TeamPCP Partners With Vect Ransomware Group to Escalate Cross-Ecosystem Open Source Supply Chain Attacks — Threadlinqs Intelligence
As of 2026-07-27, TeamPCP Partners With Vect Ransomware Group to Escalate Cross-Ecosystem Open Source Supply Chain Attacks is a critical-severity supply chain threat attributed to TeamPCP (Russia), tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 53 indicators of compromise.
Threat ID: TL-2026-0288 · Severity: CRITICAL · Status: ACTIVE · Category: SUPPLY_CHAIN
Updated: 2026-07-27 · revalidated 1× · latest source
Attribution: TeamPCP · Russia · FINANCIAL
Threat actor TeamPCP (a.k.a. PCPcat, ShellForce, DeadCatx3) has partnered with emerging ransomware-as-a-service operation Vect to chain open source supply chain compromises into ransomware campaigns.
TeamPCP (also tracked as PCPcat, ShellForce, DeadCatx3, PersyPCP, CipherForce) is a cloud-native cybercrime threat cluster that has executed one of the most consequential supply chain campaigns of 2026. Active since at least July 2025 via their Telegram channel, the group compromised over 60,000 servers globally before pivoting to targeted supply chain attacks against open source security tooling.
The campaign began on February 28, 2026 when TeamPCP exploited a misconfigured pull_request_target workflow in Aqua Security's Trivy repository to steal a privileged Personal Access Token (PAT). After an incomplete credential rotation on March 1, the attacker retained residual access through the compromised aqua-bot and Argon-DevOps-Mgt service accounts.
On March 19, TeamPCP leveraged this access to publish a malicious Trivy binary v0.69.4 and force-push malicious commits to 75 of 76 trivy-action tags and all 7 setup-trivy tags, transforming pinned CI/CD tags into payload delivery channels. The embedded infostealer harvested credentials from Runner.Worker process memory, including GitHub PATs, AWS IMDS credentials, SSH keys, cloud tokens, Kubernetes secrets, and CI/CD environment variables. Exfiltration used a hybrid AES-256-CBC + RSA-4096 encryption scheme, with data sent as tpcp.tar.gz to typosquatted domain scan.aquasecurtiy[.]org (45.148.10.212).
By March 20, stolen npm tokens fueled a self-propagating worm (CanisterWorm) that autonomously enumerated packages owned by compromised token holders and republished malicious versions. Over 50 packages were infected across @EmilGroup (28 packages), @opengov (16 packages), @teale.io/eslint-config, @airtm/uuid-base32, and @pypestream/floating-ui-dom. The worm used ICP (Internet Computer Protocol) canister tdtqy-oyaaa-aaaae-af2dq-cai.raw.icp0.io as a decentralized, censorship-resistant C2 dead-drop, and installed pgmon.service persistence.
On March 22, TeamPCP deployed a geopolitically-targeted Kubernetes wiper payload. Iranian systems (detected via Asia/Tehran timezone and fa_IR locale) received the destructive host-provisioner-iran DaemonSet that recursively deleted host filesystems and forced reboots. Non-Iranian systems received the CanisterWorm backdoor instead. The same day, all 44 Aqua Security internal repositories were defaced, and malicious Docker Hub images (trivy:0.69.5, 0.69.6) were published using stolen Aqua credentials.
On March 23, the campaign expanded to Checkmarx: 35 KICS GitHub Action tags were hijacked via compromised cx-plugins-releases service account, ast-github-action v2.3.28 was backdoored, and malicious OpenVSX extensions checkmarx.ast-results v2.53.0 and cx-dev-assist v1.7.0 were published. Exfiltration shifted to checkmarx[.]zone (83.142.209.11).
On March 24, TeamPCP compromised LiteLLM on PyPI, a package with 95 million monthly downloads present in 36% of cloud environments. Malicious versions 1.82.7 and 1.82.8 were published using credentials stolen in the Trivy incident. Version 1.82.7 injected a base64-encoded payload into litellm/proxy/proxy_server.py; version 1.82.8 added litellm_init.pth, a Python startup hook that executes malware on any Python invocation system-wide. The three-stage payload includes a credential harvester (332 lines targeting 50+ sensitive paths), a Kubernetes lateral movement toolkit deploying privileged node-setup-* pods, and a persistent systemd backdoor (sysmon.service) polling checkmarx.zone/raw every 50 minutes. Data was exfiltrated to models.litellm[.]cloud. PyPI quarantined both versions by 11:25 UTC.
On March 26, Vect ransomware group announced on BreachForums a formal partnership with TeamPCP, stating they would chain supply chain compromises into devastating follow-on ransomware campaigns. Vect is an emerging RaaS operation launched in December 2025, written in C++ using ChaCha20-Poly1305 AEAD encryption with intermittent encryption for speed. It targets Windows, Linux, and VMware ESXi, uses Monero for payments, TOX
Weaknesses (CWE)
CWE-506, CWE-829, CWE-494, CWE-502
Target sectors: technology, software-development, cloud-infrastructure, government, financial, healthcare, education, manufacturing, critical-infrastructure
Target regions: Global, North America, Europe, South America, Africa, Middle East
Detections & IOCs
As of 2026-07-27, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 53 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
SUPPLY_CHAIN, CRITICAL, threat intelligence, cybersecurity, CVE-2025-55182, T1593, T1583, T1583, T1587, T1608, T1195, T1195, T1078, T1059, T1204