TeamPCP

G1056

Threat group.View on attack.mitre.org

About this group

TeamPCP is a financially-motivated, cloud-native threat group that has been active since at least September 2025. Initially focused on ransomware and cryptocurrency theft, TeamPCP shifted in early 2026 to systematic, worm-driven credential theft and software supply chain attacks targeting Continuous Integration and Continuous Delivery (CI/CD) workflows. TeamPCP has monetized access through extortion and through partnerships with ransomware actors including Vect and CipherForce.

Techniques used36

Procedure examples36

TechniqueProcedure example
T1005
Data from Local System

TeamPCP has stolen source code from victim environments including Mistral AI.

T1027.003
Steganography

TeamPCP has hidden malicious payloads in the frame data of WAV audio files.

T1036.005
Match Legitimate Resource Name or Location

TeamPCP has cloned GitHub commit metadata including the author name, email, committer, and timestamps to use for impostor commits. TeamPCP has also used legitimate file names such as msbuild.exe and ringtone.wav to mask malicious payloads.

T1059.004
Unix Shell

TeamPCP has leveraged malware capable of execution via the Linux CLI.

T1059.006
Python

TeamPCP has poisoned PyPi packages with malicious code and has used a 13 file modular Python framework for data collection.

T1059.007
JavaScript

TeamPCP has used the JavaScript runtime for malware delivery and injected malicious JavaScript into OpenVSX extensions.

T1059.013
Container CLI/API

TeamPCP has queried the Kubernetes API for local service account tokens and has used `kubectl` for lateral movement.

T1078
Valid Accounts

TeamPCP has compromised credentials associated with open source security scanning tools and used them to push malicious code to all the resources the tools had access to.

T1078.004
Cloud Accounts

TeamPCP has used compromised credentials for GitHub and software package repositories, including privileged service accounts, to inject malicious code into CI/CD pipelines.

T1098
Account Manipulation

TeamPCP has modified settings to publish private Aqua Security repositories to GitHub as public.

T1105
Ingress Tool Transfer

TeamPCP has modified legitimate software binaries to retrieve secondary payloads from C2.

T1176.002
IDE Extensions

TeamPCP has compromised VS Code and Open VSX IDE extensions.

T1190
Exploit Public-Facing Application

TeamPCP has exploited misconfigurations in GitHub Actions and vulnerabilities such as CVE-2026-33634 in the Aqua Security Trivy scanner and CVE-2025-55182 (React2Shell) against vulnerable cloud endpoints.

T1195.001
Compromise Software Dependencies and Development Tools

TeamPCP has conducted coordinated supply chain attacks targeting open-source developer infrastructure including the NPM, VS Code, Docker, and PyPi ecosystems to compromise multiple software packages.

T1485
Data Destruction

TeamPCP has deployed privileged DaemonSets to delete files on Kubernetes clusters and has executed recursive file deletions on non-containerized hosts.

View all 36 procedure examples

Software3

Campaigns0

None recorded.

References6

  1. Aqua Security Blog Trivy Compromise APR 2026 Open source
    Aqua Team. (2026, April 1). Update: Ongoing Investigation and Continued Remediation. Retrieved July 1, 2026.
  2. Aqua Security Trivy Compromise MAR 2026 Open source
    Aqua Security . (2026, March 21). Trivy ecosystem supply chain temporarily compromised. Retrieved July 1, 2026.
  3. Palo Alto TeamPCP MAR 2026 Open source
    Unit 42. (2026, March 31). Weaponizing the Protectors: TeamPCP’s Multi-Stage Supply Chain Attack on Security Infrastructure. Retrieved July 1, 2026.
  4. Trend Micro TeamPCP MAY 2026 Open source
    Santos, J. and Navato, J.R. (2026, May 13). Analyzing TeamPCP’s Supply Chain Attacks: Checkmarx KICS and elementary-data in CI/CD Credential Theft. Retrieved July 16, 2026.
  5. Wiz TeamPCP Profile MAY 2026 Open source
    Wiz. (2026, May 20). TeamPCP. Retrieved July 16, 2026.
  6. Wiz Trivy Compromise MAR 2026 Open source
    McCarthy, R. (2026, March 20). Trivy Compromised: Everything You Need to Know about the Latest Supply Chain Attack. Retrieved July 1, 2026.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.