TeamPCP Cloud Stealer — Malware Profile

The TeamPCP Cloud Stealer is a comprehensive filesystem credential stealer that can harvest, encrypt, and exfiltrate credentials from over 50 sensitive file paths across CI/CD, cloud, developer tooling, and container environments. The TeamPCP Cloud Stealer was the primary payload used by TeamPCP in March 2026 during early stages of a cascading supply chain campaign targeting CI/CD workflows.

MITRE ATT&CK techniques (47)

IntelFusions coverage

Attributed threat actors

Read the full analysis on IntelFusions