Unmasking TeamPCP, King of Software Supply Chain Attacks

August 27, 2026

A walkthrough of the process of deanonymization

By Flare’s Emerging Threats Team

For five days in March 2026, a single stolen token let one group poison five software ecosystems including a package downloaded 95 million times a month. The attack started with a misconfigured GitHub Actions workflow, and ended with backdoored code sitting inside CI/CD pipelines around the world.

Today, two people behind this attack were arrested. TeamPCP, allegedly operated by these threat actors, started attacks in late 2025 running opportunistic cloud exploits, then pivoted in early 2026 to targeting the software supply chain itself.

Flare’s Emerging Threats Team wanted to share examples of some of the techniques that can be used to unmask one operator behind TeamPCP, using the Flare platform to trace a single alias across the accounts, credentials, and infrastructure that connected back to a real identity. There were other independent investigations on this topic, including by Brian Krebs. Below, we walk through who TeamPCP is and share the process of deanonymizing threat actors.

Key Takeaways About the Unmasking of TeamPCP

  • The deanonymization process started with a single TeamPCP alias and traced every account it touched from there.
  • TeamPCP maintained Telegram channels, posted publicly on X, taunted victims, and gave a press interview. The same appetite for credit that amplified their campaigns produced the reused handles, avatars, and infrastructure references that made the operator identifiable.
  • For defenders: four controls would have broken TeamPCP’s chain of attack, and one of them is credential hygiene. More detailed recommendations are included below.
Flare CTA Block Preview

TI Friday — Live Session

TI Friday: Unmasking TeamPCP

Join us for TI Friday this Friday August 28 at 12 PM ET. Flare’s Emerging Threats Team will present their investigation into TeamPCP, walking through how the group was unmasked, and will be available afterward to answer questions.

Friday, 12pm ET – 1pm ET
Live walkthrough from Flare’s Emerging Threats Team, plus open Q&A
Save Your Spot →

What is TeamPCP?

TeamPCP History

TeamPCP surfaced in late 2025 as an opportunistic cloud-exploitation crew. An automated scanner swept the internet for exposed Docker APIs, Kubernetes control planes, Ray dashboards, and Redis instances. The group deployed containers on each compromised host. Every host became a scanner and proxy node, and the infection self-propagated. Flare’s honeypots recorded the activity firsthand and fingerprinted 185 Docker compromises in one phase. Revenue came from three sources. XMRig mining paid little. A rented proxy network brought in more. The group leaked or sold stolen data for extortion. TeamPCP broke out in December 2025 with a React2Shell campaign against Next.js applications. Their own control-server dashboard claimed more than 59,000 servers compromised in under 48 hours.

In early 2026, TeamPCP shifted to the software supply chain, and targeted security tools other companies trust. In late February, TeamPCP exploited a misconfigured GitHub Actions workflow in Aqua Security’s Trivy, the most widely deployed open-source vulnerability scanner, and stole a service-account token. Aqua rotated credentials but missed some. The leftover access held. On March 19, TeamPCP published a malicious Trivy release across every distribution channel at once. The release laced thousands of CI/CD pipelines with a credential stealer. The access cascaded. The AI-proxy library LiteLLM ran the poisoned Trivy inside the build pipeline, so the attackers harvested LiteLLM’s PyPI publishing token. On March 24, they shipped two backdoored LiteLLM releases. The package draws roughly 95 million downloads a month. One token, never fully revoked, let a single crew poison five software ecosystems in about five days.

Team PCP Aliases

TeamPCP’s earlier alliases

The group operates behind a web of names, which was important to our investigation as we’ll get into further below. The core identity is TeamPCP, but its work shows up under PCPcat (its first named campaign), ShellForce (its leak-publication persona), DeadCatx3 (a GitHub account hosting tooling), as well as Persy_PCP and PCPsh (earlier Telegram handles).

The group is loud by choice. They are active in Telegram channels, post on X under @pcpcats (now deleted), and like to taunt victims. That visibility is central to understanding them, and we return to it in the attribution and motivation sections below. In an interview with Forbes, TeamPCP stated “the group is a loose-knit group of teenagers and young adults who couldn’t find paying work, so they turned to cybercrime.”

Why We Went Looking

The same channels that let them taunt victims and claim credit also gave us a place to start. A group that talks this much, this publicly, under this many aliases, doesn’t just invite scrutiny, but it hands you the first thread to pull. So once TeamPCP crossed from opportunistic cloud exploits into poisoning five software ecosystems in a matter of days, we treated attribution not as a curiosity but as a priority, and started working backward from the aliases themselves.

Attribution Process: Who is Behind TeamPCP?

Flare’s Threat Flow (AI Threat Analysis tool) revealed that TeamPCP was active under a few usernames during prior operations. One of these was DeadCatx3, which was distinctive enough to be a viable pivot point, and it anchored the rest of this analysis.

To begin our search, we plugged that name into OSINT Industries, a way to search usernames across hundreds of social media platforms, and a few accounts stuck out including HackerOne and Hugging Face, which we’ll discuss, as well as Scratch, eBay, and Twitter.

One result that came back was from HackerOne, a platform that offers crowdsourced bug bounties and penetration testing for other companies. The account in question had the name Ruben Thomson connected to it.

It can’t be that easy, can it?

HackerOne profile connected to deadcatx3

Another account found in the initial search of DeadCatx3, was a Hugging Face profile with the initials, R T (possibly short for Ruben Thomson).

Hugging Face profile of “RT,” with the username DeadCatX3

Listed under his Hugging Face profile was a domain, masscan[.]cloud. This domain was used as a C2 for the Mini-Shai-Hulud worm launched by TeamPCP in May of this year.

