TeamPCP is a financially motivated cybercriminal group that emerged in late 2025 and rapidly evolved into a significant threat targeting cloud-native environments and software supply chains. Unlike traditional ransomware groups that primarily rely on network intrusions and encryption, TeamPCP focuses on compromising software development ecosystems, cloud infrastructure, and developer environments to maximize downstream impact.
Public reporting has linked the group to multiple campaigns involving exposed cloud services, credential theft, malicious package distribution, CI/CD compromises, and software supply chain attacks. Throughout 2025 and 2026, TeamPCP expanded from exploiting misconfigured cloud infrastructure to targeting GitHub repositories, AI frameworks, developer tools, and open-source package ecosystems.
The group’s operations demonstrate a clear progression in capability—from opportunistic cloud exploitation to coordinated software supply chain attacks supported by underground infrastructure, affiliate recruitment, and custom malware families such as Shai-Hulud, Mini Shai-Hulud, and Miasma.
This report examines TeamPCP’s evolution, operational infrastructure, campaign history, associated malware, and the techniques that have enabled the group to compromise software supply chains at scale.

Figure: Public profile used by TeamPCP to establish its underground presence and advertise operations.
TeamPCP is a financially motivated cybercriminal group active since late 2025, primarily targeting cloud infrastructure, software development environments, CI/CD pipelines, and open-source ecosystems. The group has consistently demonstrated an interest in stealing developer credentials, compromising software repositories, and abusing trusted software distribution channels to maximize the reach of its campaigns.
The threat actor operates under several aliases, including PCPCat, ShellForce, CipherForce, and DeadCatx3. Google Threat Intelligence Group tracks the activity cluster as UNC6780.
Rather than focusing on traditional ransomware operations, TeamPCP has invested heavily in cloud exploitation, credential theft, software supply chain compromises, and underground collaboration. This operational model enables the group to compromise a relatively small number of high-value developer environments while potentially affecting thousands of downstream users.
Primary objectives include:
The precise geographic origin of TeamPCP remains unknown, and there is currently insufficient public evidence to attribute the group to a specific country with confidence.
TeamPCP first established a public presence in late 2025 through Telegram and underground cybercrime forums. During its initial phase, the group focused on building credibility within the underground ecosystem by advertising stolen data, recruiting affiliates, and launching communication platforms including the ShellForce Telegram channel and the CipherForce data leak site.
These activities laid the foundation for the group’s later transition into large-scale cloud and software supply chain operations.
Analyst Assessment
Rather than immediately conducting high-profile attacks, TeamPCP appears to have deliberately developed its underground reputation before expanding its operational capabilities. This phased approach is commonly observed among financially motivated threat actors seeking to establish trusted relationships with affiliates and access brokers.
Between late 2025 and mid-2026, TeamPCP significantly expanded both the scale and sophistication of its operations. Early campaigns focused on exploiting exposed cloud services and harvesting credentials. Over time, the group shifted toward software supply chain compromises targeting developer tools, AI frameworks, GitHub repositories, and package registries.
This progression illustrates a strategic transition from opportunistic exploitation to attacks capable of impacting large numbers of downstream organizations.
| Date | Campaign | Primary Target | Operational Significance |
| Sep 2025 | Cloud Infrastructure Attacks | Kubernetes, Docker, Redis, Ray | Initial cloud exploitation campaigns |
| Dec 2025 | Operation PCPcat | Next.js applications | Large-scale credential theft |
| Feb 2026 | Trivy GitHub Actions | CI/CD environments | Early software supply chain activity |
| Mar 2026 | LiteLLM Compromise | AI development ecosystem | Expansion into AI supply chains |
| Apr 2026 | Checkmarx Incident | Developer environments | Broader developer ecosystem targeting |
| May 2026 | Shai-Hulud Campaign | Software packages | Custom malware supporting supply chain attacks |

