TeamPCP kicks off Supply-Chain March Madness

There are some other discussions on this group, but I just think their attack chain is very interesting. Over the course of 5 days, this group was able to make a pretty big impact.

From SANS:

Day 1 (Mar 19): Trivy binary, GitHub Actions, and Docker images are compromised. Credential stealers harvest secrets from CI/CD runner memory.

Day 2 (Mar 20): Stolen npm tokens feed a self-propagating worm (CanisterWorm) that infects 66+ npm packages across multiple organizations.

Day 4 (Mar 22): Malicious Docker images are pushed. 44 Aqua Security repositories are defaced. An Iran-targeted wiper component is discovered.

Day 5 (Mar 23): Checkmarx KICS and AST GitHub Actions are hijacked. Malicious VS Code extensions are published.

Day 6 (Mar 24): LiteLLM is compromised on PyPI using credentials stolen from a Trivy scan—completing the chain from security scanner to AI infrastructure.

Another interesting thing is the Day 2 attack with CanisterWorm had a Iran-locale focused wiper. The Forbes article interviewed the now “leader” of the group who says they are a bunch of teenagers but actual attribution and motivation doesn’t seem to be clear yet. I’d guess that they are financially motivated based on the SOCRadar article:

The Telnyx Python SDK was compromised on PyPI at 03:51 UTC on March 27, confirming active expansion into new targets using the same WAV steganography delivery pattern.

On April 2–3, CERT-EU officially attributed the breach of the European Commission’s AWS environment to TeamPCP. Approximately 92 GB of compressed data was stolen from 42 internal departments and 29 EU entities. ShinyHunters subsequently published approximately 340 GB (uncompressed) of this data on their dark web leak site, marking the first confirmed nation-state-tier institutional victim of the campaign.

A leadership transition was announced on Telegram, with the original operator DMT stepping down and a new leader operating under the alias T00001B taking control. The new leadership confirmed the operation would continue and that new partners had already joined.

The Vect Ransomware Group announced a formal partnership with TeamPCP on BreachForums, stating intent to deploy ransomware across every organization affected by the Trivy and LiteLLM compromises.

But the political targeting really stands out for me here. Have we ever had an instance of a ransomware/TA group that is furthering western nation state political objectives while also collecting money from selling stolen data? We’ve seen this behavior for decades now in the Russian Commonwealth states and from Iranian and occasionally Chinese threat actors, but I cannot recall a time where US political actions were assisted like this by crimeware group.

I am not suggesting that TeamPCP has any US government affiliation.

https://socradar.io/blog/dark-web-profile-teampcp/

https://www.forbes.com/sites/thomasbrewster/2026/03/26/hackers-launch-devastating-attacks-on-ai-devs/

1 Like