ATT&CKReferencesPhoenix TeamPCP 20 MAY 2026

Phoenix TeamPCP 20 MAY 2026

Webb, M. (2026, May 20). TeamPCP Wave Four: GitHub Breach via Poisoned VS Code Extension, durabletask PyPI Worm, and ~4,000 Internal Repositories Exfiltrated. Retrieved July 16, 2026.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples30

TechniqueUsed byProcedure example
T1008
Fallback Channels
MalwareMini Shai-Hulud

Mini Shai-Hulud has established Fallback Channels to exfiltrate data to Github when other configured infrastructure is found to be unreachable.

T1021.007
Cloud Services
MalwareMini Shai-Hulud

Mini Shai-Hulud has accessed and propagated to AWS EC2 instances via SSM Send-Command.

T1041
Exfiltration Over C2 Channel
MalwareMini Shai-Hulud

Mini Shai-Hulud has exfiltrated encrypted archives over C2 domains.

T1059.006
Python
MalwareMini Shai-Hulud

Mini Shai-Hulud has utilized Python scripts to execute payloads.

T1059.013
Container CLI/API
GroupTeamPCP

TeamPCP has queried the Kubernetes API for local service account tokens and has used `kubectl` for lateral movement.

T1078.004
Cloud Accounts
GroupTeamPCP

TeamPCP has used compromised credentials for GitHub and software package repositories, including privileged service accounts, to inject malicious code into CI/CD pipelines.

T1082
System Information Discovery
MalwareMini Shai-Hulud

Mini Shai-Hulud has gathered system information of victim hosts through the use of common discovery commands to include `hostname`, `uname-a` and `printenv`. Mini Shai-Hulud has also conducted system checks of the victim device to include enumerating the system type and the number of CPUs operating on victim host.

T1102.001
Dead Drop Resolver
MalwareMini Shai-Hulud

Mini Shai-Hulud has leveraged GitHub commit-search API to recover fallback C2 domains stored in auto-created public Github repositories.

T1105
Ingress Tool Transfer
MalwareMini Shai-Hulud

Mini Shai-Hulud has the ability to download additional payloads from adversary controlled or compromised infrastructure.

T1124
System Time Discovery
MalwareMini Shai-Hulud

Mini Shai-Hulud has queried the system timezone configuration and timezone data files to include `/etc/localtime`, and locale settings to determine the geolocation of the compromised host.

T1132.001
Standard Encoding
MalwareMini Shai-Hulud

Mini Shai-Hulud has used base64 encoding to obfuscate URLs used for C2.

T1176.002
IDE Extensions
GroupTeamPCP

TeamPCP has compromised VS Code and Open VSX IDE extensions.

T1195.001
Compromise Software Dependencies and Development Tools
GroupTeamPCP

TeamPCP has conducted coordinated supply chain attacks targeting open-source developer infrastructure including the NPM, VS Code, Docker, and PyPi ecosystems to compromise multiple software packages.

T1213.003
Code Repositories
MalwareMini Shai-Hulud

Mini Shai-Hulud has gathered and downloaded data stored on both compromised and publicly accessible code repositories.

T1480
Execution Guardrails
MalwareMini Shai-Hulud

Mini Shai-Hulud has utilized execution guardrails in order to prevent operating in restricted geolocations to include Russia by checking the devices language and terminating when a forbidden value is detected. Mini Shai-Hulud has also utilized designated instructions that execute when victim hosts match geolocations to include wiping victim devices when the device is determined to be located within Iran or Israel.

T1485
Data Destruction
MalwareMini Shai-Hulud

Mini Shai-Hulud has wiped data on devices that fall within specified parameters to include those that resolve to specific geolocations including Iran and Israel. Mini Shai-Hulud has also implemented a dead-man’s switch that wipes the victims home directory if the operator revokes a GitHub token created by the adversary.

T1497.001
System Checks
MalwareMini Shai-Hulud

Mini Shai-Hulud has evaded execution in virtual environments and sandboxes through checking system information to include the number of CPUs and exiting at times when there were less than four and other times when there were less than two CPUs.

T1528
Steal Application Access Token
MalwareMini Shai-Hulud

Mini Shai-Hulud has stolen application access tokens and other tokens to include those associated with CI/CD.

T1550.001
Application Access Token
MalwareMini Shai-Hulud

Mini Shai-Hulud has the ability to authenticate using stolen application access tokens.

T1552.001
Credentials In Files
MalwareMini Shai-Hulud

Mini Shai-Hulud has collected credentials stored within configuration files. Mini Shai-Hulud has also gathered credentials from files stored in common credential file paths to include targeting git-credentials, azureProfile.json, and application_default_credentials.json.

T1555.005
Password Managers
MalwareMini Shai-Hulud

Mini Shai-Hulud has gathered credentials stored in password managers to include password vaults.

T1555.006
Cloud Secrets Management Stores
MalwareMini Shai-Hulud

Mini Shai-Hulud has captured credentials stored in cloud secret stores.

T1567.001
Exfiltration to Code Repository
MalwareMini Shai-Hulud

Mini Shai-Hulud has exfiltrated data through the use of the victim’s own GitHub repository by creating a new public repository using a unique naming convention from a curated list of key words or themes.

T1583.001
Domains
GroupTeamPCP

TeamPCP has registered domains resembling legitimate victim sites such as scan.aquasecurtiy[.]org, checkmarx[.]zone, and git-tanstack[.]com to mask C2 and exfiltration endpoints. TeamPCP has also set up a dark web leak site to post stolen data.

T1585.001
Social Media Accounts
GroupTeamPCP

TeamPCP has used its own Telegram channel and X accounts @pcpcats and @xploitrsturtle2 for external communications.

T1609
Container Administration Command
MalwareMini Shai-Hulud

Mini Shai-Hulud has utilized container administration commands to gather details of compromised hosts and gather credentials to include Kubernetes command-line utilities `kubectl get secrets`.

T1614.001
System Language Discovery
MalwareMini Shai-Hulud

Mini Shai-Hulud has the ability to check system details for its language configuration and terminates actions when the system is configured for the Russian language.

T1657
Financial Theft
GroupTeamPCP

TeamPCP has engaged in cryptocurrency mining and theft. TeamPCP has also partnered with ransomware and data theft extortion groups, sold leaked code, and crowdsourced supply chain compromises by open-sourcing their Mini Shai-Hulud malware.

T1677
Poisoned Pipeline Execution
GroupTeamPCP

TeamPCP has compromised trusted CI/CD pipelines by injecting credential-stealing payloads into legitimate workflows and software packages including open-source security tools Trivy and KICS, and AI gateway LiteLLM.

T1677
Poisoned Pipeline Execution
MalwareMini Shai-Hulud

Mini Shai-Hulud has utilized Github Actions to propagate through the use of triggered workflows.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.