Validated Containment Architectures are here. →Explore

Executive Summary

TeamPCP, a sophisticated threat actor, has been actively compromising open-source software supply chains since at least 2020. Their operations involve injecting malicious code into widely-used software packages, leading to unauthorized access and control over numerous systems. In late 2025, they exploited the ShadowRay vulnerability (CVE-2023-48022) in the Ray AI framework, creating a self-propagating botnet that hijacked AI infrastructure globally. (oligo.security)

The rapid evolution of TeamPCP's attack methods, facilitated by AI, underscores the growing threat to open-source ecosystems. Their ability to adapt and scale attacks highlights the urgent need for enhanced security measures in software development and deployment processes.

Why This Matters Now

The increasing reliance on open-source software and AI technologies has expanded the attack surface for threat actors like TeamPCP. Their prolonged and evolving campaigns demonstrate the critical need for organizations to implement robust supply chain security practices to mitigate potential risks.

Attack Path Analysis

Related CVEs

MITRE ATT&CK® Techniques

Potential Compliance Exposure

Sector Implications

Sources

Frequently Asked Questions

The ShadowRay vulnerability (CVE-2023-48022) is a critical flaw in the Ray AI framework that allows remote code execution, exploited by TeamPCP to create a self-propagating botnet. ([oligo.security](https://www.oligo.security/blog/shadowray-2-0-attackers-turn-ai-against-itself-in-global-campaign-that-hijacks-ai-into-self-propagating-botnet?utm_source=openai))

Cloud Native Security Fabric Mitigations and ControlsCNSF

Aviatrix Zero Trust CNSF is pertinent to this incident as it could have constrained the attacker's ability to move laterally and exfiltrate data by enforcing strict segmentation and identity-aware policies.

Initial Compromise

Control: Cloud Native Security Fabric (CNSF)

Mitigation: The attacker's initial access may have been limited to the compromised workload, reducing the potential for further exploitation.

Privilege Escalation

Control: Zero Trust Segmentation

Mitigation: The attacker's ability to escalate privileges could have been constrained, limiting their control over additional systems.

Lateral Movement

Control: East-West Traffic Security

Mitigation: The attacker's lateral movement may have been restricted, reducing their ability to access sensitive data across cloud environments.

Command & Control

Control: Multicloud Visibility & Control

Mitigation: The attacker's command and control communications could have been detected and disrupted, reducing their ability to maintain persistence.

Exfiltration

Control: Egress Security & Policy Enforcement

Mitigation: The attacker's data exfiltration efforts may have been blocked, preventing the transfer of sensitive information to external servers.

Impact (Mitigations)

The overall impact of the attack could have been minimized, reducing data theft and service disruption.

Impact at a Glance

Affected Business Functions

  • Software Development
  • Continuous Integration/Continuous Deployment (CI/CD)
  • AI Model Training
Operational Disruption

Estimated downtime: 14 days

Financial Impact

Estimated loss: $5,000,000

Data Exposure

Source code repositories, developer credentials, AI model training data

Recommended Actions

  • Implement Zero Trust Segmentation to restrict lateral movement within cloud environments.
  • Enhance East-West Traffic Security to monitor and control internal communications.
  • Deploy Egress Security & Policy Enforcement to prevent unauthorized data exfiltration.
  • Utilize Multicloud Visibility & Control to detect and respond to anomalous activities across cloud platforms.
  • Apply Inline IPS (Suricata) to identify and block known exploit patterns and malicious payloads.

Secure the Paths Between Cloud Workloads

A cloud-native security fabric that enforces Zero Trust across workload communication—reducing attack paths, compliance risk, and operational complexity.

Cta pattren Image