TeamPCP Supply Chain Campaign Enters Monetization Phase, Halting New Compromises

A sprawling and sophisticated supply chain attack executed by the threat group TeamPCP has entered a new phase, according to security researchers. As of June 8, 2026, the campaign, which began in March by compromising widely used open-source security tools, has seen its first 48-hour pause in new compromises. The SANS Institute reports this shift in tempo suggests the attackers may be moving from expansion to monetizing the vast amounts of credentials and cloud access they have already stolen.

The attack, tracked as CVE-2026-33634, was initiated on March 19, 2026, when TeamPCP compromised a service account for Aqua Security’s Trivy, a popular vulnerability scanner. According to reports from Palo Alto Networks’ Unit 42, the attackers then force-pushed malicious code to 76 different version tags in the Trivy project’s GitHub repository. This action turned the trusted security tool into a credential-stealing weapon that was then automatically executed by thousands of businesses within their software development pipelines.

In our experience, incidents like the TeamPCP campaign represent a critical shift in operational risk that many business leaders are unprepared for. This is no longer just an IT issue; it's a core business continuity threat. When the very tools purchased to mitigate risk become the attack vector, it demonstrates a potential vulnerability in the broader security and procurement strategy. For small and mid-sized companies, the reliance on third-party and open-source tools is a double-edged sword: it enables rapid growth but also introduces complex, often invisible, supply chain vulnerabilities. The speed of this attack, moving from compromise to widespread data exfiltration in hours, means that reactive security measures are insufficient. Businesses must proactively understand and quantify these threats as part of their overall financial planning. This is precisely the type of scenario where our financial risk management services become essential. We help clients map these operational vulnerabilities to their financial impact and build resilient strategies to protect their bottom line. To understand your company's exposure, contact C&S Finance Group LLC at csfinancegroup.com.

The initial compromise of Trivy was just the beginning of a cascading attack that spread across multiple software ecosystems. The SANS Institute confirmed the campaign quickly expanded to infect npm packages, Docker Hub images, Checkmarx’s KICS security tool, and the popular LiteLLM Python package on PyPI. The scope of victims is extensive and includes high-profile organizations such as Bitwarden, TanStack, Mistral AI, and Microsoft. One security researcher's timeline noted that approximately 3,800 of GitHub's own internal software repositories were also impacted.

TeamPCP, also known by aliases such as PCPcat and ShellForce, has been active since at least September 2025 and functions as a hybrid threat actor. It operates as an access broker, data-leak extortion crew, and cloud exploitation group, with known partnerships with other notorious entities like the LAPSUS$ group and Vect Ransomware operators. According to an analysis by security firm Oligo, once the malicious code harvested credentials, TeamPCP’s operators moved swiftly. Within 24 hours, they began methodical reconnaissance across victims' Amazon Web Services (AWS) environments, enumerating everything from user roles and virtual servers to databases and S3 storage buckets. The attackers operated from VPN exit nodes and virtual private servers in a high-tempo campaign designed for rapid value extraction rather than long-term stealth.

The campaign is particularly notable for its strategy of targeting security infrastructure itself. By poisoning tools like Trivy and KICS, TeamPCP exploited the implicit trust that organizations place in the software designed to protect them. As a SANS Institute white paper on the incident titled it, this is a case of "When the Security Scanner Became the Weapon." This approach collapses the window between compromise and exploitation, dramatically increasing the blast radius from a single malicious software package.

As of early June, the operational tempo has changed significantly. The SANS Internet Storm Center diary entry for June 8 noted the first 48-hour period without any newly compromised software packages since the campaign began. This pause coincides with intelligence suggesting the attackers are beginning to monetize their efforts. Researchers are actively monitoring for the deployment of Vect ransomware using credentials distributed by TeamPCP affiliates. Meanwhile, the broader business community awaits public statements from potentially impacted companies like AstraZeneca and a formal attribution report from cybersecurity firm Mandiant, which has been engaged to investigate the LiteLLM compromise. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added the vulnerability to its Known Exploited Vulnerabilities (KEV) catalog but has not yet issued a standalone emergency directive.

Moving forward, security teams and business leaders will be watching closely to see if the pause in new attacks holds or if TeamPCP resumes its campaign of compromising software repositories. The primary focus now shifts to the consequences of the breaches, including potential ransomware attacks, data leaks on illicit forums, and the long-term impact of stolen cloud credentials. The pending reports from investigators will be critical in providing a full accounting of the attack's scope and informing defensive strategies against future supply chain compromises.