From OSS to AWS: TeamPCP's Cloud Transformation

Keerthana S June 26, 2026| 12:09 PM Technology

The cybercriminal group known as TeamPCP has expanded its large-scale software supply chain campaign beyond open-source repositories, now targeting Amazon Web Services (AWS) environments using stolen cloud credentials. According to cybersecurity researchers at Wiz, the attackers quickly validated compromised credentials before launching cloud reconnaissance, lateral movement, and large-scale data theft.

From Supply Chain Attacks to Cloud Breaches

Active since 2024, TeamPCP initially focused on compromising cloud environments before shifting its attention to software supply chains in 2025. The group recently gained widespread attention after compromising Aqua Security's Trivy vulnerability scanner, triggering a chain of attacks that later spread to NPM, PyPI, and OpenVSX.

Figure 1. Cloud Transformation.

The malicious code hidden inside compromised Trivy packages executed automatically in downstream CI/CD pipelines, allowing the attackers to steal publishing tokens, API keys, SSH credentials, and other sensitive secrets from developers and organizations. Figure 1 shows cloud transformation.

Stolen Credentials Open the Door to AWS

After collecting thousands of credentials, TeamPCP used the open-source security tool TruffleHog to verify which AWS access keys, Azure secrets, and SaaS tokens were still active. Within just 24 hours, the attackers began exploring compromised AWS environments, mapping cloud services, container clusters, and AWS Secrets Manager instances to identify valuable targets.

Researchers observed the group using GitHub workflows and AWS ECS Exec to run Bash commands and Python scripts directly inside cloud-hosted containers, enabling deeper access to victim environments.

Large-Scale Data Theft

Once inside AWS, the attackers exfiltrated source code, configuration files, secrets, databases, and data stored in Amazon S3 buckets. Security experts believe the operation affected tens of thousands of repositories, with the stolen information potentially being shared with other cybercriminal groups for future attacks.

Possible Links to Other Threat Groups

Researchers suspect TeamPCP may be collaborating with other well-known cybercriminal organizations [1]. The extortion group Lapsus$ appeared to have advance knowledge of TeamPCP's activities, while the Vect Ransomware Group has publicly claimed to have partnered with the hackers, raising concerns that the stolen data could be used for ransomware or extortion campaigns.

Strengthening Cloud Security

Following the incident, AWS reminded customers to follow cloud security best practices by using temporary credentials such as IAM roles instead of long-term access keys. Security experts also recommend rotating credentials regularly, monitoring cloud activity, and protecting CI/CD pipelines to reduce the risk of similar supply chain attacks.

The campaign highlights how compromised developer tools can quickly become gateways into enterprise cloud environments, turning a software supply chain attack into a large-scale cloud security breach.

Reference:

  1. https://www.securityweek.com/teampcp-moves-from-oss-to-aws-environments/
Cite this article:

Keerthana S (2026), From OSS to AWS: TeamPCP's Cloud Transformation, AnaTechMaz, pp.198.

Recent Post

Blog Archive