Figure: Timeline illustrating TeamPCP’s transition from cloud exploitation to software supply chain compromises.
TeamPCP’s operational evolution can be divided into four major phases:
The group’s earliest campaigns focused on identifying and exploiting exposed cloud services, including Docker APIs, Kubernetes clusters, Redis instances, and Ray dashboards. Automated scanning enabled rapid discovery of vulnerable internet-facing systems, while successful compromises were used to harvest credentials and establish persistence.
Following its initial cloud operations, TeamPCP launched Operation PCPcat, targeting vulnerable Next.js applications to steal environment files, API keys, cloud credentials, SSH keys, and other sensitive secrets. Compromised systems were subsequently incorporated into the group’s broader scanning infrastructure.
Building on access to developer environments, TeamPCP shifted toward compromising CI/CD pipelines, GitHub repositories, and open-source software packages. This strategy enabled the group to distribute malicious code through trusted software components rather than directly attacking end-user organizations.
Recent operations demonstrate continued investment in custom malware families, including Shai-Hulud, Mini Shai-Hulud, and Miasma, which support credential theft, software supply chain attacks, and multi-stage payload delivery.
Analyst Assessment
TeamPCP’s progression reflects a broader trend in financially motivated cybercrime, where attackers increasingly target software development ecosystems instead of individual organizations. By compromising trusted development infrastructure, threat actors can achieve significantly greater downstream impact while reducing the effort required to reach multiple victims.
TeamPCP’s earliest observed campaigns targeted exposed cloud-native services and internet-facing development environments. Rather than relying on phishing or traditional endpoint compromises, the group automated the discovery and exploitation of misconfigured cloud services, enabling large-scale attacks with minimal manual interaction.
Observed targets included exposed Docker APIs, Kubernetes clusters, Redis instances, Ray dashboards, and vulnerable React/Next.js applications. Public reporting indicates the group leveraged the React2Shell (CVE-2025-55182) vulnerability, where applicable, to achieve remote code execution and establish initial access to vulnerable servers.
Following successful exploitation, TeamPCP harvested credentials, deployed persistence mechanisms, and converted compromised systems into additional scanning nodes, allowing the campaign to scale rapidly.
This approach enabled TeamPCP to compromise cloud infrastructure while simultaneously expanding its attack surface through automated propagation.

Figure : High-level workflow of TeamPCP’s cloud infrastructure exploitation campaign.
Operation PCPcat marked TeamPCP’s transition from opportunistic cloud exploitation to organized credential theft.
Security researchers at Beelzebub observed the campaign after deploying a vulnerable Next.js honeypot designed to emulate real-world developer environments. Instead of immediately blocking the intrusion, researchers monitored the complete attack lifecycle, providing valuable insight into TeamPCP’s tooling and operational workflow.
Once access was established, the attackers searched for sensitive configuration files and extracted credentials from the compromised server, including:
.env filesCollected data was transmitted to the group’s command-and-control (C2) infrastructure for centralized processing.
Researchers also observed the deployment of FRP (Fast Reverse Proxy) and Gost, enabling persistent remote access and encrypted tunneling to compromised systems.
Analysis of the exposed C2 infrastructure suggested the campaign had already compromised more than 59,000 systems, demonstrating the highly automated nature of TeamPCP’s operations.
Analyst Assessment
Operation PCPcat illustrates TeamPCP’s emphasis on credential acquisition over immediate monetization. By harvesting developer and cloud credentials, the group significantly expanded opportunities for subsequent cloud intrusions and software supply chain attacks.

Figure: Observed execution flow of the Operation PCPcat credential theft campaign.
Following its cloud-focused campaigns, TeamPCP shifted its attention to software development environments and CI/CD infrastructure.
Rather than directly targeting end-user organizations, the group sought to compromise trusted components of the software development lifecycle, including GitHub repositories, GitHub Actions workflows, package registries, and developer pipelines. This strategy enabled malicious code to be distributed through legitimate software packages, significantly increasing the potential impact of each compromise.
Public reporting links TeamPCP to multiple campaigns affecting AI frameworks, developer tools, and open-source ecosystems, reflecting a deliberate focus on high-trust software distribution channels.
Observed objectives included:
Compared with earlier cloud attacks, these operations required greater planning and access but offered substantially broader downstream impact.

Figure: Generalized attack flow illustrating TeamPCP’s software supply chain compromise methodology.
Between early 2026 and mid-2026, TeamPCP rapidly expanded its software supply chain operations, progressing from isolated package compromises to coordinated attacks targeting developer ecosystems and technology companies.
| Date | Campaign | Target |
| February 2026 | Trivy GitHub Actions | CI/CD pipelines |
| March 2026 | LiteLLM | AI development ecosystem |
| April 2026 | Checkmarx | Developer environments |
| May 2026 | Shai-Hulud | Package registries |
| May–June 2026 | Multiple package compromises | Open-source ecosystems |
The frequency and diversity of these incidents indicate an increasing operational focus on trusted software distribution channels.

