TeamPCP is a financially motivated cybercrime threat actor, also tracked as UNC6780, that emerged in late 2025 and became prominent in 2026 for large-scale software supply-chain intrusions and cloud-focused credential theft. The group has also been associated with the aliases DeadCatx3, PCPcat, ShellForce, CipherForce, and Persy_PCP. Its operations center on compromising trusted developer tooling, CI/CD pipelines, package ecosystems, and cloud-native infrastructure in order to steal credentials, propagate to downstream environments, and monetize access through data theft and ransomware partnerships. TeamPCP initially focused on opportunistic exploitation of exposed or misconfigured cloud services, including Docker APIs, Kubernetes clusters, Redis servers, and Ray-related services. It later escalated into coordinated supply-chain attacks affecting open-source security tools, developer utilities, AI middleware, package repositories, GitHub Actions, container distribution channels, and developer endpoints. Reported victims and targets have included projects and vendors in the cloud-native security, application security, AI, developer tooling, and software infrastructure sectors. The actor is best known for a March 2026 campaign that compromised multiple widely used tools in rapid succession, including Aqua Security’s Trivy ecosystem, Checkmarx GitHub Actions, and LiteLLM, followed by broader propagation through npm and other ecosystems. In these incidents, TeamPCP abused stolen CI/CD secrets, publishing credentials, service-account tokens, and signing or release automation trust relationships. The group repeatedly leveraged mutable release tags, poisoned GitHub Actions workflows, malicious package uploads, and compromised build pipelines to distribute credential-stealing payloads under legitimate project identities. A recurring payload associated with the actor is commonly referred to as the TeamPCP Cloud Stealer. Across reporting, this malware harvested secrets from CI/CD runners and developer systems, including GitHub tokens, cloud credentials from AWS, GCP, and Azure, Kubernetes tokens, SSH keys, API keys, database credentials, environment variables, browser and messaging application data, cryptocurrency wallet material, and secrets used by AI development tools. Observed collection methods included dumping runner process memory, scraping local files and shell history, querying cloud metadata services, and searching repositories or workspaces for embedded secrets such as webhook tokens. Exfiltration was typically encrypted and designed with fallback mechanisms to preserve access even if primary channels were disrupted. TeamPCP has demonstrated strong tradecraft in abusing software trust chains rather than relying solely on direct exploitation. Reported techniques include force-pushing malicious commits to trusted version tags, compromising package publishing workflows, abusing pull_request_target-style CI misconfigurations, extracting tokens from runner memory, cache poisoning in CI environments, and using poisoned developer extensions or packages to gain access to internal repositories and endpoints. The group has also used self-propagating malware, including CanisterWorm and Mini Shai-Hulud, to steal package-manager credentials and automatically spread through additional packages and ecosystems. Beyond credential theft, TeamPCP activity has included persistence and destructive behavior. Reported payloads established persistence through mechanisms such as systemd user services, scheduled tasks, launch agents, Python startup hooks, and modifications to developer tooling configuration files. Some campaigns also included region-targeted sabotage or wiper logic aimed at specific locale or timezone conditions, including destructive actions in Kubernetes environments. These behaviors distinguish the actor from purely opportunistic package malware operators and indicate willingness to combine espionage, monetization, and disruption. The group has targeted both upstream maintainers and downstream consumers. Its compromises have affected security scanners, infrastructure-as-code tooling, AI middleware, developer libraries, GitHub Actions, VS Code extensions, and package ecosystems including npm and PyPI, with additional activity reported in container and extension distribution channels. TeamPCP has also been linked to the compromise of GitHub internal repositories through a poisoned Visual Studio Code extension installed on an employee device, after which the actor allegedly attempted to sell stolen internal source code and organizational data. TeamPCP is widely assessed as a cybercriminal rather than state-sponsored actor. Its behavior indicates a hybrid operating model that combines supply-chain intrusion, credential harvesting, access brokerage, direct data-sale activity, and ransomware monetization. Reporting has linked the group to parallel ransomware channels, including its own CipherForce branding and a relationship with the Vect ransomware ecosystem. These links suggest TeamPCP uses stolen credentials and downstream access not only for continued propagation but also for extortion and affiliate-style monetization. Overall, TeamPCP represents a high-impact supply-chain threat actor focused on developer trust boundaries, cloud-native environments, and software distribution infrastructure. Its hallmark characteristics are rapid multi-wave compromise, credential-centric post-exploitation, abuse of legitimate release mechanisms, worm-like propagation across ecosystems, and flexible monetization through theft, resale, and ransomware-aligned operations.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
43 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
11 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A named group behind the Mini Shai-Hulud campaign targeting both npm and PyPI in a coordinated software supply-chain operation, later publishing the worm source code publicly to encourage wider criminal reuse.
Financially motivated cybercrime group conducting supply chain attacks against developer tooling and selling stolen source code/data rather than relying solely on ransomware extortion.
Cybercrime group conducting supply chain attacks, including the GitHub breach via a poisoned VS Code extension and prior compromises of open-source security and AI-related packages. The group is also described as stealing CI/CD credentials, publishing infected package versions, and attempting to sell stolen GitHub repository contents.
Allegedly offering stolen GitHub source code and internal organization data for sale following unauthorized access to GitHub internal repositories.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.