Executive Summary
TeamPCP, a sophisticated threat actor, has been actively compromising open-source software supply chains since at least 2020. Their operations involve injecting malicious code into widely-used software packages, leading to unauthorized access and control over numerous systems. In late 2025, they exploited the ShadowRay vulnerability (CVE-2023-48022) in the Ray AI framework, creating a self-propagating botnet that hijacked AI infrastructure globally. (oligo.security)
The rapid evolution of TeamPCP's attack methods, facilitated by AI, underscores the growing threat to open-source ecosystems. Their ability to adapt and scale attacks highlights the urgent need for enhanced security measures in software development and deployment processes.
Why This Matters Now
The increasing reliance on open-source software and AI technologies has expanded the attack surface for threat actors like TeamPCP. Their prolonged and evolving campaigns demonstrate the critical need for organizations to implement robust supply chain security practices to mitigate potential risks.
Attack Path Analysis
TeamPCP initiated the attack by compromising open-source software packages, embedding malicious code to gain initial access. They escalated privileges by exploiting vulnerabilities in AI infrastructure, allowing deeper system control. Utilizing compromised credentials, they moved laterally across cloud environments to access sensitive data. Established command and control channels enabled persistent communication with infected systems. Data exfiltration was conducted by transferring stolen information to external servers. The attack culminated in significant data theft and potential disruption of AI services.
Kill Chain Progression
Initial Compromise
Description
TeamPCP compromised open-source software packages, embedding malicious code to gain initial access.
Related CVEs
CVE-2023-48022
CVSS 9.8A critical missing authentication vulnerability in the Ray open-source AI framework allows remote attackers to execute arbitrary code on unpatched servers.
Affected Products:
Anyscale Ray – < 2.8.1
Exploit Status:
exploited in the wildCVE-2026-33634
CVSS 8.8Malicious code injection in Aqua Security's Trivy vulnerability scanner allows attackers to execute credential-stealing malware during routine scans.
Affected Products:
Aqua Security Trivy – < 0.30.0
Exploit Status:
exploited in the wild
MITRE ATT&CK® Techniques
Supply Chain Compromise
Modify Authentication Process
Application Layer Protocol
Obfuscated Files or Information
Resource Hijacking
Exploitation for Client Execution
Valid Accounts
Ingress Tool Transfer
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Ensure software integrity
Control ID: 6.3.2
NYDFS 23 NYCRR 500 – Cybersecurity Policy
Control ID: 500.03
DORA – ICT Risk Management Framework
Control ID: Article 5
CISA ZTMM 2.0 – Supply Chain Risk Management
Control ID: 3.1
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Computer Software/Engineering
TeamPCP's systematic compromise of 1,000+ open-source packages creates critical supply chain vulnerabilities in software development environments requiring enhanced egress security and threat detection.
Information Technology/IT
AI infrastructure exploitation through ShadowRay vulnerabilities and open-source compromises necessitates zero trust segmentation and multicloud visibility controls for IT service providers.
Biotechnology/Greentech
Heavy reliance on open-source AI frameworks for research creates exposure to TeamPCP's supply chain attacks, requiring enhanced Kubernetes security and anomaly detection capabilities.
Financial Services
AI adoption race and open-source dependencies expose financial institutions to supply chain compromises, demanding encrypted traffic monitoring and egress policy enforcement per compliance requirements.
Sources
- Open-source software’s archenemy TeamPCP goes back further than anyone thoughthttps://cyberscoop.com/teampcp-long-active-history-2020-oligo-security/Verified
- How TeamPCP turned Aqua Security's own Trivy scanner into a weapon against millions of developershttps://thenewstack.io/teampcp-trivy-supply-chain-attack/Verified
- ShadowRay 2.0 Exploits Unpatched Ray Flaw to Build Self-Spreading GPU Cryptomining Botnethttps://thehackernews.com/2025/11/shadowray-20-exploits-unpatched-ray.htmlVerified
- When the Security Scanner Became the Weapon: Inside the TeamPCP Supply Chain Campaignhttps://www.sans.org/blog/when-security-scanner-became-weapon-inside-teampcp-supply-chain-campaignVerified
- Unpatched flaw in Anyscale's Ray AI framework under attackhttps://www.techtarget.com/searchsecurity/news/366575576/Unpatched-flaw-in-Anyscales-Ray-AI-framework-under-attackVerified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Aviatrix Zero Trust CNSF is pertinent to this incident as it could have constrained the attacker's ability to move laterally and exfiltrate data by enforcing strict segmentation and identity-aware policies.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: The attacker's initial access may have been limited to the compromised workload, reducing the potential for further exploitation.
Control: Zero Trust Segmentation
Mitigation: The attacker's ability to escalate privileges could have been constrained, limiting their control over additional systems.
Control: East-West Traffic Security
Mitigation: The attacker's lateral movement may have been restricted, reducing their ability to access sensitive data across cloud environments.
Control: Multicloud Visibility & Control
Mitigation: The attacker's command and control communications could have been detected and disrupted, reducing their ability to maintain persistence.
Control: Egress Security & Policy Enforcement
Mitigation: The attacker's data exfiltration efforts may have been blocked, preventing the transfer of sensitive information to external servers.
The overall impact of the attack could have been minimized, reducing data theft and service disruption.
Impact at a Glance
Affected Business Functions
- Software Development
- Continuous Integration/Continuous Deployment (CI/CD)
- AI Model Training
Estimated downtime: 14 days
Estimated loss: $5,000,000
Source code repositories, developer credentials, AI model training data
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust Segmentation to restrict lateral movement within cloud environments.
- • Enhance East-West Traffic Security to monitor and control internal communications.
- • Deploy Egress Security & Policy Enforcement to prevent unauthorized data exfiltration.
- • Utilize Multicloud Visibility & Control to detect and respond to anomalous activities across cloud platforms.
- • Apply Inline IPS (Suricata) to identify and block known exploit patterns and malicious payloads.



