a package with over 95 million monthly downloads; a single stolen maintainer credential compounded into confirmed or claimed impact against 2,500+ organizations, an EU institution, and multiple automotive OEMs. This dynamic — narrow initial access, broad downstream consequence — is structurally difficult for individual victim organizations to defend against, since the compromise arrives through a trusted update channel rather than a perimeter they control.
Attribution to the TeamPCP brand for the core March–August 2026 campaign is [HIGH] confidence, cross-corroborated by independent vendor telemetry (Wiz, Unit 42, KELA/UNC6780, CrowdStrike/Altered Spider) and now reinforced by criminal charges. Confidence on the group's internal structure remains [MEDIUM]: multiple outlets describe TeamPCP as a loose confederation of individuals drawn from several existing cybercriminal circles rather than a single hierarchical cell, which is consistent with an arrest netting only two individuals against a campaign of this scale. A competing hypothesis worth flagging explicitly: some claimed victims (Databricks, and possibly AstraZeneca — separately linked by some researchers to LAPSUS$) may reflect opportunistic claim-jacking on leak forums rather than confirmed TeamPCP operations, and should not be treated as confirmed without independent forensic corroboration. This assessment would move to [HIGH] on structure if unsealed court filings conclusively map the "DMT"/PersyPCP Telegram personas to the named defendants.
Forward risk trajectory: the August 2026 arrests are unlikely to fully neutralize the group given its loose, multi-member structure and infrastructure explicitly engineered for resilience — a decentralized ICP blockchain C2 channel and GitHub-repository fallback dead drops are both designed to survive conventional takedown. Expect continued targeting of security and DevSecOps tooling as a high-leverage vector (compromising the tools defenders trust is more efficient than defeating them), and continued Vect/BreachForums-affiliate monetization even if the CipherForce-specific operators identified in this action go dark.