Inside TeamPCP’s Shell Arsenal
ID: 70dca9ec-506e-5e1a-9e66-78aae99dd164
STIX ID: report--70dca9ec-506e-5e1a-9e66-78aae99dd164
Feed Name: THE RAVEN FILE
This report details a March 2026 supply-chain campaign by a threat actor named TeamPCP that compromised multiple open-source projects (notably Trivy and LiteLLM) to deploy a family of lightweight shell loaders and credential-stealers that harvest CI/CD and cloud secrets, execute in-memory Python payloads, deploy Kubernetes persistence (privileged pods/daemonsets), and exfiltrate encrypted data to typo-squatted domains and Cloudflare tunnels; the document includes MD5 hashes, domains, TTP mappings, and recommended detection IOCs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
