← Back to all threat actors

TeamPCP

Also known as PCPCat, ShellForce, DeadCatx3, SHADOW-WATER-058, UNC6780
Tracked as G1056

TeamPCP is a financially-motivated, cloud-native threat group that has been active since at least September 2025. Initially focused on ransomware and cryptocurrency theft, TeamPCP shifted in early 2026 to systematic, worm-driven credential theft and software supply chain attacks targeting Continuous Integration and Continuous Delivery (CI/CD) workflows. TeamPCP has monetized access through extortion and through partnerships with ransomware actors including Vect and CipherForce.

How we source and review actor profiles
Motivation
ransomware
Status
Active

Threat intelligence assessment

At a glance

Facts

  • TeamPCP is a hacking group known for widespread supply-chain attacks over the past year
  • The malicious activity is believed to have been carried out by a loose-knit collective of threat actors who all frequent the same hacking forums, Discord servers, and Telegram channels
  • Rather than a cohesive group, members operate through shared online spaces

Activity timeline

Facts

  • Targeted open-source software and developer platforms to steal credentials, authentication secrets, and source code
  • Malicious code distributed by TeamPCP has potentially compromised over a thousand organizations worldwide
  • Enabled the theft of half a million credentials and the exfiltration of at least 300GB of data
  • Global remediation costs estimated to be hundreds of millions of dollars

Attribution assessment

Facts

  • TeamPCP-linked infrastructure traced back to 2020 and possibly tied to activity previously tracked as TA-NATALSTATUS and IronErn through overlapping domains, malware deployment paths, staging techniques, and backend infrastructure, though continuity cannot be determined with 100% certainty

Operational playbook

Facts

  • Worked by stealing publishing credentials from trusted open-source projects and pushing poisoned versions through projects' own release channels
  • Used compromised credentials from one project to attack the next
  • Operated across five distribution ecosystems: GitHub Actions, Docker Hub, npm, PyPI, and OpenVSX

Initial access and identity targets

Facts

  • Stole publishing credentials from open-source projects

Capabilities and evasion

Facts

  • Potentially compromised more than 1,000 organizations globally
  • Enabled theft of more than 500,000 credentials
  • Exfiltrated at least 300 gigabytes of data according to AFP (CloudSEK reported 153GB archive from attackers' own exfiltrated data)

Infrastructure patterns

Facts

  • Operated through hacking forums, Discord servers, and Telegram channels

Communication and pressure channels

Facts

  • Used Telegram for coordination
  • Maintained reused aliases and accounts across platforms

Observed targeting

Facts

  • Targeted systems used by government, academic, and private-sector organizations

Named victims

Organizations

  • Trivy (open-source security scanner)
  • Checkmarx KICS (open-source security scanner)
  • LiteLLM (AI gateway)
  • keyv (npm package)
  • cacheable (npm package)

Defender guidance

Facts

  • Treat exfiltrated data and credentials as persistent risk
  • Rotate all CI/CD secrets, publishing tokens, and cloud credentials accessible during exposure windows
  • Search organizations for tpcp-docs and docs-tpcp repositories
  • Pin all GitHub Actions workflows to verified commit SHA hashes rather than floating version tags
  • Pin dependencies to verified versions

Reported detail

Facts

  • Two Western Australian men were charged in August 2026 as principal participants in TeamPCP, a cybercrime group responsible for compromising open-source projects Trivy, Checkmarx KICS, and LiteLLM in March 2026
  • TeamPCP stole publishing credentials from trusted projects and injected malicious code into subsequent releases across multiple package repositories, compromising over 1,000 organizations globally
  • The group exfiltrated over 500,000 credentials and at least 300 gigabytes of data, with 16 confirmed victims published on their leak site
  • TeamPCP-linked infrastructure dates back to 2020 and may be connected to previously tracked groups TA-NATALSTATUS and IronErn, though the relationship remains uncertain
  • The group maintained persistence through stolen CI/CD credentials and open-sourced a worm framework, with continued activity detected in August 2026

Activity timeline

A dated ledger of actor-claimed victims, campaigns, indicators, identity mappings, relationships, and CVE links. Each date states what it measures. For extensive leak-site histories, victim entries are limited to the 100 most recent distinct listings.

Cataloged
Indicator1 indicator cataloged

Types: tool.

First observed
CVECVE-2026-58231 linked to this actor

Alleged TeamPCP Hackers Charged in Australia Over Major Supply Chain Attacks

Cataloged
IdentityAlias: PCPCat

Reviewed identity mapping approved on this date.

Cataloged
IdentityAlias: ShellForce

Reviewed identity mapping approved on this date.

Cataloged
IdentityAlias: DeadCatx3

Reviewed identity mapping approved on this date.

Cataloged
IdentityAlias: SHADOW-WATER-058

Reviewed identity mapping approved on this date.

Cataloged
IdentityAlias: UNC6780

Reviewed identity mapping approved on this date.

Cataloged
IdentityTracking identifier: G1056

Reviewed identity mapping approved on this date.

Identity and attribution

Exact names and tracking identifiers resolve to this canonical profile. Rebrands, affiliations, and overlapping clusters remain separate confidence-rated relationships.

Name map

TeamPCPCanonical Name
DeadCatx3Alias
PCPCatAlias
SHADOW-WATER-058Alias
ShellForceAlias
UNC6780Alias
G1056Tracking Id

Loading CVEs, techniques, indicators, malware, victims, and activity...