Also known as: Altered Spider, PCPcat, ShellForce, DeadCatx3, CanisterWorm, SHADOW-WATER-058, UNC6780
The npm ecosystem experienced a critical shift in September 2025 with the Shai-Hulud worm, marking the transition from isolated attacks to systematic supply chain compromises. In April 2026, TeamPCP launched a coordinated campaign through a malicious @bitwarden/cli package targeting multiple distribution channels including Docker Hub, GitHub Actions, and VS Code extensions. The multi-stage payload employs advanced obfuscation, harvests credentials from cloud providers and developer workstations, exfiltrates data through encrypted HTTPS and GitHub repositories, and self-propagates by backdooring npm packages using stolen tokens. The malware implements GitHub's search API as a resilient command-and-control fallback mechanism and features anti-detection measures including Russian locale killswitches. This represents an evolution toward wormable propagation, infrastructure-level persistence, and dormant payloads that activate under specific conditions.
Executive Summary
TeamPCP is a sophisticated threat actor that launched a coordinated campaign in April 2026, compromising the npm ecosystem through a malicious @bitwarden/cli package. This campaign marks an evolution in their tactics, techniques, and procedures (TTPs), employing advanced obfuscation, credential harvesting, and data exfiltration. The actor's goals and motivations are focused on supply chain compromise and infrastructure-level persistence.
Goals & Targeting
The TeamPCP threat actor's strategic objectives and targeting profile suggest a focus on supply chain compromise and infrastructure-level persistence. They target specific sectors and countries, seeking to gain access to sensitive data and systems, and have been observed to target multiple distribution channels including Docker Hub, GitHub Actions, and VS Code extensions. The actor's typical victims are likely to be organizations that rely on the npm ecosystem, and may include developers, cloud providers, and other entities that use these technologies.
Enhanced Description
The TeamPCP campaign has significant implications for the security of the npm ecosystem, as it demonstrates the potential for widespread compromise through supply chain attacks. The actor's use of advanced obfuscation techniques and anti-detection measures makes it difficult for defenders to detect and respond to these attacks, and the ability to self-propagate and employ resilient command-and-control mechanisms makes it challenging to eradicate the malware from infected systems.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
The TeamPCP campaign has been observed to be highly coordinated, with the actor employing a range of tactics and techniques to compromise their targets. The campaign has been ongoing since at least April 2026, and has targeted multiple distribution channels including Docker Hub, GitHub Actions, and VS Code extensions. The actor's typical victims are likely to be organizations that rely on the npm ecosystem, and may include developers, cloud providers, and other entities that use these technologies. Notable past operations include the compromise of the npm ecosystem through the Shai-Hulud worm in September 2025.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The confidence level in the available data is moderate to high, based on the observation of the actor's tactics and techniques. However, there are some information gaps, including the actor's primary motivation and goals, as well as the full extent of their capabilities and targeting profile. Further analysis and intelligence gathering are needed to fully understand the threat posed by TeamPCP.
No campaigns linked yet.
No observed data linked yet.
36
Techniques
3
Tools
0
Campaigns
170
IOCs
0
Observed Data
12
Tactics