Sysdig Threat Research Team. (2026, March 23). TeamPCP expands: Supply chain compromise spreads from Trivy to Checkmarx GitHub Actions. Retrieved July 1, 2026.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1003.007 Proc Filesystem |
MalwareTeamPCP Cloud Stealer | TeamPCP Cloud Stealer can scrape memory from the Runner.Worker process by reading `/proc/<pid>/mem` to extract secrets including plaintext tokens. |
| T1041 Exfiltration Over C2 Channel |
MalwareTeamPCP Cloud Stealer | TeamPCP Cloud Stealer has exfiltrated collected data to typosquat C2 domains including scan.aquasecurtiy[.]org. |
| T1049 System Network Connections Discovery |
MalwareTeamPCP Cloud Stealer | TeamPCP Cloud Stealer can search compromised systems for webhook URLs connecting to Slack and Discord. |
| T1059.004 Unix Shell |
MalwareTeamPCP Cloud Stealer | TeamPCP Cloud Stealer has abused the shell script files entrypoint.sh (in trivy-action) and setup.sh (in ast-github-action/2.3.28) for discovery and credential harvesting. |
| T1071.001 Web Protocols |
MalwareTeamPCP Cloud Stealer | TeamPCP Cloud Stealer has used `curl` to upload stolen data to attacker controlled domains. |
| T1528 Steal Application Access Token |
MalwareTeamPCP Cloud Stealer | TeamPCP Cloud Stealer can read runner.worker process memory to extract plaintext tokens. |
| T1555.006 Cloud Secrets Management Stores |
MalwareTeamPCP Cloud Stealer | TeamPCP Cloud Stealer can enumerate multiple filesystem paths to extract credentials for AWS, GCP, and Azure including Identity Access Management (IAM) credentials. |
| T1555.006 Cloud Secrets Management Stores |
GroupTeamPCP | TeamPCP has used malware to exfiltrate cloud secrets from targeted environments including AWS, GCP, and Azure. |
| T1560.001 Archive via Utility |
MalwareTeamPCP Cloud Stealer | TeamPCP Cloud Stealer has bundled collected data into a file named tpcp.tar.gz for exfiltration. |
| T1567.001 Exfiltration to Code Repository |
MalwareTeamPCP Cloud Stealer | TeamPCP Cloud Stealer can create a repository in the victim's GitHub account using the victim's own GITHUB_TOKEN to upload stolen credentials. |
| T1573.001 Symmetric Cryptography |
MalwareTeamPCP Cloud Stealer | TeamPCP Cloud Stealer has encrypted collected data using a hybrid AES-256 and RSA-4096 encryption prior to exfiltration over 'curl`. |
| T1573.002 Asymmetric Cryptography |
MalwareTeamPCP Cloud Stealer | TeamPCP Cloud Stealer has encrypted collected data using a hybrid RSA-4096 and AES-256-encryption prior to exfiltration over 'curl`. |
| T1583.001 Domains |
GroupTeamPCP | TeamPCP has registered domains resembling legitimate victim sites such as scan.aquasecurtiy[.]org, checkmarx[.]zone, and git-tanstack[.]com to mask C2 and exfiltration endpoints. TeamPCP has also set up a dark web leak site to post stolen data. |
| T1677 Poisoned Pipeline Execution |
GroupTeamPCP | TeamPCP has compromised trusted CI/CD pipelines by injecting credential-stealing payloads into legitimate workflows and software packages including open-source security tools Trivy and KICS, and AI gateway LiteLLM. Aikido TeamPCP Telnyx MAR 2026Aqua Security Blog Trivy Compromise APR 2026Aqua Security Trivy Compromise MAR 2026FBI TeamPCP JUL 2026Flashpoint Mini Shai-Hulud MAY 2026Google AI Threat Tracker MAY 2026Hunt.io TeamPCP Toolkit MAY 2026Palo Alto TeamPCP MAR 2026Phoenix TeamPCP 20 MAY 2026Sysdig TeamPCP MAR 2026Trend Micro TeamPCP MAY 2026Wiz Mini Shai-Hulud MAY 2026Wiz TeamPCP KICS MAR 2026Wiz Trivy Compromise MAR 2026 |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.