C2 used in Mini-Shai-Hulud worm

To be more certain of this identity, and ensure it wasn’t stolen, we searched for more concrete evidence.

Investigating the Name

Digging deeper into the Ruben Thomson name yielded a few emails, including [email protected] and [email protected]. Searching the school email on the Flare Credential Browser tool gave us a password.

We performed a reverse pivot from that leaked password in Flare, which provided us the email “[email protected]”.

Flare Credentials Browser [Redacted] showed a few emails associated with the surfaced password

Our next step was to see what else was connected to this email account and how we could tie this back to TeamPCP to confirm our suspicions.

All accounts listed under the surfinup8 gmail via PredictaGraph

Flare Credentials Browser [Redacted] revealed the passwords for various accounts that [email protected] is affiliated with (Flare link to post, sign up for the free trial to access if you aren’t already a customer)

Searching for accounts under the surfinup8 Gmail account gives us the TikTok account: “yolosolo17.” The name listed on the profile: Ruben Thomson, and the only video posted to the account is of his Steam account which uses the name “YolocrownZ.”

Screenshot [Redacted] of TikTok account associated with the surfinup8 email account

Maybe this Steam account has something related to TeamPCP? We kept digging further to answer this question.

Finding the Steam account was more complex. As there were a series of emails that shared the same domain (one possibility being that it is shared by family members) we looked through leaked credentials and were able to find a Steam account associated with one of the emails.

If you notice the account shown on TikTok is VAC banned, the account linked to his acquaintance is not VAC banned.

Ruben Thomson’s acquaintance’s Steam account

Looking at the comments on the first Steam account, there was a comment from an account by the name of Ellis. The Ellis account has a VAC ban from the same date shown on the TikTok account.

Steam Account from Thomson’s TikTok shows VAC ban from September 13, 2016

Thomson’s Steam account profile picture is of a cat sitting in front of a few computer monitors, and reverse image searching this came back with zero results, possibly indicating that it is unique to Ruben Thomson himself.

Thomson’s Steam Account with a VAC ban on September 13, 2016

Thomson’s Steam profile account picture

Solving the Attribution Puzzle

To connect the pieces of information we found, we searched the Telegram account “PCP.sh” on Flare. We then found a screenshot of the TeamPCP Telegram account using the same profile picture as Thomson’s Steam account, signaling with high confidence that Ruben Thomson is the leader of Team PCP.

Search result for “pcp.sh” on Flare (Flare link to post, sign up for the free trial to access if you aren’t already a customer)

Concluding the Investigation

Each piece on its own could be explained as a shared name, a coincidental password, or a family resemblance in a profile picture. But taken together, they form a single unbroken chain: the DeadCatx3 handle ties to a HackerOne profile under Ruben Thomson’s name and a Hugging Face account listing TeamPCP’s own C2 domain; a reused password links his school email to a personal Gmail; that Gmail leads to a TikTok account under his name; and the Steam profile linked from that TikTok carries the exact same avatar seen fronting the TeamPCP Telegram channel.

It no longer became circumstantial, and we had evidence to demonstrate that this was the same person, using the same habits, and leaving the same fingerprints across every layer of his double life.

We assessed with high confidence that the operator behind the DeadCatx3 identity, and TeamPCP itself, was Ruben Thomson, based in Perth, Australia. From there, Flare’s Credentials Browser combined with PredictaGraph did the work of tracing that identity across leaked passwords, connected emails, and linked accounts, turning a single alias into a verifiable person. We confirmed these findings with law enforcement.

Actionable Takeaways for Defenders

  • Pin GitHub Actions to full commit SHAs, not tags. Tag references resolve to whatever the maintainer’s repository points at, which is exactly what TeamPCP replaced.
  • Treat credential rotation as an inventory exercise, not an incident task. Aqua rotated after the February intrusion and still left the access that shipped a backdoored release three weeks later. Rotation only works if you know the full set.
  • Scope publishing tokens narrowly and give them short lifetimes. A PyPI token that can publish anything, forever, converts one build-pipeline compromise into a supply chain event.
  • Alert on outbound connections from security tooling. A vulnerability scanner making unexpected network calls during a build is a high-signal, low-noise detection, and it is what the Trivy and LiteLLM payloads both required.
  • Monitor your own domains in stealer logs and combolists. The same reused-credential exposure that let us walk from a school email to a Telegram avatar is what an attacker uses to walk into your environment.

What TeamPCP Means for Security Teams

The technical story here is not sophistication. The group’s early operations were pure opportunism: scan for exposed services, drop a container, mine Monero. What changed was targeting. TeamPCP worked out that a vulnerability scanner running inside a build pipeline holds more credentials than most of the hosts it would ever compromise directly, and that trust in security tooling is transitive. LiteLLM didn’t get breached, but it ran Trivy.

That is the pattern worth internalizing, and it is the same one that made Mini Shai-Hulud work two months later. The blast radius of a compromised build tool is every pipeline that runs it, and the blast radius of every one of those pipelines is every credential it can see.

TeamPCP built a brand on cats and jokes: the calling card in the logs, the “silly cat” bio, the worm source code published under an MIT license with a punchline attached. That instinct for an audience is what turned an opportunistic scanner crew into one of the most consequential supply chain actors of the past year, and it is the same instinct that left a distinctive avatar sitting on a Steam profile for a decade, waiting for someone to look.

Flare CTA Block Preview

TI Friday — Live Session

TI Friday: Unmasking TeamPCP

Join us for TI Friday this Friday August 28 at 12 PM ET. Flare’s Emerging Threats Team will present their investigation into TeamPCP, walking through how the group was unmasked, and will be available afterward to answer questions.

Friday, 12pm ET – 1pm ET
Live walkthrough from Flare’s Emerging Threats Team, plus open Q&A
Save Your Spot →
Share article