Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors TeamPCP

Also known as: Altered Spider, PCPcat, ShellForce, DeadCatx3, CanisterWorm, SHADOW-WATER-058, UNC6780

Description

The npm ecosystem experienced a critical shift in September 2025 with the Shai-Hulud worm, marking the transition from isolated attacks to systematic supply chain compromises. In April 2026, TeamPCP launched a coordinated campaign through a malicious @bitwarden/cli package targeting multiple distribution channels including Docker Hub, GitHub Actions, and VS Code extensions. The multi-stage payload employs advanced obfuscation, harvests credentials from cloud providers and developer workstations, exfiltrates data through encrypted HTTPS and GitHub repositories, and self-propagates by backdooring npm packages using stolen tokens. The malware implements GitHub's search API as a resilient command-and-control fallback mechanism and features anti-detection measures including Russian locale killswitches. This represents an evolution toward wormable propagation, infrastructure-level persistence, and dormant payloads that activate under specific conditions.

AI Analysis

· 2 months ago

Executive Summary

TeamPCP is a sophisticated threat actor that launched a coordinated campaign in April 2026, compromising the npm ecosystem through a malicious @bitwarden/cli package. This campaign marks an evolution in their tactics, techniques, and procedures (TTPs), employing advanced obfuscation, credential harvesting, and data exfiltration. The actor's goals and motivations are focused on supply chain compromise and infrastructure-level persistence.

Goals & Targeting

The TeamPCP threat actor's strategic objectives and targeting profile suggest a focus on supply chain compromise and infrastructure-level persistence. They target specific sectors and countries, seeking to gain access to sensitive data and systems, and have been observed to target multiple distribution channels including Docker Hub, GitHub Actions, and VS Code extensions. The actor's typical victims are likely to be organizations that rely on the npm ecosystem, and may include developers, cloud providers, and other entities that use these technologies.

Enhanced Description

The TeamPCP campaign has significant implications for the security of the npm ecosystem, as it demonstrates the potential for widespread compromise through supply chain attacks. The actor's use of advanced obfuscation techniques and anti-detection measures makes it difficult for defenders to detect and respond to these attacks, and the ability to self-propagate and employ resilient command-and-control mechanisms makes it challenging to eradicate the malware from infected systems.

Key Capabilities

  • Advanced obfuscation techniques
  • Credential harvesting
  • Data exfiltration
  • Self-propagation through backdooring npm packages
  • Resilient command-and-control mechanisms

MITRE ATT&CK Tactics

Initial Access
Execution
Persistence
Privilege Escalation
Defense Evasion
Credential Access
Discovery
Lateral Movement
Collection
Exfiltration
Command and Control

ATT&CK Techniques

T1587.001
T1195
T1588.001
T1589.001
T1059.003
T1055
T1566.001

Software / Tooling

Shai-Hulud
Payload
@bitwarden/cli

Campaigns & Victims

The TeamPCP campaign has been observed to be highly coordinated, with the actor employing a range of tactics and techniques to compromise their targets. The campaign has been ongoing since at least April 2026, and has targeted multiple distribution channels including Docker Hub, GitHub Actions, and VS Code extensions. The actor's typical victims are likely to be organizations that rely on the npm ecosystem, and may include developers, cloud providers, and other entities that use these technologies. Notable past operations include the compromise of the npm ecosystem through the Shai-Hulud worm in September 2025.

IOC Patterns

  • Spear-phishing with macro-laced Office documents
  • C2 over DNS using fast-flux
  • Staging infrastructure on bulletproof hosting
  • Malicious @bitwarden/cli packages
  • Backdoored npm packages

Recommended Actions

  • Implement robust security controls for npm packages and dependencies
  • Use secure protocols for data transmission and storage
  • Monitor for suspicious activity on GitHub and other development platforms
  • Implement anti-detection measures such as sandboxing and behavioral analysis
  • Conduct regular security audits and vulnerability assessments

Suggested Tags

APT
Supply Chain Compromise
Malware
Credential Harvesting
Data Exfiltration

Confidence Assessment

The confidence level in the available data is moderate to high, based on the observation of the actor's tactics and techniques. However, there are some information gaps, including the actor's primary motivation and goals, as well as the full extent of their capabilities and targeting profile. Further analysis and intelligence gathering are needed to fully understand the threat posed by TeamPCP.

ATT&CK Techniques

Credential Access
3 techniques
Execution
5 techniques
Impact
3 techniques
Initial Access
2 techniques
Persistence
4 techniques
Resource Development
8 techniques
Stealth
6 techniques

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

SHA256 3 URL 9 Domain 4 MD5 3 SHA1 1

References

  1. Aqua Security Trivy Compromise MAR 2026 — Aqua Security . (2026, March 21). Trivy ecosystem supply chain temporarily compromised. Retrieved July 1, 2026.
  2. Aqua Security Blog Trivy Compromise APR 2026 — Aqua Team. (2026, April 1). Update: Ongoing Investigation and Continued Remediation. Retrieved July 1, 2026.
  3. Google AI Threat Tracker MAY 2026 — Google Threat Intelligence Group. (2026, May 11). GTIG AI Threat Tracker: Adversaries Leverage AI for Vulnerability Exploitation, Augmented Operations, and Initial Access. Retrieved July 7, 2026.
  4. Wiz Trivy Compromise MAR 2026 — McCarthy, R. (2026, March 20). Trivy Compromised: Everything You Need to Know about the Latest Supply Chain Attack. Retrieved July 1, 2026.
  5. Trend Micro TeamPCP MAY 2026 — Santos, J. and Navato, J.R. (2026, May 13). Analyzing TeamPCP’s Supply Chain Attacks: Checkmarx KICS and elementary-data in CI/CD Credential Theft. Retrieved July 16, 2026.
  6. Palo Alto TeamPCP MAR 2026 — Unit 42. (2026, March 31). Weaponizing the Protectors: TeamPCP’s Multi-Stage Supply Chain Attack on Security Infrastructure. Retrieved July 1, 2026.
  7. Wiz TeamPCP Profile MAY 2026 — Wiz. (2026, May 20). TeamPCP. Retrieved July 16, 2026.

Intel Summary

36

Techniques

3

Tools

0

Campaigns

170

IOCs

0

Observed Data

12

Tactics

Tags

Supply Chain Attack
Backdoor / C2
APT
Supply Chain Compromise
Malware
Credential Harvesting
Data Exfiltration

Details

MITRE ID
G1056
Type
Apt
Confidence
50%
Added
May 3, 2026
STIX ID
intrusion-set--20f26558-e05d-46cf-8847-c2b5a83ee779
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.