TeamPCP Cloud Stealer is a credential-harvesting malware payload associated with the TeamPCP threat group, also tracked under aliases including DeadCatx3, PCPcat, and ShellForce. It emerged prominently in March 2026 during a series of software supply-chain compromises affecting developer and security tooling used in CI/CD environments, including poisoned GitHub Actions, trojanized package releases, and backdoored binaries. The malware was designed to preserve the expected functionality of compromised tools while covertly stealing secrets from build runners, developer systems, and cloud-native environments.
Its primary purpose is theft of credentials and sensitive configuration material. Reported targets include GitHub tokens, SSH keys, cloud provider credentials for AWS, Google Cloud, and Microsoft Azure, Kubernetes tokens and kubeconfig data, Docker credentials, Git credentials, secrets stored in environment files, database credentials, TLS private keys, VPN-related material, CI/CD configuration secrets, cryptocurrency wallet data, and collaboration webhook URLs. In CI/CD runner environments, the malware has been observed dumping process memory from runner processes to recover secrets that may not be present on disk, and it also searches dozens of filesystem locations commonly used to store credentials across cloud, container, and developer workflows.
The malware encrypts collected data prior to exfiltration using hybrid cryptography based on AES-256 and RSA-4096. Exfiltration has been conducted to attacker-controlled infrastructure themed to resemble legitimate vendors, and some variants include fallback exfiltration by abusing victim GitHub access to create repositories or release assets for staging stolen data. On Linux systems, TeamPCP Cloud Stealer has also been associated with deployment of a Python-based backdoor and persistence via user-level systemd services, including use of hidden directories in the user home path to store components. Some reporting further links related payload chains to follow-on persistence, Kubernetes abuse, and additional malware deployment in downstream compromises.
TeamPCP Cloud Stealer has been deployed through supply-chain attacks against trusted software distribution channels and CI/CD components, including compromised GitHub Actions and malicious Python package releases. It is particularly associated with attacks on cloud-native and developer ecosystems, where access to pipeline secrets can enable cascading compromise of additional repositories, packages, registries, and enterprise SaaS environments. High-confidence reporting consistently characterizes it as a purpose-built cloud and CI/CD credential stealer used to harvest secrets at scale from Linux-based runners and other developer infrastructure.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The payload design was consistent across all three targets... The malware was self-attributed in its string table: "TeamPCP Cloud stealer."
Their malware consistently self-identifies through an embedded string, “TeamPCP Cloud stealer,” which has become one of the clearest attribution markers across all campaign phases.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
TeamPCP Cloud Stealer can create a hidden directory in the user's home folder on Linux hosts to write a python backdoor.
When the infected software runs, the TeamPCP Cloud Stealer searches the system memory and files for digital master keys that allow access to a company’s servers. It specifically hunts for Kubernetes tokens and Solana cryptocurrency wallets.
The malware self-identifies as TeamPCP Cloud stealer in a Python comment on the final line of the embedded filesystem credential harvester.
35 distinct techniques documented for this family, organized by ATT&CK tactic.
attackers used the residual service account token to force-push 76 of 77 version tags in the aquasecurity/trivy-action repository
The threat actor known as TeamPCP orchestrated a four-wave supply chain campaign between March 19–24, 2026, compromising Trivy, Checkmarx KICS/AST GitHub Actions, and LiteLLM.
Version 1 - Monolithic Architecture : A 150-line bash script focused on environment fingerprinting and immediate credential harvesting...
Version 1 - Monolithic Architecture : A 150-line bash script focused on environment fingerprinting and immediate credential harvesting...
it executes a base64-encoded Python filesystem harvester signed "TeamPCP Cloud stealer"
The stealer performed memory scraping of /proc/*/mem to dump the Runner.Worker process
On March 19, during the active compromise window, the Commission's pipeline executed the malicious Trivy release and exfiltrated an AWS API key carrying management rights over multiple Commission AWS accounts.
The attack uses WAV steganography to hide encrypted second-stage payloads within valid audio files, allowing the malware to bypass network filters while establishing persistence
the malware exfiltrated stolen data to the vendor-themed typosquat domain checkmarx[.]zone .
The stealer performed memory scraping of /proc/*/mem to dump the Runner.Worker process
attackers used the residual service account token to force-push 76 of 77 version tags in the aquasecurity/trivy-action repository
The content repeatedly describes malware and threat actors creating hidden folders, adding dot prefixes to filenames, and setting file attributes such as hidden/system to conceal files and directories from users and defenders.
TeamPCP Cloud Stealer, a purpose-built payload designed for CI/CD runner environments that dumped process memory from the GitHub Actions runner, swept SSH keys, cloud provider credentials, and Kubernetes secrets
Beyond the primary targets, TeamPCP leveraged harvested tokens to infect 48 additional packages.
Stage 1 reads /proc/PID/environ for the current process and any running Runner.Worker , Runner.Listener , runsvc , or run.sh processes. It captures environment variables matching env or ssh in the key name, and if a value points to a file on disk, reads that file too.
It captures environment variables matching env or ssh in the key name, and if a value points to a file on disk, reads that file too.
it executes a base64-encoded Python filesystem harvester ... that reads ... shell history
immediate credential harvesting from AWS/GCP/Azure credentials using the compromised endpoint’s instance metadata service (IMDS).
AADInternals can gather unsecured credentials for Azure AD services, such as Azure AD Connect, from a local machine... Agent Tesla has the ability to extract credentials from configuration or support files... APT33 has used a variety of publicly available tools like LaZagne to gather credentials.
the Python filesystem harvester ... reads SSH keys, cloud credentials, Kubernetes configs, Docker credentials, .env files, terraform state, shell history, database configs, TLS private keys, and cryptocurrency wallets, walking multiple directories up to 6 levels deep
then encrypted and exfiltrated the collected data using AES-256 and RSA-4096 to attacker-controlled servers.
147 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
29 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An information-stealing malware used in a supply-chain attack that infected tens of thousands of devices via the compromised LiteLLM open-source Python library.
A purpose-built stealer for CI/CD runner environments that harvests process memory, SSH keys, cloud credentials, and Kubernetes secrets, encrypts the stolen data, and exfiltrates it to attacker-controlled infrastructure. It also has a fallback exfiltration method using a repository named tpcp-docs inside the victim GitHub organization.
Purpose-built stealer for CI/CD runner environments that harvests process memory, SSH keys, cloud credentials, and Kubernetes secrets, then encrypts and exfiltrates the stolen data; it can fall back to storing secrets in a repository named tpcp-docs inside the victim GitHub organization.
Information-stealing malware delivered via a compromised LiteLLM PyPI package, impacting tens of thousands of devices.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.