TPM has been hacked already, but it requires physical access and a huge level of sophistication. This might be the kind of thing for nation-state level hackers, not from random files you download from The Pirate Bay.
https://arstechnica.com/gadgets/2021/08/how-to-go-from-stolen-pc-to-network-intrusion-in-30-minutes/