Figure : Chronological overview of TeamPCP’s software supply chain campaigns.
In May 2026, TeamPCP publicly claimed responsibility for compromising GitHub’s internal repositories through a malicious Visual Studio Code extension installed on an employee’s workstation.
GitHub subsequently confirmed unauthorized access to approximately 3,800 internal repositories, while stating there was no evidence that customer repositories or enterprise customer data had been compromised. Public reporting further indicated that the attackers later advertised access to the stolen repositories on underground forums.
Although some aspects of TeamPCP’s public claims remain independently unverified, the incident demonstrates the increasing value threat actors place on developer environments and trusted software development infrastructure.
Analyst Assessment
The reported GitHub incident represents a significant evolution in TeamPCP’s operational model. Rather than exploiting individual organizations, the group sought to compromise infrastructure capable of affecting software development at scale. This reflects a broader trend among financially motivated threat actors toward targeting the software supply chain as a force multiplier.

Figure: Reported attack path leading to unauthorized access to GitHub’s internal repositories.
Evidence collected from TeamPCP’s Telegram channel and underground forums indicates that the group targeted organizations across multiple regions. Advertisements published by the group referenced access to organizations in the United States, Canada, the United Kingdom, Australia, New Zealand, and several European countries, suggesting a broad operational scope rather than region-specific campaigns.
While these advertisements provide insight into the group’s intended victim profile, they should not be interpreted as independently verified victim counts.

Figure: Example of TeamPCP advertising access to organizations across multiple regions.

Figure: Countries referenced in TeamPCP’s underground advertisements.
TeamPCP maintains an interconnected ecosystem of communication platforms, underground forums, and leak infrastructure that supports its cybercriminal operations. These platforms serve distinct purposes, including affiliate recruitment, victim communication, data monetization, and operational coordination.
Beyond conducting attacks, TeamPCP actively participated in underground cybercrime communities to expand its influence and recruit collaborators.
Public forum posts indicate that the group organized a software supply chain competition, encouraging participants to conduct large-scale supply chain attacks using Shai-Hulud malware. The campaign reportedly offered a 1,000 USD (XMR) reward and was promoted alongside affiliate recruitment efforts targeting access brokers and experienced operators.
The group also claimed a leadership role within an underground forum, reflecting an effort to strengthen its position within the broader cybercriminal ecosystem.
Key Observations

Figure: Forum posts illustrating recruitment efforts and software supply chain competitions.
Public reporting suggests TeamPCP collaborates with multiple cybercriminal groups.
Observed communications indicate an operational relationship between TeamPCP and Xpl0itrs, with the groups appearing to cooperate during selected campaigns.

Figure: Public communication indicating operational collaboration.
Underground forum posts also announced a partnership between Vect Ransomware and TeamPCP, suggesting an intent to combine software supply chain access with ransomware operations.
Although public reporting confirms these partnership announcements, the full extent of operational collaboration remains unclear.

Figure: Underground forum announcement describing collaboration between TeamPCP and Vect.
TeamPCP employs a combination of legitimate administration tools, publicly available utilities, and custom malware to automate cloud exploitation, credential theft, persistence, and software supply chain attacks.
| Category | Tool / Malware | Purpose |
| Cloud Exploitation | Docker API, Kubernetes API, Redis, Ray Dashboard | Exploitation of exposed cloud services |
| Remote Access | FRP, Gost | Persistent remote access and encrypted tunneling |
| Credential Theft | TeamPCP Cloud Stealer | Theft of credentials and application secrets |
| Malware | CanisterWorm | Automated propagation |
| Malware | SANDCLOCK | Credential theft |
| Malware | Shai-Hulud | Software supply chain compromise |
| Malware | Mini Shai-Hulud | Lightweight variant of Shai-Hulud |
| Malware | Miasma / Hades | Multi-stage malware campaign |
The group’s tooling demonstrates a progression from exploiting exposed cloud infrastructure to developing custom malware capable of supporting large-scale software supply chain operations.
Within a relatively short period, TeamPCP has evolved from an emerging cybercriminal group into a significant threat targeting cloud-native environments and software development ecosystems. Its progression from opportunistic cloud exploitation to coordinated software supply chain attacks reflects a deliberate shift toward techniques capable of affecting large numbers of downstream organizations.
Rather than relying solely on traditional ransomware operations, TeamPCP combines credential theft, CI/CD compromise, malicious package distribution, and custom malware to maximize operational reach. The group’s use of underground forums, affiliate partnerships, and dedicated leak infrastructure further demonstrates a mature cybercriminal ecosystem supporting these activities.
As organizations continue to adopt cloud-native architectures and software supply chains become increasingly interconnected, attacks targeting developer environments are likely to remain an attractive avenue for financially motivated threat actors. Defending against these campaigns requires organizations to secure development pipelines, monitor cloud identities, protect software repositories, and continuously validate the integrity of third-party dependencies.
Contributors:
Siva Prasad Boddu

Rudra Pratap
