TeamPCP is known for supply chain attacks against open-source tools targeting Kubernetes and cloud environments.
Analyst brief
TeamPCP, also tracked as Altered Spider or CanisterWorm, is a threat actor conducting supply chain attacks against open-source tools. They primarily target Kubernetes environments and cloud infrastructures by compromising widely used tools such as Trivy, KICS, and LiteLLM to deploy credential-stealing malware. Their TTPs include Python execution, steganography, persistence via Systemd services, and leveraging a self-propagating worm called CanisterWorm. Defenders should focus on verifying the integrity of open-source dependencies, especially in CI/CD pipelines, monitor for anomalous code execution chains, and scrutinize access attempts to cloud secrets management stores.
TeamPCP
Altered SpiderPCPcatShellForce
activeunknown
TeamPCP is a threat actor that has executed a coordinated series of supply chain attacks, compromising widely-used open source tools such as Trivy, KICS, and LiteLLM to deploy credential-stealing malware. They employed techniques like credential harvesting, lateral movement within Kubernetes environments, and audio steganography to evade detection. The group has demonstrated the ability to leverage stolen credentials to propagate attacks across multiple ecosystems, including npm and PyPI, using a self-propagating worm known as CanisterWorm. Their operations have included the use of AES-256 encryption and RSA-4096 for exfiltration of sensitive data.
Monitor file systems and network traffic to identify suspicious files and encrypted data, paying attention to Steganography and legitimate resource name matching.