FlagThis
← Threat Actors
/
Russia/CIS
/
TeamPCP
DOSSIER // TEAMPCP
TeamPCP
ACTIVE CAMPAIGN TRACKED
⚠ Critical Threat
Russia/CIS
Primary Aliases:
Altered Spider
UNC6780
CanisterWorm
CipherForce
🔍 Adversary Rosetta Stone (11) ▾
📋 Copy All
Sponsor / State Affiliation
criminal organization
Primary Motivation
financial (extortion, ransomware, and sale of exfiltrated intellectual property)
Active Timeline
Unknown – Present
Confidence Rating
95% (Grounded)
Shai-Hulud / Mini Shai-Hulud, Trivy/LiteLLM Cascade, Grafana Labs GitHub Breach
📥 Export ATT&CK Layer (.json)
🔔 RSS Feed
🏛️ CISA Advisories ↗
📋 Copy Dossier Briefing
⚔️ Weaponized CVE Matrix
(0)
No specific weaponized CVEs currently mapped in the public baseline.
🎯 Target Sectors & Focus
Software Development Ecosystems (npm, PyPI, Docker Hub, Packagist)
AI/ML Tooling (e.g., LiteLLM, Mistral AI, Guardrails AI)
Cybersecurity Tooling (e.g., Trivy, Checkmarx)
Cloud-Native Infrastructure (Kubernetes, Docker APIs, Ray dashboards, Redis)
CI/CD Pipelines and GitHub Repositories
🛡️ MITRE ATT&CK® Attack Lifecycle
(9 TTPs)
📥 Download Navigator JSON
All Stages
9
Initial Access
1
Persistence & Privilege Escalation
1
Credential Access & Discovery
2
Command & Control
2
Operational Techniques
3
Initial Access
1
T1566
Self-propagating supply chain worms (Shai-Hulud/Mini Shai-Hulud)
↗
Persistence & Privilege Escalation
1
T1547
OIDC token extraction from GitHub Actions runner memory to forge SLSA provenance
↗
Credential Access & Discovery
2
T1003
IDE extension abuse (VS Code extensions) for credential theft
↗
T1003
Credential stealing via SANDCLOCK and FIRESCALE malware
↗
Command & Control
2
T1071
Partnership with Ransomware-as-a-Service (RaaS) operators (Vect)
↗
T1071
AI-driven payload generation and prompt injection to evade scanners
↗
Operational Techniques
3
T1000
GitHub Actions cache poisoning
↗
T1000
Abuse of exposed cloud-native APIs (Docker, Ray, Redis)
↗
T1000
Git tag manipulation and workflow injection
↗
📰 Verified Campaigns & Intelligence Archive
🔔 Subscribe to Alerts
[DEEP DIVE]
TeamPCP Supply-Chain Compromise of Trivy, Checkmarx KICS, and LiteLLM
Attacks and Vulnerabilities
2026-09-01
[DEEP DIVE]
TeamPCP: Open-Source Software Supply Chain Campaign
Attacks and Vulnerabilities
2026-08-29
[DEEP DIVE]
The Vect and TeamPCP Alliance: Industrialized Supply Chain and Cloud-Native Ransomware Orchestration
Strategies and Tactics
2026-07-04
[DEEP DIVE]
Shai-Hulud: npm and PyPI Cross-Ecosystem Worm
Attacks and Vulnerabilities
2026-08-29
[DEEP DIVE]
LiteLLM and PyTorch Lightning Supply Chain Attack
Attacks and Vulnerabilities
2026-08-13
[DEEP DIVE]
Npm, Microsoft, and AI Coding Agents: Shai Hulud and Miasma Worm Supply Chain Campaigns
New Products/Tools
2026-07-07
[DEEP DIVE]
Multi-Vector Supply Chain Campaign: Mastra AI, GitHub Actions, and Arch Linux AUR Compromise
Attacks and Vulnerabilities
2026-07-02
[DEEP DIVE]
GitHub Investigating TeamPCP Claimed Breach of ~4,000 Internal Repositories
Attacks and Vulnerabilities
Adversary Rosetta Stone // TeamPCP
×
🦅 CrowdStrike Monikers
Altered Spider
📋
🔍 Mandiant / Google Threat Intel
UNC6780
📋
🛡️ Other Industry Tracking Codes
CanisterWorm
📋
CipherForce
📋
DeadCatx3
📋
G1056
📋
PCPcat
📋
Persy_PCP
📋
SHADOW-WATER-058
📋
ShellForce
📋
storm_2999
📋
Copied to clipboard
SHARE INTELLIGENCE WIRE
×
Story Title
X / Twitter
Bluesky
LinkedIn
Copy Link
LINK COPIED TO CLIPBOARD