IndicatorType,IndicatorValue,ExpirationTime,Action,Severity,Title,Description,RecommendedActions,RbacGroups,Category,MitreTechniques,GenerateAlert FileSha256,18a24f83e807479438dcab7a1804c51a00dafc1d526698a66e0640d1e5dd671a,2026-09-25T00:00:00Z,BlockAndRemediate,High,TeamPCP Malicious entrypoint.sh - Trivy Stealer,Trivy-action credential stealer. Dumps Runner.Worker process memory and exfiltrates encrypted secrets. Source: Phoenix Security.,Quarantine and rotate all CI/CD secrets and cloud credentials.,,Malware,"T1195.002,T1552.005,T1041",true FileSha256,c37c0ae9641d2e5329fcdee847a756bf1140fdb7f0b7c78a40fdc39055e7d926,2026-09-25T00:00:00Z,BlockAndRemediate,High,TeamPCP CanisterWorm Wave 4 Final Form,Self-propagating npm worm with armed ICP blockchain C2 backdoor. Source: Aikido Security.,Rotate npm tokens. Remove systemd pgmon service. Delete /tmp/pglog.,,Malware,"T1195.002,T1059.006,T1543.002",true FileSha256,0c0d206d5e68c0cf64d57ffa8bc5b1dad54f2dda52f24e96e02e237498cb9c3a,2026-09-25T00:00:00Z,BlockAndRemediate,High,TeamPCP CanisterWorm Wave 3 Self-Propagating Test,Self-propagating worm variant with test payload. Source: Aikido Security.,Rotate npm tokens. Audit npm packages for unauthorized version bumps.,,Malware,"T1195.002,T1059.006,T1543.002",true FileSha256,61ff00a81b19624adaad425b9129ba2f312f4ab76fb5ddc2c628a5037d31a4ba,2026-09-25T00:00:00Z,BlockAndRemediate,High,TeamPCP CanisterWorm Wave 2 Armed ICP Backdoor,Armed ICP blockchain backdoor with manual deployment. Source: Aikido Security.,Remove systemd pgmon service. Block ICP canister domain.,,Malware,"T1195.002,T1059.006,T1102",true FileSha256,f398f06eefcd3558c38820a397e3193856e4e6e7c67f81ecc8e533275284b152,2026-09-25T00:00:00Z,BlockAndRemediate,High,TeamPCP CanisterWorm Wave 1 deploy.js,Initial deploy script spreading malicious payload to npm packages via stolen tokens. Source: Aikido Security.,Rotate npm publishing tokens. Audit all published packages.,,Malware,"T1195.002,T1059.007",true FileSha256,7df6cef7ab9aae2ea08f2f872f6456b5d51d896ddda907a238cd6668ccdc4bb7,2026-09-25T00:00:00Z,BlockAndRemediate,High,TeamPCP CanisterWorm Wave 2 deploy.js,Deploy script with --tag latest flag for wider propagation. Source: Aikido Security.,Rotate npm publishing tokens. Check npm audit logs.,,Malware,"T1195.002,T1059.007",true FileSha256,5e2ba7c4c53fa6e0cef58011acdd50682cf83fb7b989712d2fcf1b5173bad956,2026-09-25T00:00:00Z,BlockAndRemediate,High,TeamPCP CanisterWorm Wave 3+ Minified deploy.js,Minified silent deploy script for stealth npm propagation. Source: Aikido Security.,Rotate npm tokens. Audit npm packages for patch bumps Mar 20-24.,,Malware,"T1195.002,T1059.007",true IpAddress,83.142.209.11,2026-09-25T00:00:00Z,Block,High,TeamPCP C2 Server - checkmarx.zone,Primary C2 IP for Checkmarx/KICS supply chain wave. Port 443. Source: Sysdig TRT / Wiz.,Block at firewall. Rotate secrets if any connection detected.,,CommandAndControl,"T1071.001,T1041",true IpAddress,45.148.10.212,2026-09-25T00:00:00Z,Block,High,TeamPCP C2 Server - scan.aquasecurtiy.org,Primary C2 IP for Trivy supply chain wave. Port 443. Source: Wiz / StepSecurity.,Block at firewall. Rotate CI/CD secrets if connection detected.,,CommandAndControl,"T1071.001,T1041",true DomainName,checkmarx.zone,2026-09-25T00:00:00Z,Block,High,TeamPCP C2 Domain - Checkmarx Typosquat,Typosquat C2 domain for credential exfiltration and payload delivery. Resolves to 83.142.209.11. Source: Wiz / Sysdig.,Block at DNS and proxy. Search logs for historical resolution.,,CommandAndControl,"T1583.001,T1071.001",true DomainName,scan.aquasecurtiy.org,2026-09-25T00:00:00Z,Block,High,TeamPCP C2 Domain - Aqua Security Typosquat,Typosquat C2 domain - deliberate misspelling aquasecurTIY. Resolves to 45.148.10.212. Source: Wiz / Socket.,Block at DNS and proxy. Typosquat designed to evade manual log review.,,CommandAndControl,"T1583.001,T1071.001",true DomainName,models.litellm.cloud,2026-09-25T00:00:00Z,Block,High,TeamPCP C2 Domain - LiteLLM PyPI Wave,C2 domain for trojanized LiteLLM PyPI packages v1.82.7 and v1.82.8. Source: Endor Labs / Mend.,Block domain. Check pip show litellm for compromised versions.,,CommandAndControl,"T1583.001,T1071.001",true DomainName,tdtqy-oyaaa-aaaae-af2dq-cai.raw.icp0.io,2026-09-25T00:00:00Z,Block,High,TeamPCP ICP Canister - CanisterWorm Dead-Drop C2,ICP blockchain canister dead-drop C2. Cannot be taken down conventionally. Source: Aikido Security.,Block domain. Check for systemd pgmon service on Linux hosts.,,CommandAndControl,"T1102,T1071.001",true Url,https://checkmarx.zone/static/checkmarx-util-1.0.4.tgz,2026-09-25T00:00:00Z,Block,High,TeamPCP Second-Stage Payload URL,Second-stage credential stealer package triggered by compromised OpenVSX extensions. Source: Wiz.,Block URL. Search proxy logs for any GET requests.,,Malware,"T1105,T1059.007",true Url,https://checkmarx.zone/vsx,2026-09-25T00:00:00Z,Block,High,TeamPCP Exfiltration Endpoint - VSX,Exfiltration endpoint receiving encrypted tpcp.tar.gz credential archives. Source: Wiz.,Block URL. Search proxy logs for POST requests.,,Exfiltration,"T1041,T1567",true Url,https://checkmarx.zone/raw,2026-09-25T00:00:00Z,Block,High,TeamPCP Persistence Polling URL,Persistence backdoor polls this URL every 50 minutes. Kill switch: youtube in response. Source: Wiz.,Block URL. Check systemd user services for sysmon.service.,,CommandAndControl,"T1071.001,T1543.002",true Url,https://tdtqy-oyaaa-aaaae-af2dq-cai.raw.icp0.io/,2026-09-25T00:00:00Z,Block,High,TeamPCP ICP Canister C2 Full URL,ICP blockchain canister dead-drop polled every 50 min by Python backdoor. Source: Aikido Security.,Block URL. Hunt for /tmp/pglog and /tmp/.pg_state on Linux hosts.,,CommandAndControl,"T1102,T1105",true