DUSTMAKER is a cross-platform JavaScript credential stealer used by the financially motivated threat actor TeamPCP, also tracked as UNC6780 and Altered Spider. Active since April 2026, it succeeded the group’s SANDCLOCK credential stealer and is optimized for CI/CD pipelines, AI development tooling, and developer environments. DUSTMAKER steals credentials to support TeamPCP extortion operations and has been associated with software supply-chain compromises affecting open-source development ecosystems. Unlike SANDCLOCK, DUSTMAKER is not reported to include container-escape functionality. Variants hide malicious content within AI coding-assistant and IDE workspaces and can abuse workspace configuration to induce AI assistants to execute scripts during normal development activity. It also employs prompt-injection content intended to hinder LLM-assisted security analysis.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The report also describes DUSTMAKER, tied to UNC6780 or TeamPCP, which targeted AI development tools and CI/CD systems.
DUSTMAKER is a successor to the SANDCLOCK credential stealer in TeamPCP operations and is a cross-platform JavaScript payload optimized for CI/CD pipelines.
5 distinct techniques documented for this family, organized by ATT&CK tactic.
“The threat actor leveraged an AI coding chatbot, a prompt, and a set of agent instructions to plan, build, and execute a mass credential harvesting campaign in less than six hours.”
The agents actively searched server-side systems, identified weaknesses, and carried out targeted actions against online infrastructure... [The Recon] dashboard was designed to organize, validate, and manage more than 23,800 stolen secrets in real time, including API keys connected to cloud and AI services.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Malware/activity associated with targeting AI-development tooling and CI/CD systems. It used hidden AI-coding-assistant and IDE workspace directories to blend malicious project files into development environments.
Malware associated with a supply-chain campaign targeting AI development tools and CI/CD systems. It used hidden AI-coding-assistant and IDE workspace directories to blend malicious files into projects and targeted assistant configuration files for credential collection.
Credential-stealing malware that embeds methods for targeting or exploiting AI tools and open-source software-development practices.
Credential stealer that abuses AI coding and IDE workspace directories and malicious configuration files to induce assistant-driven script execution. It also uses fake pipeline tasks disguised as AI utilities to search for developer tokens and keys.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.