TeamPCP Cloud Stealer

MITRE ATT&CK: S9041 View on attack.mitre.org

Aliases: TeamPCP Cloud Stealer, SANDCLOCK

Profile updated
2026-08-15 03:00:04

Context

The TeamPCP Cloud Stealer is a comprehensive filesystem credential stealer that can harvest, encrypt, and exfiltrate credentials from over 50 sensitive file paths across CI/CD, cloud, developer tooling, and container environments. The TeamPCP Cloud Stealer was the primary payload used by TeamPCP in March 2026 during early stages of a cascading supply chain campaign targeting CI/CD workflows.(Citation: Wiz Trivy Compromise MAR 2026)(Citation: Aqua Security Trivy Compromise MAR 2026)(Citation: Aqua Security Blog Trivy Compromise APR 2026)(Citation: Sysdig TeamPCP MAR 2026)(Citation: Wiz TeamPCP KICS MAR 2026)(Citation: Palo Alto TeamPCP MAR 2026)(Citation: Google AI Threat Tracker MAY 2026)(Citation: FBI TeamPCP JUL 2026)

Used by threat actors

Reports & references

  • ic3.gov — 260702 (report)
  • cloud.google.com — Ai Vulnerability Exploitation Initial Access (report)
  • github.com — Ghsa 69Fq Xp46 6X23 (report)
  • Palo Alto Unit 42 — Teampcp Supply Chain Attacks (report)
  • aquasec.com — Trivy Supply Chain Attack What You Need To Know (report)
  • wiz.io — Trivy Compromised Teampcp Supply Chain Attack (report)
  • MITRE ATT&CK — S9041 (report)
  • sysdig.com — Teampcp Expands Supply Chain Compromise Spreads From Trivy To Checkmarx Github Actions (report)
  • wiz.io — Teampcp Attack Kics Github Action (report)

External references