TeamPCP Cloud Stealer
MITRE ATT&CK: S9041 View on attack.mitre.org
Aliases: TeamPCP Cloud Stealer, SANDCLOCK
- Profile updated
- 2026-08-15 03:00:04
Context
The TeamPCP Cloud Stealer is a comprehensive filesystem credential stealer that can harvest, encrypt, and exfiltrate credentials from over 50 sensitive file paths across CI/CD, cloud, developer tooling, and container environments. The TeamPCP Cloud Stealer was the primary payload used by TeamPCP in March 2026 during early stages of a cascading supply chain campaign targeting CI/CD workflows.(Citation: Wiz Trivy Compromise MAR 2026)(Citation: Aqua Security Trivy Compromise MAR 2026)(Citation: Aqua Security Blog Trivy Compromise APR 2026)(Citation: Sysdig TeamPCP MAR 2026)(Citation: Wiz TeamPCP KICS MAR 2026)(Citation: Palo Alto TeamPCP MAR 2026)(Citation: Google AI Threat Tracker MAY 2026)(Citation: FBI TeamPCP JUL 2026)
Used by threat actors
- TeamPCP (threat-actor)
Reports & references
- ic3.gov — 260702 (report)
- cloud.google.com — Ai Vulnerability Exploitation Initial Access (report)
- github.com — Ghsa 69Fq Xp46 6X23 (report)
- Palo Alto Unit 42 — Teampcp Supply Chain Attacks (report)
- aquasec.com — Trivy Supply Chain Attack What You Need To Know (report)
- wiz.io — Trivy Compromised Teampcp Supply Chain Attack (report)
- MITRE ATT&CK — S9041 (report)
- sysdig.com — Teampcp Expands Supply Chain Compromise Spreads From Trivy To Checkmarx Github Actions (report)
- wiz.io — Teampcp Attack Kics Github Action (report)