logo

Inside TeamPCP’s Shell Arsenal

ID: 70dca9ec-506e-5e1a-9e66-78aae99dd164

STIX ID: report--70dca9ec-506e-5e1a-9e66-78aae99dd164

Feed Name: THE RAVEN FILE

Threat Score
90/100

Date Published: 2026-04-02

Date Updated: 2026-05-13

Author: RakeshKrish

...
...

This report details a March 2026 supply-chain campaign by a threat actor named TeamPCP that compromised multiple open-source projects (notably Trivy and LiteLLM) to deploy a family of lightweight shell loaders and credential-stealers that harvest CI/CD and cloud secrets, execute in-memory Python payloads, deploy Kubernetes persistence (privileged pods/daemonsets), and exfiltrate encrypted data to typo-squatted domains and Cloudflare tunnels; the document includes MD5 hashes, domains, TTP mappings, and recommended detection IOCs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.