SANDCLOCK is a credential-stealing malware family used by the financially motivated threat actor TeamPCP, which is formally tracked as UNC6780. It has been deployed in large-scale software supply chain compromises affecting trusted developer and security tooling, particularly in CI/CD and build environments. Reported delivery vectors include poisoned GitHub Actions workflows and trojanized packages published through ecosystems such as PyPI, enabling the malware to execute inside developer pipelines and downstream enterprise build systems.
SANDCLOCK is designed to harvest high-value secrets from ephemeral and developer-centric environments. Confirmed targets include AWS credentials, GitHub tokens, Kubernetes ServiceAccount tokens and configurations, SSH private keys, local environment variables, API-related secrets, and cryptocurrency wallet data. Multiple reports describe it extracting credentials directly from CI runner memory and build environments, making it especially dangerous in automated pipelines where broadly scoped tokens and cloud credentials are often present.
A notable operational characteristic of SANDCLOCK is its effort to evade network detection by disguising exfiltration as benign telemetry. It has been described as mimicking legitimate monitoring traffic and sending stolen data in HTTP POST requests crafted to resemble routine telemetry or observability communications. This tradecraft supports stealthy exfiltration from environments where outbound monitoring traffic is expected.
SANDCLOCK has been associated with follow-on monetization and intrusion activity by TeamPCP and affiliated criminal actors. Stolen credentials from campaigns involving SANDCLOCK were reportedly reused for downstream compromises of cloud and SaaS environments, additional supply chain abuse, extortion, and ransomware-adjacent monetization. The malware has featured prominently in compromises involving tools such as Trivy, Checkmarx-related assets, LiteLLM, and the Telnyx Python SDK, with repeated indications that AI-related developer infrastructure was deliberately targeted alongside broader software supply chain objectives.
Within the TeamPCP intrusion set, SANDCLOCK functions as a core credential access and exfiltration component rather than a persistence-focused implant. Its role is to rapidly collect secrets from trusted build and developer contexts, enabling subsequent lateral abuse, data theft, and criminal monetization across victim environments.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The group's March campaign exploited mutable GitHub Actions version tags in Aqua Security's Trivy scanner (CVE-2026-33634, CVSS 9.4) to deploy the SANDCLOCK credential stealer across an estimated 10,000-plus CI/CD pipeline runs. | The injected payload was the SANDCLOCK credential stealer, a purpose-built tool that mimics legitimate telemetry traffic — disguising exfiltration as POST requests to domains resembling monitoring services — to evade network detection controls.
The four CVEs associated with this campaign are CVE-2026-33634, CVE-2026-48027, CVE-2026-45321, and CVE-2025-55182.
The four CVEs associated with this campaign are CVE-2026-33634, CVE-2026-48027, CVE-2026-45321, and CVE-2025-55182.
The four CVEs associated with this campaign are CVE-2026-33634, CVE-2026-48027, CVE-2026-45321, and CVE-2025-55182.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The injected payload was the SANDCLOCK credential stealer, a purpose-built tool that mimics legitimate telemetry traffic — disguising exfiltration as POST requests to domains resembling monitoring services — to evade network detection controls.
17 distinct techniques documented for this family, organized by ATT&CK tactic.
Attackers used stolen credentials to clone more than 300 of Cisco's internal GitHub repositories, exfiltrating source code for Cisco AI Assistant, Cisco AI Defense, and products that had not yet been publicly announced.
designed to harvest sensitive information, including cloud access tokens, credentials, API keys, and other authentication material associated with services such as Amazon Web Services (AWS), Google Cloud Platform (GCP), and Microsoft Azure.
TeamPCP, formally designated UNC6780 by Google's Threat Intelligence Group, has executed at least three distinct supply chain campaign waves between March 19 and May 20, 2026, compromising security scanners, AI gateways, package managers, and — most recently — GitHub's own internal infrastructure.
The group's March campaign exploited mutable GitHub Actions version tags in Aqua Security's Trivy scanner (CVE-2026-33634, CVSS 9.4) to deploy the SANDCLOCK credential stealer across an estimated 10,000-plus CI/CD pipeline runs, subsequently cascading to Checkmarx KICS, LiteLLM, and the Telnyx Python SDK.
Its corresponding GitHub Action — aquasecurity/trivy-action — was referenced by downstream workflows using mutable version tags rather than pinned commit hashes, meaning that any attacker who could push a new commit and update those tags would instantly reach every pipeline that ran a Trivy scan on subsequent executions.
Its corresponding GitHub Action — aquasecurity/trivy-action — was referenced by downstream workflows using mutable version tags rather than pinned commit hashes, meaning that any attacker who could push a new commit and update those tags would instantly reach every pipeline that ran a Trivy scan on subsequent executions.
The injected payload was the SANDCLOCK credential stealer, a purpose-built tool that mimics legitimate telemetry traffic — disguising exfiltration as POST requests to domains resembling monitoring services — to evade network detection controls.
Attackers used stolen credentials to clone more than 300 of Cisco's internal GitHub repositories, exfiltrating source code for Cisco AI Assistant, Cisco AI Defense, and products that had not yet been publicly announced.
designed to harvest sensitive information, including cloud access tokens, credentials, API keys, and other authentication material associated with services such as Amazon Web Services (AWS), Google Cloud Platform (GCP), and Microsoft Azure.
Its corresponding GitHub Action — aquasecurity/trivy-action — was referenced by downstream workflows using mutable version tags rather than pinned commit hashes, meaning that any attacker who could push a new commit and update those tags would instantly reach every pipeline that ran a Trivy scan on subsequent executions.
SANDCLOCK scraped secrets from CI runner memory and transmitted AWS keys, GitHub tokens, Kubernetes configurations, and SSH private keys to attacker-controlled infrastructure.
SANDCLOCK scraped secrets from CI runner memory and transmitted AWS keys, GitHub tokens, Kubernetes configurations, and SSH private keys to attacker-controlled infrastructure.
SANDCLOCK: a credential stealing tool used by TeamPCP that extracts AWS credentials, Kubernetes ServiceAccount tokens, local environment variables, and cryptocurrency wallet data.
Simultaneously, the xinference PyPI package — a framework for running open-source LLMs in research and production environments — was poisoned with an expanded credential harvester that added cryptocurrency wallet data (MetaMask, Phantom, and Solana wallet files) to its exfiltration targets alongside standard developer credentials.
43 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
21 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Malware used in TeamPCP supply chain compromises as part of credential theft and persistent access operations.
Credential and data stealing malware that extracts AWS credentials, Kubernetes service account tokens, environment variables, and cryptocurrency wallet data.
Credential and data stealer that extracts AWS credentials, Kubernetes ServiceAccount tokens, local environment variables, and cryptocurrency wallet data.
A credential stealer used in software supply chain compromises to extract AWS keys and GitHub tokens from build environments.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.