Key Takeaways
- TeamPCP’s infrastructure and tactics connect its recent supply chain attacks to campaigns targeting exposed servers as early as April 2020.
- The operation expanded from cryptomining and botnet building into broad software supply chain compromise across ecosystems like GitHub Actions and Docker Hub.
- Compromises involving Aqua Security’s Trivy, Checkmarx KICS, and LiteLLM show how one trusted development tool can create cascading exposure.
Oligo Security has connected TeamPCP’s recent software supply chain campaign to a longer record of attacks against internet-facing infrastructure, extending the threat actor’s apparent operational history back to April 2020.
Rather than a new group that abruptly appeared in late 2025, TeamPCP appears to be the latest identity associated with an established operational ecosystem. Oligo Security researchers reported the connection rests on overlapping domains, malware deployment paths, staging techniques, backend infrastructure, and operational tradecraft.
Several campaigns form that bridge. ShadowRay 2.0, also known as IronErn, hijacked artificial intelligence infrastructure during the second half of 2025 and turned compromised systems into a self-propagating botnet. TA-NATALSTATUS, observed during the same period, targeted exposed Redis servers and installed cryptocurrency miners.
Researchers assess TA-NATALSTATUS as an evolution of Redis-targeting activity detailed by Trend Micro in April 2020. That earlier activity suggests operators associated with TeamPCP spent years learning how to identify and exploit exposed Redis, Ray, Docker, and React environments before shifting toward developer ecosystems.
Automated scanning and wormable exploitation produce large pools of compromised servers, while stolen repository or automation tokens provide access to software trusted by downstream users. Activity disclosed toward the end of 2025 highlighted this transition, exploiting security flaws in React Server Components (RSC) and Next.js to facilitate the extraction of credentials.
The campaign subsequently pivoted across GitHub Actions, npm, PyPI, Docker Hub, VS Code Marketplace, and Jenkins. Token theft and GitHub Actions abuse gave TeamPCP a route to poison open-source projects and reach developer systems through legitimate distribution channels.
A 2026 case study involving Aqua Security’s Trivy illustrates how a single trusted tool can amplify downstream exposure. The compromise reportedly cascaded into Checkmarx KICS and LiteLLM, extending exposure beyond the original project. Trend Micro and SANS reporting described at least seven confirmed waves in the broader campaign. SANS reported that the Trivy compromise reached 4 additional ecosystems and was tracked as CVE-2026-33634 with a CVSS score of 9.4.
For enterprise security teams, the practical response extends beyond patching individual vulnerabilities. Organizations can reduce exposure by restricting public access to Redis, Ray, Docker, and Kubernetes services, rotating automation tokens, limiting GitHub Actions permissions, reviewing maintainer accounts, and verifying build provenance. TeamPCP’s trajectory shows why infrastructure security and software supply chain security can no longer be treated as separate programs.
⬇️