SANDCLOCK is a Python-based credential-stealing malware used by the financially motivated threat actor TeamPCP, also tracked as UNC6780. It targeted Linux-based developer workstations, CI/CD runners, containerized workloads, and Kubernetes environments during software supply-chain compromises affecting developer, security, and AI-related tooling. The stealer harvests cloud credentials, source-control tokens, Kubernetes ServiceAccount tokens and configurations, SSH material, environment variables, environment files, process-memory secrets, AI-provider API keys, and cryptocurrency-wallet data. SANDCLOCK has been reported to escalate privileges to root on compromised build systems and includes container-escape functionality. It supports automatic execution through Python startup mechanisms, encrypts collected data before exfiltration, and attempts to blend outbound collection traffic with legitimate-looking telemetry. Where direct network exfiltration is unavailable, it can use compromised source-control accounts to stage stolen material. Stolen credentials associated with SANDCLOCK activity have been used for downstream account compromise, supply-chain abuse, extortion, and ransomware-enabled monetization.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The group's March campaign exploited mutable GitHub Actions version tags in Aqua Security's Trivy scanner (CVE-2026-33634, CVSS 9.4) to deploy the SANDCLOCK credential stealer across an estimated 10,000-plus CI/CD pipeline runs. | The injected payload was the SANDCLOCK credential stealer, a purpose-built tool that mimics legitimate telemetry traffic — disguising exfiltration as POST requests to domains resembling monitoring services — to evade network detection controls.
The four CVEs associated with this campaign are CVE-2026-33634, CVE-2026-48027, CVE-2026-45321, and CVE-2025-55182.
The four CVEs associated with this campaign are CVE-2026-33634, CVE-2026-48027, CVE-2026-45321, and CVE-2025-55182.
The four CVEs associated with this campaign are CVE-2026-33634, CVE-2026-48027, CVE-2026-45321, and CVE-2025-55182.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
SANDCLOCK, used by TeamPCP in March and April 2026, is a Python-based credential stealer designed for Linux and Kubernetes environments.
SANDCLOCK, used by TeamPCP in March and April 2026, is a Python-based credential stealer designed for Linux and Kubernetes environments.
26 distinct techniques documented for this family, organized by ATT&CK tactic.
The threat actor group “TeamPCP” compromised maintainer credentials for LiteLLM and published malicious package versions 1.82.7 and 1.82.8 to PyPI around March 2026
TeamPCP ... has conducted a series of large-scale software supply chain compromises targeting PyPI, npm, and Docker Hub.
The malicious LiteLLM releases were published after the compromised Trivy component reached the project’s build environment. The incident carries the risk of trusted package supply chain attacks: one altered dependency can reach environments before maintainers react.
TeamPCP allegedly inserted malicious code into software hosted on public repositories, which was then unwittingly used by other developers. The group injected malicious code into legitimate software packages and pushed trojanized versions through normal distribution channels.
Execution T1059 Command & Scripting (CI runner) Malicious code runs inside CI/CD job context
...haben Angreifer im Python Packages Index (PyPI) kompromittierte Pakete eingeschleust. Diese wurden offenbar von automatisierten Build-Systemen zigtausendfach heruntergeladen und verwendet...
Its corresponding GitHub Action — aquasecurity/trivy-action — was referenced by downstream workflows using mutable version tags rather than pinned commit hashes, meaning that any attacker who could push a new commit and update those tags would instantly reach every pipeline that ran a Trivy scan on subsequent executions.
File path /proc/<pid>/mem Process memory path reportedly scraped for CI/CD secrets
Privilege Escalation T1068 Exploitation for Priv-Esc SANDCLOCK escalated to root on compromised runners
The injected payload was the SANDCLOCK credential stealer, a purpose-built tool that mimics legitimate telemetry traffic — disguising exfiltration as POST requests to domains resembling monitoring services — to evade network detection controls.
File path /proc/<pid>/mem Process memory path reportedly scraped for CI/CD secrets
The threat actor group “TeamPCP” compromised maintainer credentials for LiteLLM and published malicious package versions 1.82.7 and 1.82.8 to PyPI around March 2026
Its corresponding GitHub Action — aquasecurity/trivy-action — was referenced by downstream workflows using mutable version tags rather than pinned commit hashes, meaning that any attacker who could push a new commit and update those tags would instantly reach every pipeline that ran a Trivy scan on subsequent executions.
SANDCLOCK scraped secrets from CI runner memory and transmitted AWS keys, GitHub tokens, Kubernetes configurations, and SSH private keys to attacker-controlled infrastructure.
Over 2,500+ organizations and hundreds of thousands of CI/CD environments suffered full-credential exposure, compromising cloud infrastructure keys, repository access tokens, SSH credentials, Kubernetes secrets, and AI provider API keys
On a CI/CD runner, the credential-stealing payload sought elevated access and searched for SSH keys, cloud credentials, Kubernetes tokens, environment files and secrets in process memory.
On every compromised runner the stealer escalated to root and swept SSH keys, cloud credentials, Kubernetes tokens, .env files and in-memory secrets from /proc/<pid>/mem
Collection T1114 / T1530 local capture Writes secrets to local 127.0.0.1 capture files
Die Daten haben die Angreifer mit AES-256 und einem fest einprogrammierten RSA-4096-Key verschlüsselt und an Server gesendet, die eine Typosquatting-Domain nutzten.
43 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
29 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Python-based Linux/Kubernetes credential stealer used in TeamPCP supply-chain compromises. It steals cloud and developer credentials, targets cryptocurrency wallets, and includes container-escape functionality.
Credential and data stealer that extracts AWS credentials, Kubernetes ServiceAccount tokens, local environment variables, and cryptocurrency-wallet data.
A backdoor/credential-stealing malware implanted via malicious LiteLLM package versions 1.82.7 and 1.82.8 in a supply-chain attack, exposing cloud keys, repository tokens, SSH credentials, Kubernetes secrets, and AI provider API keys from affected CI/CD environments and repositories.
Credential-stealing malware used in the LiteLLM/Trivy supply-chain campaign. It executed inside compromised CI/CD runners, escalated to root, harvested environment secrets, SSH keys, cloud credentials, Kubernetes tokens, .env files, and in-memory secrets from /proc/<pid>/mem, then wrote per-run loot files for exfiltration.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.