Gold Open Source
ExplorePackagesVulnerabilitiesCWEsMCP ServersScan
Login
Gold Open Source

The authoritative source for production-ready open-source components. Every package, container image, AI model, and MCP server undergoes rigorous verification for security, malware, and license compliance.

Explore Gold

  • Explore Everything
  • Packages
  • Gold Certified Packages
  • Container Images
  • AI Models
  • MCP Servers
  • Agent Skills
  • Chip Manufacturers

Security Data & Tools

  • Scan Your Dependencies
  • Trending Threats
  • Threat RSS Feeds
  • CVE Database
  • Actively Exploited (KEV)
  • SGZ Zero-Days
  • CWE Index
  • MITRE ATT&CK
  • Malicious Packages
  • Security Glossary
  • Supply-Chain Report
  • Developers (API & Badge)
  • Chrome Extension
  • Credits & Data Sources

Products

  • The Platform
  • ESSCM
  • Portal
  • TPRM
  • OSM
  • Cowork
  • Code / Runner
  • Guard

Use Cases

  • Know Your Software
  • Auto-Fix Vulnerabilities
  • Asset Discovery
  • AI Governance
  • MCP Server Security
  • Supply Chain Compliance
  • Zero-Day Discovery
  • All Use Cases

Company

  • About
  • Pricing
  • Blog
  • Documentation
  • Safeguard Academy
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 Gold Open Source. All rights reserved.

Built with care bySafeguard
Home/ATT&CK/Software/S9041
MITRE ATT&CK Malware

TeamPCP Cloud Stealer (S9041)

SANDCLOCK
ShareXLinkedInRedditHN

The [TeamPCP Cloud Stealer](https://attack.mitre.org/software/S9041) is a comprehensive filesystem credential stealer that can harvest, encrypt, and exfiltrate credentials from over 50 sensitive file paths across CI/CD, cloud, developer tooling, and container environments. The [TeamPCP Cloud Stealer](https://attack.mitre.org/software/S9041) was the primary payload used by [TeamPCP](https://attack.mitre.org/groups/G1056) in March 2026 during early stages of a cascading supply chain campaign targeting CI/CD workflows.(Citation: Wiz Trivy Compromise MAR 2026)(Citation: Aqua Security Trivy Compromise MAR 2026)(Citation: Aqua Security Blog Trivy Compromise APR 2026)(Citation: Sysdig TeamPCP MAR 2026)(Citation: Wiz TeamPCP KICS MAR 2026)(Citation: Palo Alto TeamPCP MAR 2026)(Citation: Google AI Threat Tracker MAY 2026)(Citation: FBI TeamPCP JUL 2026)

Platforms: Containers, Linux, macOS, SaaS, Windows

▪Techniques implemented (47)

T1020Automated ExfiltrationT1548.003Sudo and Sudo CachingT1140Deobfuscate/Decode Files or InformationT1552.003Shell HistoryT1119Automated CollectionT1657Financial TheftT1213.003Code RepositoriesT1033System Owner/User DiscoveryT1016System Network Configuration DiscoveryT1213.006DatabasesT1609Container Administration CommandT1070.004File DeletionT1049System Network Connections DiscoveryT1041Exfiltration Over C2 ChannelT1526Cloud Service DiscoveryT1580Cloud Infrastructure DiscoveryT1057Process DiscoveryT1083File and Directory DiscoveryT1573.001Symmetric CryptographyT1573.002Asymmetric CryptographyT1560.001Archive via UtilityT1564.001Hidden Files and DirectoriesT1543.002Systemd ServiceT1036.005Match Legitimate Resource Name or LocationT1003.007Proc FilesystemT1552.007Container APIT1105Ingress Tool TransferT1546.016Installer PackagesT1567.001Exfiltration to Code RepositoryT1059.007JavaScriptT1027.013Encrypted/Encoded FileT1071.001Web ProtocolsT1546.018Python Startup HooksT1528Steal Application Access TokenT1555Credentials from Password StoresT1059.006PythonT1613Container and Resource DiscoveryT1518Software DiscoveryT1008Fallback ChannelsT1555.006Cloud Secrets Management StoresT1059.004Unix ShellT1552.001Credentials In FilesT1480Execution GuardrailsT1082System Information DiscoveryT1552.004Private KeysT1074.001Local Data StagingT1678Delay Execution

▪Used by groups (1)

G1056TeamPCP
S9041on MITRE ATT&CK →

MITRE ATT&CK® is a registered trademark of The MITRE Corporation. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation.