Also known as PCPCat, ShellForce, DeadCatx3, SHADOW-WATER-058, UNC6780
Tracked asG1056
TeamPCP is a financially-motivated, cloud-native threat group that has been active since at least September 2025. Initially focused on ransomware and cryptocurrency theft, TeamPCP shifted in early 2026 to systematic, worm-driven credential theft and software supply chain attacks targeting Continuous Integration and Continuous Delivery (CI/CD) workflows. TeamPCP has monetized access through extortion and through partnerships with ransomware actors including Vect and CipherForce.
TeamPCP is a hacking group known for widespread supply-chain attacks over the past year
The malicious activity is believed to have been carried out by a loose-knit collective of threat actors who all frequent the same hacking forums, Discord servers, and Telegram channels
Rather than a cohesive group, members operate through shared online spaces
Activity timeline
Facts
Targeted open-source software and developer platforms to steal credentials, authentication secrets, and source code
Malicious code distributed by TeamPCP has potentially compromised over a thousand organizations worldwide
Enabled the theft of half a million credentials and the exfiltration of at least 300GB of data
Global remediation costs estimated to be hundreds of millions of dollars
Attribution assessment
Facts
TeamPCP-linked infrastructure traced back to 2020 and possibly tied to activity previously tracked as TA-NATALSTATUS and IronErn through overlapping domains, malware deployment paths, staging techniques, and backend infrastructure, though continuity cannot be determined with 100% certainty
Operational playbook
Facts
Worked by stealing publishing credentials from trusted open-source projects and pushing poisoned versions through projects' own release channels
Used compromised credentials from one project to attack the next
Operated across five distribution ecosystems: GitHub Actions, Docker Hub, npm, PyPI, and OpenVSX
Initial access and identity targets
Facts
Stole publishing credentials from open-source projects
Capabilities and evasion
Facts
Potentially compromised more than 1,000 organizations globally
Enabled theft of more than 500,000 credentials
Exfiltrated at least 300 gigabytes of data according to AFP (CloudSEK reported 153GB archive from attackers' own exfiltrated data)
Infrastructure patterns
Facts
Operated through hacking forums, Discord servers, and Telegram channels
Communication and pressure channels
Facts
Used Telegram for coordination
Maintained reused aliases and accounts across platforms
Observed targeting
Facts
Targeted systems used by government, academic, and private-sector organizations
Named victims
Organizations
Trivy (open-source security scanner)
Checkmarx KICS (open-source security scanner)
LiteLLM (AI gateway)
keyv (npm package)
cacheable (npm package)
Defender guidance
Facts
Treat exfiltrated data and credentials as persistent risk
Rotate all CI/CD secrets, publishing tokens, and cloud credentials accessible during exposure windows
Search organizations for tpcp-docs and docs-tpcp repositories
Pin all GitHub Actions workflows to verified commit SHA hashes rather than floating version tags
Pin dependencies to verified versions
Reported detail
Facts
Two Western Australian men were charged in August 2026 as principal participants in TeamPCP, a cybercrime group responsible for compromising open-source projects Trivy, Checkmarx KICS, and LiteLLM in March 2026
TeamPCP stole publishing credentials from trusted projects and injected malicious code into subsequent releases across multiple package repositories, compromising over 1,000 organizations globally
The group exfiltrated over 500,000 credentials and at least 300 gigabytes of data, with 16 confirmed victims published on their leak site
TeamPCP-linked infrastructure dates back to 2020 and may be connected to previously tracked groups TA-NATALSTATUS and IronErn, though the relationship remains uncertain
The group maintained persistence through stolen CI/CD credentials and open-sourced a worm framework, with continued activity detected in August 2026
Activity timeline
A dated ledger of actor-claimed victims, campaigns, indicators, identity mappings, relationships, and CVE links. Each date states what it measures. For extensive leak-site histories, victim entries are limited to the 100 most recent distinct listings.
Cataloged
Indicator1 indicator cataloged
Types: tool.
First observed
CVECVE-2026-58231 linked to this actor
Alleged TeamPCP Hackers Charged in Australia Over Major Supply Chain Attacks
Cataloged
IdentityAlias: PCPCat
Reviewed identity mapping approved on this date.
Cataloged
IdentityAlias: ShellForce
Reviewed identity mapping approved on this date.
Cataloged
IdentityAlias: DeadCatx3
Reviewed identity mapping approved on this date.
Cataloged
IdentityAlias: SHADOW-WATER-058
Reviewed identity mapping approved on this date.
Cataloged
IdentityAlias: UNC6780
Reviewed identity mapping approved on this date.
Cataloged
IdentityTracking identifier: G1056
Reviewed identity mapping approved on this date.
Identity and attribution
Exact names and tracking identifiers resolve to this canonical profile. Rebrands, affiliations, and overlapping clusters remain separate confidence-rated relationships.
Name map
TeamPCPCanonical Name
DeadCatx3Alias
PCPCatAlias
SHADOW-WATER-058Alias
ShellForceAlias
UNC6780Alias
G1056Tracking Id
Loading CVEs, techniques, indicators, malware, victims, and activity...