Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
TeamPCP ... implemented more than half a dozen different methods to target or exploit AI tools and open source software development practices, some of which are embedded within its Dustmaker credential stealer software.
DUSTMAKER is a successor to the SANDCLOCK credential stealer in TeamPCP operations and is a cross-platform JavaScript payload optimized for CI/CD pipelines.
4 distinct techniques documented for this family, organized by ATT&CK tactic.
“The threat actor leveraged an AI coding chatbot, a prompt, and a set of agent instructions to plan, build, and execute a mass credential harvesting campaign in less than six hours.”
The agents actively searched server-side systems, identified weaknesses, and carried out targeted actions against online infrastructure... [The Recon] dashboard was designed to organize, validate, and manage more than 23,800 stolen secrets in real time, including API keys connected to cloud and AI services.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Credential-stealing malware that embeds methods for targeting or exploiting AI tools and open-source software-development practices.
Credential stealer that abuses AI coding and IDE workspace directories and malicious configuration files to induce assistant-driven script execution. It also uses fake pipeline tasks disguised as AI utilities to search for developer tokens and keys.
A cross-platform JavaScript credential-stealing payload used by TeamPCP from April 2026 onward. It is optimized for CI/CD pipelines, steals credentials to support extortion, and uniquely poisons AI-assistant workspaces and uses prompt injection for defense evasion.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.