Who is TeamPCP?
TeamPCP is a financially motivated ransomware group tied to software supply chain compromise, credential theft, extortion, and abuse of developer infrastructure. The group is also tracked through aliases including ShellForce, PCPcat, TeamPCP, DeadCatx3, Altered Spider, and PersyPCP. The group has also claimed ownership of CipherForce, which it describes as its private locker.
TeamPCP is not just going after traditional enterprise targets. Their activity is focused on the tools developers use every day: open-source packages, GitHub repositories, CI/CD workflows, VS Code extensions, Kubernetes environments, Docker, npm, PyPI, Trivy, KICS, LiteLLM, the Telnyx Python SDK, and other parts of the development workflow. Developer environments often contain sensitive access by default, including source code, API keys, SSH keys, cloud tokens, Kubernetes secrets, package publishing credentials, and build-system permissions. If an attacker compromises one trusted tool, they do not need to break into every company one by one. They can use the software supply chain itself as the path in.
What’s happening right now?
According to Bitsight Threat Intelligence, TeamPCP-related activity increased by 471% in the last month compared to similar groups. TeamPCP’s activity lines up with where cybercrime is moving, as we discussed in the 2026 State of the Underground. Attackers are moving upstream into the software development process. Instead of only trying to phish users or break into networks directly, they are going after the trusted tools, packages, credentials, and workflows that developers already use.
Attackers do not need to break in through the front door. They can slip a compromised package into a project, use a stolen token to publish malware under a trusted name, or rely on a malicious extension to steal local credentials. Once a repository is compromised, internal code, secrets, and business logic can all be exposed. This is a business risk because one compromised dependency, vendor, package, or extension can affect customers, partners, suppliers, and downstream users.
Who is at risk?
TeamPCP is most relevant to organizations that rely heavily on software development infrastructure and third-party code. That includes software vendors, SaaS companies, cloud-native organizations, open-source maintainers, DevOps teams, platform engineering teams, and companies using GitHub, npm, PyPI, Docker, GitHub Actions, VS Code, or Kubernetes.
Bitsight Threat Intelligence has seen a huge shift towards third party targeted attacks. Threat actors are going after larger blast radius attacks, so a company does not need to be directly targeted by TeamPCP to be in the line of fire. If a vendor, package, extension, or dependency is compromised, the risk can move downstream. That is why this should be treated as a third-party risk issue, a developer security issue, and a business continuity issue.
TeamPCP supply chain activity
More recent reporting also connects TeamPCP to Vect, an emerging Ransomware-as-a-Service operation. The concern is that TeamPCP’s access from supply chain compromise and stolen credentials could help feed Vect ransomware deployment and extortion activity. Recently, TeamPCP has been linked to compromised developer and security tools, including Trivy, KICS, LiteLLM, and the Telnyx Python SDK. The group has used credential-stealing malware to harvest secrets from developer and cloud environments, including SSH keys, Kubernetes credentials, cloud tokens, .env files, package publishing credentials, and other access that can help attackers move deeper into an environment.
The FBI FLASH also lists SANDCLOCK, Mini Shai-Hulud, and Miasma as malware used by TeamPCP. SANDCLOCK is described as a credential-stealing tool, while Mini Shai-Hulud and Miasma are tied to self-replicating supply chain activity across npm and PyPI. This supports the broader pattern: TeamPCP is using stolen credentials and trusted package ecosystems to scale activity across developer environments.
Another major piece of reporting involved claims around thousands of GitHub internal repositories. Public reporting linked the activity to a malicious Visual Studio Code extension installed by a GitHub employee. GitHub reportedly contained the incident, removed affected extensions, isolated the device, and rotated critical secrets.
Recent social media activity also shows TeamPCP’s name being used in connection with the xinference PyPI hijack, where reporting referenced stolen cloud credentials, SSH keys, and .env secrets.
Statement on Vect
TeamPCP and Vect are now reported to be working together, which changes the risk picture. TeamPCP brings the supply chain side of the operation, compromising developer and security tools, stealing credentials, and gaining access through trusted software channels. Vect brings the ransomware side through its Ransomware-as-a-Service operation and extortion model. That combination matters because it connects two parts of the attack chain. TeamPCP can create access at scale through compromised packages, CI/CD pipelines, and stolen credentials. Vect can then use that access to support ransomware deployment and extortion.
TeamPCP
Supply chain access
Compromises dev & security tools
Targets the tooling engineering and security teams rely on every day.
Steals credentials
Harvests logins and keys to move through environments as a trusted identity.
Rides trusted software channels
Reaches targets through compromised packages and CI/CD pipelines.
Vect
Ransomware & extortion
Runs Ransomware-as-a-Service
Supplies the ransomware operation other actors can plug into.
Drives the extortion model
Pressures victims to pay through leak threats and deadlines.
Alone, Vect still needs a way in.
Access at scale, monetized through ransomware
TeamPCP's compromised packages, pipelines, and credentials give Vect the access it needs to deploy ransomware and run extortion.
There is also an important recovery issue. Vect’s encryptor has reportedly had serious coding flaws. For files larger than 128 KB, researchers found that the ransomware can corrupt data in a way that makes recovery impossible, even if a victim pays and receives a key. That makes clean, disconnected backups even more important.
Earlier TeamPCP messaging tried to separate CipherForce from Vect’s encryption issues, but newer reporting indicates the two groups are now working together. The FBI FLASH confirms TeamPCP’s supply chain activity and broader collaboration with cyber actors, while public reporting from security researchers and media connects TeamPCP specifically to Vect.