TeamPCP, also tracked as UNC6780, is a financially motivated cybercriminal threat actor active since late 2025 that became prominent for large-scale software supply-chain intrusions in 2026. Known aliases include DeadCatx3, PCPcat, Persy_PCP, ShellForce, Team_PCP, and related tracking names such as UNC6780. The actor has also been associated in reporting with the CipherForce name and with malware and campaign labels including SANDCLOCK, CanisterWorm, CanisterSprawl, Mini Shai-Hulud, Miasma, and Hades. TeamPCP initially focused on opportunistic cloud-native exploitation, including exposed Docker APIs, Kubernetes clusters, Redis services, Ray dashboards, and vulnerable public-facing applications. Its activity later evolved into coordinated supply-chain operations targeting trusted developer and security tooling across GitHub Actions, container registries, npm, PyPI, OpenVSX, and Visual Studio Code extension ecosystems. High-confidence reporting links the actor to compromises affecting Trivy, Checkmarx KICS and AST GitHub Actions and related artifacts, LiteLLM, the Telnyx Python SDK, Bitwarden CLI, xinference, SAP CAP packages, Nx Console, and other open-source or developer-facing components. A defining characteristic of TeamPCP is cascading credential theft: the actor compromises one project’s CI/CD or release pipeline, steals secrets and publishing credentials from downstream users, and then reuses those credentials to compromise additional projects and ecosystems. The group has repeatedly abused insecure GitHub Actions patterns, especially pull_request_target-style workflow misconfigurations, mutable version tags, exposed CI/CD secrets, package publishing tokens, and signing or release credentials. It has also leveraged trusted publishing workflows by extracting short-lived credentials from runner memory. Its malware consistently targets build and developer environments for high-value secrets, including GitHub tokens, npm and PyPI publishing credentials, cloud provider credentials, Kubernetes configurations and service-account material, SSH keys, database credentials, Terraform state, environment files, API keys, and cryptocurrency wallet data. Observed collection methods include scraping CI runner memory, reading process environments, harvesting files from common credential locations, querying cloud metadata services, enumerating IAM and storage resources, and collecting Kubernetes secrets. Exfiltration has used encrypted archives and multiple fallback channels, including victim-controlled repositories or release assets when primary infrastructure was unavailable. TeamPCP has demonstrated post-compromise tradecraft beyond initial credential theft. Reporting describes rapid validation of stolen credentials, cloud reconnaissance within hours of access, enumeration of IAM roles, compute resources, storage, databases, and container infrastructure, and in some cases persistence through user-level services or Kubernetes DaemonSets. Some payloads used Internet Computer Protocol canisters as decentralized command-and-control infrastructure, an unusual technique in software supply-chain operations. Variants also showed worm-like propagation across package ecosystems by identifying publishable packages and republishing trojanized updates under legitimate namespaces. The actor’s 2026 campaign had substantial downstream impact. Trivy-related compromises alone reportedly exposed thousands of CI/CD workflows and more than 1,000 SaaS environments. Stolen credentials were subsequently used in intrusions affecting major organizations, including the European Commission and Cisco development environments. TeamPCP activity has also been linked to theft of large volumes of source code and cloud data, and to follow-on exploitation by other criminal actors using credentials harvested during the campaign. TeamPCP is assessed as financially motivated rather than state-sponsored. Google formally designated the cluster as UNC6780, and available reporting does not place it within a known nation-state intrusion set. The actor has been linked to extortion and ransomware-adjacent activity, including operational overlap or partnership claims involving Vect and use of the CipherForce name. Public reporting also describes TeamPCP as a loose-knit criminal group rather than a formal hierarchical organization, though that characterization is less firmly corroborated than its operational behavior. From a tactics-and-techniques perspective, TeamPCP is notable for supply-chain compromise, abuse of CI/CD pipelines, credential access from memory and files, trusted relationship abuse, package and container poisoning, cloud and Kubernetes discovery, persistence via services and cluster workloads, and rapid lateral pivoting through stolen secrets. Its operations illustrate a mature criminal model that treats developer tooling and release infrastructure as scalable access brokers for downstream enterprise compromise.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
54 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
30 malware families attributed to this actor across reporting.
25 additional families tracked in Mallory.
7 CVEs this actor has used in observed campaigns. 7 of them exploited in the wild.
On 19 March, TeamPCP launched a coordinated multi-channel attack that resulted in CVE-2026-33634, a supply chain compromise affecting the official Trivy distribution infrastructure.
The tracking identifier is CVE-2026-45321 (CVSS 9.6 per The Hacker News; advisory GHSA-g7cv-rxg3-hmpx per Snyk).
Their December 2025 'React2Shell' campaign exploited CVE-2025-55182 to target exposed Docker APIs, Kubernetes clusters, Ray dashboards, and Redis servers, deploying a worm-driven botnet that peaked around December 25 before going quiet.
Analysis of react.py This script is clearly set to exploit CVE-2025-29927, also known as React2Shell. ... This script implements a fully automated React/Next.js exploitation pipeline centered on abusing CVE-2025-29927 to achieve remote command execution at scale.
The four CVEs associated with this campaign are CVE-2026-33634, CVE-2026-48027, CVE-2026-45321, and CVE-2025-55182.
2 more CVEs tied to this actor tracked in Mallory.
555 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned as a comparison point and explicitly assessed as likely not involved in the Sandworm_Mode activity.
Financially motivated threat group linked to major software supply-chain activity, including use of the Mini Shai-Hulud worm and derivative campaigns affecting the software development ecosystem.
Named as the group allegedly responsible for the CanisterWorm intrusion against RapidFort and the exfiltration of large volumes of cloud and DevOps data later offered for sale.
A threat cluster linked to earlier 2026 software supply chain compromises involving trusted development tools and software-publishing identities. In this reference, it is discussed as potentially related to the AsyncAPI compromise through shared tooling and operational methods, but the article explicitly says the evidence does not conclusively prove TeamPCP conducted the July attack.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.