Malware.View on attack.mitre.org
The TeamPCP Cloud Stealer is a comprehensive filesystem credential stealer that can harvest, encrypt, and exfiltrate credentials from over 50 sensitive file paths across CI/CD, cloud, developer tooling, and container environments. The TeamPCP Cloud Stealer was the primary payload used by TeamPCP in March 2026 during early stages of a cascading supply chain campaign targeting CI/CD workflows.
| Technique | Procedure example |
|---|---|
| T1003.007 Proc Filesystem |
TeamPCP Cloud Stealer can scrape memory from the Runner.Worker process by reading `/proc/<pid>/mem` to extract secrets including plaintext tokens. |
| T1008 Fallback Channels |
TeamPCP Cloud Stealer can compress and encrypt data and exfiltrate it via POST to an attacker-controlled domain. If that method fails it can use the victim's own GitHub account to create a public repository and uploads the encrypted data as a release asset. |
| T1016 System Network Configuration Discovery |
TeamPCP Cloud Stealer has the ability to enumerate network interfaces. |
| T1020 Automated Exfiltration |
TeamPCP Cloud Stealer can compress and encrypt data and exfiltrate it via POST to scan.aquasecurtiy[.]org. If that method fails it attempts to use a stolen GITHUB_TOKEN to create a repo and exfiltrate the data there. |
| T1027.013 Encrypted/Encoded File |
TeamPCP Cloud Stealer has used multi-stage payloads with double Base64-encoded scripts to evade static analysis. |
| T1033 System Owner/User Discovery |
TeamPCP Cloud Stealer can use `whoami` on self-hosted runners to identify the current user. |
| T1036.005 Match Legitimate Resource Name or Location |
TeamPCP Cloud Stealer has installed a backdoor named sysmon.py on targeted systems. |
| T1041 Exfiltration Over C2 Channel |
TeamPCP Cloud Stealer has exfiltrated collected data to typosquat C2 domains including scan.aquasecurtiy[.]org. |
| T1049 System Network Connections Discovery |
TeamPCP Cloud Stealer can search compromised systems for webhook URLs connecting to Slack and Discord. |
| T1057 Process Discovery |
TeamPCP Cloud Stealer can locate GitHub Actions runner processes. |
| T1059.004 Unix Shell |
TeamPCP Cloud Stealer has abused the shell script files entrypoint.sh (in trivy-action) and setup.sh (in ast-github-action/2.3.28) for discovery and credential harvesting. |
| T1059.006 Python |
TeamPCP Cloud Stealer has leveraged Python scripts to download additional payloads, engage in discovery, and to establish persistence. |
| T1059.007 JavaScript |
TeamPCP Cloud Stealer has infected victims through malicious pre and post-install scripts within the package.json file. |
| T1070.004 File Deletion |
TeamPCP Cloud Stealer has the ability to remove all staged files after exfiltration. |
| T1071.001 Web Protocols |
TeamPCP Cloud Stealer has used `curl` to upload stolen data to attacker controlled domains. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.