ATT&CKReferencesAikido TeamPCP Telnyx MAR 2026

Aikido TeamPCP Telnyx MAR 2026

Eriksen, C. (2026, March 27). Popular telnyx package compromised on PyPI by TeamPCP. Retrieved July 16, 2026.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples17

TechniqueUsed byProcedure example
T1027.003
Steganography
GroupTeamPCP

TeamPCP has hidden malicious payloads in the frame data of WAV audio files.

T1036.005
Match Legitimate Resource Name or Location
GroupTeamPCP

TeamPCP has cloned GitHub commit metadata including the author name, email, committer, and timestamps to use for impostor commits. TeamPCP has also used legitimate file names such as msbuild.exe and ringtone.wav to mask malicious payloads.

T1059.006
Python
GroupTeamPCP

TeamPCP has poisoned PyPi packages with malicious code and has used a 13 file modular Python framework for data collection.

T1078
Valid Accounts
GroupTeamPCP

TeamPCP has compromised credentials associated with open source security scanning tools and used them to push malicious code to all the resources the tools had access to.

T1105
Ingress Tool Transfer
GroupTeamPCP

TeamPCP has modified legitimate software binaries to retrieve secondary payloads from C2.

T1176.002
IDE Extensions
GroupTeamPCP

TeamPCP has compromised VS Code and Open VSX IDE extensions.

T1190
Exploit Public-Facing Application
GroupTeamPCP

TeamPCP has exploited misconfigurations in GitHub Actions and vulnerabilities such as CVE-2026-33634 in the Aqua Security Trivy scanner and CVE-2025-55182 (React2Shell) against vulnerable cloud endpoints.

T1195.001
Compromise Software Dependencies and Development Tools
GroupTeamPCP

TeamPCP has conducted coordinated supply chain attacks targeting open-source developer infrastructure including the NPM, VS Code, Docker, and PyPi ecosystems to compromise multiple software packages.

T1195.001
Compromise Software Dependencies and Development Tools
MalwareCanisterWorm

CanisterWorm has spread through an automated process that infects and publishes npm packages.

T1547.001
Registry Run Keys / Startup Folder
GroupTeamPCP

TeamPCP has dropped malware into the Windows Startup folder to establish persistence.

T1550.001
Application Access Token
MalwareCanisterWorm

CanisterWorm has leveraged stolen npm tokens to automate compromise by enumerating all publishable packages in a namespace, bumping versions, and publishing itself across the entire scope.

T1550.001
Application Access Token
GroupTeamPCP

TeamPCP has used stolen access tokens to inject malicious code into CI/CD workflows and to exfiltrate sensitive data from cloud, developer, and container environments.

T1555.006
Cloud Secrets Management Stores
GroupTeamPCP

TeamPCP has used malware to exfiltrate cloud secrets from targeted environments including AWS, GCP, and Azure.

T1564.001
Hidden Files and Directories
GroupTeamPCP

TeamPCP has used a hidden .lock file to establish a 12 hour cooldown period between re-drops for installed malware.

T1583.006
Web Services
GroupTeamPCP

TeamPCP has set up Clouflare Tunnels for malware C2. TeamPCP has also used the session messenger network for decentralized, encrypted exfiltration via  *.getsession[.]org to recipient  ID `05f9e609d79eed391015e11380dee4b5c9ead0b6e2e7f0134e6e51767a87323026`.

T1677
Poisoned Pipeline Execution
GroupTeamPCP

TeamPCP has compromised trusted CI/CD pipelines by injecting credential-stealing payloads into legitimate workflows and software packages including open-source security tools Trivy and KICS, and AI gateway LiteLLM.

T1677
Poisoned Pipeline Execution
MalwareCanisterWorm

CanisterWorm has leveraged stolen tokens from Trivy users to publish itself across over 46 npm packages.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.