Executive Summary
TeamPCP, a threat actor active since at least 2020, has been implicated in a series of cyberattacks targeting internet-facing infrastructure and software supply chains. Initial activities involved compromising exposed Redis servers to deploy cryptocurrency miners, evolving into more sophisticated campaigns like ShadowRay 2.0, which hijacked AI infrastructure into self-propagating botnets. By 2026, TeamPCP expanded into high-profile supply chain attacks, injecting malicious code into popular open-source libraries through GitHub Actions and token theft, leading to widespread developer system infections.
This escalation underscores the increasing threat posed by supply chain attacks, highlighting the need for enhanced security measures in software development and deployment processes. Organizations must remain vigilant against such evolving tactics to protect their infrastructure and data.
Why This Matters Now
The recent activities of TeamPCP demonstrate a significant shift towards targeting software supply chains, exploiting the interconnected nature of modern development environments. This trend poses an urgent threat to organizations relying on open-source tools, necessitating immediate action to bolster supply chain security and prevent potential widespread compromises.
Attack Path Analysis
TeamPCP exploited vulnerabilities in internet-facing Redis servers to gain initial access, escalated privileges by deploying malware, moved laterally to compromise additional cloud-native environments, established command and control channels for remote management, exfiltrated sensitive data, and ultimately deployed ransomware and cryptocurrency miners to disrupt operations.
Kill Chain Progression
Initial Compromise
Description
Exploited vulnerabilities in exposed Redis servers to gain unauthorized access.
Related CVEs
CVE-2025-55182
CVSS 10A critical vulnerability in React Server Components (RSC) allows remote attackers to execute arbitrary code via crafted requests.
Affected Products:
React Server Components – < 17.0.2
Exploit Status:
exploited in the wildCVE-2026-33634
CVSS 8.8A vulnerability in Aqua Security's Trivy GitHub Action allows attackers to inject malicious code into CI/CD pipelines, leading to credential theft and unauthorized access.
Affected Products:
Aqua Security Trivy GitHub Action – <= 0.18.3
Exploit Status:
exploited in the wild
MITRE ATT&CK® Techniques
Exploit Public-Facing Application
Valid Accounts
Command and Scripting Interpreter
Lateral Tool Transfer
Data Encrypted for Impact
Resource Hijacking
Credentials from Password Stores
Impair Defenses
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Ensure all system components and software are protected from known vulnerabilities
Control ID: 6.2
NYDFS 23 NYCRR 500 – Cybersecurity Policy
Control ID: 500.03
DORA – ICT Risk Management Framework
Control ID: Article 5
CISA ZTMM 2.0 – Identity and Access Management
Control ID: 3.1
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Computer Software/Engineering
Multi-stage TeamPCP campaigns targeting React, Docker, Redis infrastructure plus supply chain attacks on open-source libraries threaten software development environments and code repositories.
Information Technology/IT
Kubernetes environments face systematic compromise through automated wormable exploits, lateral movement capabilities, and destructive payloads requiring enhanced segmentation and egress controls.
Banking/Mortgage
Redis server exploitation and encrypted traffic vulnerabilities expose financial data in transit, requiring Zero Trust segmentation and PCI compliance controls against credential extraction.
Health Care / Life Sciences
Cloud-native infrastructure attacks threaten patient data through east-west traffic compromise and exfiltration, demanding HIPAA-compliant multicloud visibility and anomaly detection capabilities.
Sources
- TeamPCP Linked To Redis Attacks Dating Back To 2020 And Later Supply Chain Campaignhttps://thehackernews.com/2026/08/teampcp-linked-to-redis-attacks-dating.htmlVerified
- When the Security Scanner Became the Weapon: Inside the TeamPCP Supply Chain Campaignhttps://www.sans.org/blog/when-security-scanner-became-weapon-inside-teampcp-supply-chain-campaignVerified
- TeamPCP: Cascading Supply Chain Assault via Developer Security Toolinghttps://labs.cloudsecurityalliance.org/research/csa-research-note-teampcp-supply-chain-campaign-cicd-2026040/Verified
- FBI warns developers over TeamPCP software supply chain attackshttps://www.developer-tech.com/news/fbi-teampcp-software-supply-chain-attacks/Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Aviatrix Zero Trust CNSF is pertinent to this incident as it would likely limit the attacker's ability to move laterally and exfiltrate data by enforcing strict segmentation and controlled egress policies.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: The attacker's initial access would likely be constrained to the compromised Redis server, reducing the potential for further exploitation.
Control: Zero Trust Segmentation
Mitigation: The attacker's ability to escalate privileges would likely be limited, reducing the risk of gaining higher-level access.
Control: East-West Traffic Security
Mitigation: The attacker's lateral movement would likely be restricted, limiting access to other workloads.
Control: Multicloud Visibility & Control
Mitigation: The attacker's ability to establish command and control channels would likely be detected and constrained.
Control: Egress Security & Policy Enforcement
Mitigation: The attacker's data exfiltration efforts would likely be blocked or limited.
The attacker's ability to deploy ransomware and miners would likely be limited to the initially compromised workload.
Impact at a Glance
Affected Business Functions
- Software Development
- Continuous Integration/Continuous Deployment (CI/CD) Pipelines
- Cloud Infrastructure Management
Estimated downtime: 14 days
Estimated loss: $5,000,000
Compromise of developer credentials, leading to unauthorized access to source code repositories and cloud environments.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust Segmentation to restrict lateral movement within cloud environments.
- • Enforce Egress Security & Policy Enforcement to monitor and control outbound traffic, preventing data exfiltration.
- • Deploy Inline IPS (Suricata) to detect and prevent exploitation attempts on internet-facing services.
- • Utilize Multicloud Visibility & Control to gain comprehensive insights into cloud-native environments and detect anomalies.
- • Apply East-West Traffic Security to monitor and secure internal traffic, mitigating lateral movement risks.



