ATT&CKReferencesSysdig TeamPCP MAR 2026

Sysdig TeamPCP MAR 2026

Sysdig Threat Research Team. (2026, March 23). TeamPCP expands: Supply chain compromise spreads from Trivy to Checkmarx GitHub Actions. Retrieved July 1, 2026.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples14

TechniqueUsed byProcedure example
T1003.007
Proc Filesystem
MalwareTeamPCP Cloud Stealer

TeamPCP Cloud Stealer can scrape memory from the Runner.Worker process by reading `/proc/<pid>/mem` to extract secrets including plaintext tokens.

T1041
Exfiltration Over C2 Channel
MalwareTeamPCP Cloud Stealer

TeamPCP Cloud Stealer has exfiltrated collected data to typosquat C2 domains including scan.aquasecurtiy[.]org.

T1049
System Network Connections Discovery
MalwareTeamPCP Cloud Stealer

TeamPCP Cloud Stealer can search compromised systems for webhook URLs connecting to Slack and Discord.

T1059.004
Unix Shell
MalwareTeamPCP Cloud Stealer

TeamPCP Cloud Stealer has abused the shell script files entrypoint.sh (in trivy-action) and setup.sh (in ast-github-action/2.3.28) for discovery and credential harvesting.

T1071.001
Web Protocols
MalwareTeamPCP Cloud Stealer

TeamPCP Cloud Stealer has used `curl` to upload stolen data to attacker controlled domains.

T1528
Steal Application Access Token
MalwareTeamPCP Cloud Stealer

TeamPCP Cloud Stealer can read runner.worker process memory to extract plaintext tokens.

T1555.006
Cloud Secrets Management Stores
MalwareTeamPCP Cloud Stealer

TeamPCP Cloud Stealer can enumerate multiple filesystem paths to extract credentials for AWS, GCP, and Azure including Identity Access Management (IAM) credentials.

T1555.006
Cloud Secrets Management Stores
GroupTeamPCP

TeamPCP has used malware to exfiltrate cloud secrets from targeted environments including AWS, GCP, and Azure.

T1560.001
Archive via Utility
MalwareTeamPCP Cloud Stealer

TeamPCP Cloud Stealer has bundled collected data into a file named tpcp.tar.gz for exfiltration.

T1567.001
Exfiltration to Code Repository
MalwareTeamPCP Cloud Stealer

TeamPCP Cloud Stealer can create a repository in the victim's GitHub account using the victim's own GITHUB_TOKEN to upload stolen credentials.

T1573.001
Symmetric Cryptography
MalwareTeamPCP Cloud Stealer

TeamPCP Cloud Stealer has encrypted collected data using a hybrid AES-256 and RSA-4096 encryption prior to exfiltration over 'curl`.

T1573.002
Asymmetric Cryptography
MalwareTeamPCP Cloud Stealer

TeamPCP Cloud Stealer has encrypted collected data using a hybrid RSA-4096 and AES-256-encryption prior to exfiltration over 'curl`.

T1583.001
Domains
GroupTeamPCP

TeamPCP has registered domains resembling legitimate victim sites such as scan.aquasecurtiy[.]org, checkmarx[.]zone, and git-tanstack[.]com to mask C2 and exfiltration endpoints. TeamPCP has also set up a dark web leak site to post stolen data.

T1677
Poisoned Pipeline Execution
GroupTeamPCP

TeamPCP has compromised trusted CI/CD pipelines by injecting credential-stealing payloads into legitimate workflows and software packages including open-source security tools Trivy and KICS, and AI gateway LiteLLM.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.