TeamPCP Supply Chain Campaign: LiteLLM PyPI Compromise, CanisterWorm npm Propagation, and Multi-Ecosystem Attack (CVE-2026-33634) — Threadlinqs Intelligence
As of 2026-05-30, TeamPCP Supply Chain Campaign: LiteLLM PyPI Compromise, CanisterWorm npm Propagation, and Multi-Ecosystem Attack (CVE-2026-33634) is a critical-severity supply chain threat attributed to TeamPCP (N/A), tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 30 indicators of compromise.
Threat ID: TL-2026-0279 · Severity: CRITICAL · CVSS: 9.8 · Status: MONITORING · Category: SUPPLY_CHAIN
Attribution: TeamPCP · N/A · DESTRUCTION
A coordinated five-day supply chain campaign by TeamPCP spanning PyPI, npm, Docker Hub, GitHub Actions, and OpenVSX. Beginning with the compromise of Aqua Security's Trivy scanner on March 19, 2026,
TeamPCP conducted one of the most consequential supply chain campaigns of 2026, compromising five software ecosystems over five days (March 19-24, 2026). The campaign represents a significant escalation in supply chain attack sophistication, combining credential theft, worm propagation, Kubernetes cluster compromise, and targeted destruction.
INITIAL VECTOR — TRIVY COMPROMISE (March 19):
The attack began when TeamPCP exploited a compromised "Argon-DevOps-Mgt" service account token that bridged two Aqua Security GitHub organizations. At 17:43:37 UTC on March 19, the attackers force-pushed malicious commits to 76 of 77 aquasecurity/trivy-action tags and all 7 aquasecurity/setup-trivy tags. Simultaneously, Trivy v0.69.4 was published with embedded credential-stealing binaries across all platform targets (Linux, Windows, macOS, FreeBSD, ARM). The malicious Trivy binary beaconed to scan.aquasecurtiy[.]org (typosquat resolving to 45.148.10.212) and the ICP canister tdtqy-oyaaa-aaaae-af2dq-cai.raw.icp0[.]io — the first publicly documented abuse of an Internet Computer Protocol canister as a C2 dead drop resolver.
NPM CANISTERWORM PROPAGATION (March 20-22):
Using credentials stolen from CI/CD environments via the Trivy compromise, TeamPCP deployed CanisterWorm — a self-propagating npm worm that spread across 141 malicious package artifacts spanning 66+ unique packages. Major affected scopes included @EmilGroup (28 packages), @opengov (16 packages), @teale.io, @airtm, @virtahealth, and @pypestream. The worm used the ICP canister as its command-and-control resolver and propagated by publishing new malicious versions of packages using stolen npm automation tokens.
KUBERNETES PAYLOADS AND GITHUB DEFACEMENT (March 22):
On March 22, between 20:31:07 and 20:32:26 UTC, TeamPCP executed a scripted defacement of all 44 repositories in the aquasec-com GitHub organization, renaming them with "tpcp-docs-" prefixes and setting descriptions to "TeamPCP Owns Aqua Security." Concurrently, Kubernetes-specific payloads were deployed that created privileged DaemonSets across cluster nodes. On Iranian systems, the "host-provisioner-iran" DaemonSet mounted the host root filesystem and ran a container named "kamikaze" that executed rm -rf / --no-preserve-root. Non-Iranian targets received the "host-provisioner-std" DaemonSet with persistent backdoor installation.
CHECKMARX AND OPENVSX COMPROMISE (March 23):
The campaign expanded to Checkmarx GitHub Actions (kics-github-action v1.1, ast-github-action v2.3.28) and OpenVSX extensions (ast-results 2.53.0, cx-dev-assist 1.7.0), using the same credential theft methodology from the initial Trivy breach.
LITELLM PYPI COMPROMISE (March 24):
The final escalation targeted LiteLLM, a widely-used AI proxy library present in 36% of cloud environments. At approximately 8:30 UTC, versions 1.82.7 and 1.82.8 were published to PyPI using credentials stolen via compromised Trivy in LiteLLM's CI/CD pipeline. Version 1.82.7 injected a double base64-encoded payload into litellm/proxy/proxy_server.py, executing when litellm --proxy was invoked. Version 1.82.8 added litellm_init.pth, abusing Python's .pth file mechanism to execute the payload on any Python interpreter startup system-wide. Both versions quarantined by PyPI at 11:25 UTC.
PAYLOAD KILL CHAIN:
1. COLLECT: Sweeps environment variables, SSH keys, cloud credentials (AWS/GCP/Azure), Kubernetes configs and service account tokens, Docker configs, CI/CD secrets, database credentials, cryptocurrency wallets, .env files, .npmrc tokens, and shell history.
2. ENCRYPT: Data encrypted with AES-256 session key; session key encrypted with embedded RSA-4096 public key. Packaged as tpcp.tar.gz.
3. EXFILTRATE: Primary endpoint models.litellm[.]cloud (HTTP header X-Filename: tpcp.tar.gz). Fallback creates public tpcp-docs GitHub repository if GitHub token available.
4. PERSIST: Drops ~/.config/sysmon/sysmon.py and installs ~/.config/systemd/user/sysmon.service polling every 50 minut
Weaknesses (CWE)
CWE-506, CWE-502, CWE-798, CWE-912
Target sectors: technology, financial, government, healthcare, enterprise, cloud-infrastructure, devops, artificial-intelligence
Target regions: Global, North America, Europe, Middle East
Detections & IOCs
As of 2026-07-20, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 30 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
SUPPLY_CHAIN, CRITICAL, threat intelligence, cybersecurity, CVE-2026-33634, T1195, T1195, T1059, T1059, T1204, T1543, T1546, T1547, T1611, T1078