TeamPCP Cloud Stealer is an information-stealing payload associated with the TeamPCP supply-chain activity targeting CI/CD runners, developer systems, and cloud and container environments. It was implanted into compromised software-distribution channels, including GitHub Actions and package releases, while allowing the legitimate host tool to continue operating. The malware extracts secrets from CI/CD runner memory and searches filesystem locations commonly used for SSH keys, source-control and package-manager tokens, cloud-provider credentials, Kubernetes and Docker secrets, environment files, database credentials, TLS keys, VPN configuration, cryptocurrency wallets, and collaboration-platform webhooks. It can query cloud instance metadata services for temporary credentials. Collected material is encrypted before exfiltration to attacker-controlled infrastructure; where direct exfiltration fails, it can abuse available GitHub credentials to stage stolen data in attacker-created repositories. Variants deployed outside CI/CD runners have established persistence through Python and systemd user-service mechanisms, and LiteLLM-associated variants attempted privileged Kubernetes deployment for cluster access. TeamPCP Cloud Stealer has been linked to compromises affecting Trivy, Checkmarx integrations, and LiteLLM. The TeamPCP attribution is supported by the malware's self-identification and reporting on the related campaign, though definitive attribution remains unconfirmed.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The payload design was consistent across all three targets... The malware was self-attributed in its string table: "TeamPCP Cloud stealer."
Their malware consistently self-identifies through an embedded string, “TeamPCP Cloud stealer,” which has become one of the clearest attribution markers across all campaign phases.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
During the Trivy compromise, the malware self identified as “TeamPCP Cloud stealer.”
When the infected software runs, the TeamPCP Cloud Stealer searches the system memory and files for digital master keys that allow access to a company’s servers. It specifically hunts for Kubernetes tokens and Solana cryptocurrency wallets.
The malware self-identifies as TeamPCP Cloud stealer in a Python comment on the final line of the embedded filesystem credential harvester.
33 distinct techniques documented for this family, organized by ATT&CK tactic.
La campagne TeamPCP est une série d’attaques supply chain ciblant des outils open source largement utilisés dans les pipelines CI/CD. Des GitHub Actions, extensions OpenVSX et packages npm/PyPI ont été compromis et des versions malveillantes publiées.
Version 1 - Monolithic Architecture : A 150-line bash script focused on environment fingerprinting and immediate credential harvesting...
Version 1 - Monolithic Architecture : A 150-line bash script focused on environment fingerprinting and immediate credential harvesting...
Exécution d’un script memdump.py qui dumpe la mémoire du processus Runner.Worker ; implantation via un fichier .pth exécuté à chaque démarrage de processus Python.
Force-pushed malicious code to 76 of 77 version tags in aquasecurity/trivy-action and all 7 tags in aquasecurity/setup-trivy; Published a weaponized Trivy binary (v0.69.4) to GitHub Releases, Docker Hub, GHCR, ECR Public, and deb/rpm repositories.
On March 19, during the active compromise window, the Commission's pipeline executed the malicious Trivy release and exfiltrated an AWS API key carrying management rights over multiple Commission AWS accounts.
The attack uses WAV steganography to hide encrypted second-stage payloads within valid audio files, allowing the malware to bypass network filters while establishing persistence
the malware exfiltrated stolen data to the vendor-themed typosquat domain checkmarx[.]zone .
The content repeatedly describes malware and threat actors creating hidden folders, adding dot prefixes to filenames, and setting file attributes such as hidden/system to conceal files and directories from users and defenders.
Sur GitHub-hosted Linux runners : exécution d’un script memdump.py qui dumpe la mémoire du processus Runner.Worker pour voler les secrets GitHub.
Beyond the primary targets, TeamPCP leveraged harvested tokens to infect 48 additional packages.
Stage 1 reads /proc/PID/environ for the current process and any running Runner.Worker , Runner.Listener , runsvc , or run.sh processes. It captures environment variables matching env or ssh in the key name, and if a value points to a file on disk, reads that file too.
Sur les autres environnements : scraping du système de fichiers à la recherche de credentials cloud, clés SSH, tokens de gestionnaires de packages, etc.
it executes a base64-encoded Python filesystem harvester ... that reads ... shell history
Sur les autres environnements : scraping du système de fichiers à la recherche de credentials cloud, clés SSH, tokens de gestionnaires de packages, etc.
immediate credential harvesting from AWS/GCP/Azure credentials using the compromised endpoint’s instance metadata service (IMDS).
AADInternals can gather unsecured credentials for Azure AD services, such as Azure AD Connect, from a local machine... Agent Tesla has the ability to extract credentials from configuration or support files... APT33 has used a variety of publicly available tools like LaZagne to gather credentials.
Stage 1 reads /proc/PID/environ for the current process and any running Runner.Worker , Runner.Listener , runsvc , or run.sh processes.
the Python filesystem harvester ... reads SSH keys, cloud credentials, Kubernetes configs, Docker credentials, .env files, terraform state, shell history, database configs, TLS private keys, and cryptocurrency wallets, walking multiple directories up to 6 levels deep
Exfiltration via GitHub API : création de repos pour contourner la détection réseau.
147 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
31 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Credential-stealing malware injected into the Trivy vulnerability scanner through a malicious update published using compromised service-account access.
Credential stealer used across the TeamPCP supply-chain incidents. On GitHub-hosted Linux runners it executes memdump.py to dump Runner.Worker memory and steal GitHub secrets; elsewhere it searches files for cloud credentials, SSH keys, and package-manager tokens. In the LiteLLM compromise it also enumerates Kubernetes secrets, attempts to create a privileged pod with the host filesystem mounted, persists via a Python .pth file, and exfiltrates through GitHub API-created repositories.
An information-stealing malware used in a supply-chain attack that infected tens of thousands of devices via the compromised LiteLLM open-source Python library.
A purpose-built stealer for CI/CD runner environments that harvests process memory, SSH keys, cloud credentials, and Kubernetes secrets, encrypts the stolen data, and exfiltrates it to attacker-controlled infrastructure. It also has a fallback exfiltration method using a repository named tpcp-docs inside the victim GitHub organization.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.