SANDCLOCK is a credential-stealing malware payload used by the financially motivated threat group TeamPCP, which Google tracks as UNC6780. The malware was deployed in large-scale software supply chain compromises involving poisoned GitHub Actions and trojanized packages associated with projects including Trivy, Checkmarx, LiteLLM, and the Telnyx Python SDK, with targeting focused on developer environments, CI/CD pipelines, cloud infrastructure, and security workflows. Across the reporting, SANDCLOCK is described as extracting AWS credentials, Kubernetes ServiceAccount tokens, local environment variables, GitHub tokens, and cryptocurrency wallet data from build and developer environments. The stolen credentials were used to facilitate follow-on extortion and ransomware monetization, and reporting states TeamPCP collaborated with other threat actors to monetize stolen data and maintain access to victim environments. High-confidence campaign context ties SANDCLOCK to broader TeamPCP operations that stole cloud credentials, API keys, SSH keys, and Kubernetes secrets via malicious code injected into legitimate packages. No standalone file hashes specific to SANDCLOCK are provided in the content, but the campaign-level indicators associated with TeamPCP include domains such as scan.aquasecurtiy[.]org, checkmarx[.]zone, models.litellm[.]cloud, check.git-service[.]com, git-tanstack[.]com, recv.hackmoltrepeat[.]com, and audit.checkmarx[.]cx/v1/telemetry, as well as IPs 83.142.209.11, 45.148.10.212, 83.142.209.194, 83.142.209.203, 94.154.172.43, and 67.217.57.240.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The four CVEs associated with this campaign are CVE-2026-33634, CVE-2026-48027, CVE-2026-45321, and CVE-2025-55182.
The four CVEs associated with this campaign are CVE-2026-33634, CVE-2026-48027, CVE-2026-45321, and CVE-2025-55182.
The four CVEs associated with this campaign are CVE-2026-33634, CVE-2026-48027, CVE-2026-45321, and CVE-2025-55182.
The four CVEs associated with this campaign are CVE-2026-33634, CVE-2026-48027, CVE-2026-45321, and CVE-2025-55182.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
By injecting malicious code into legitimate packages, the group deployed credential stealers, persistent backdoors, and self-propagating malware such as CanisterWorm, SANDCLOCK, Mini Shai-Hulud, and Miasma to steal cloud credentials, API keys, SSH keys, and Kubernetes secrets.
18 distinct techniques documented for this family, organized by ATT&CK tactic.
threat actors leveraged credentials stolen through the Trivy supply chain compromise... to breach Cisco's internal development environment.
designed to harvest sensitive information, including cloud access tokens, credentials, API keys, and other authentication material associated with services such as Amazon Web Services (AWS), Google Cloud Platform (GCP), and Microsoft Azure.
The attackers gained access to build systems and developer workstations through a malicious GitHub Action plugin.
TeamPCP is a financially motivated cybercriminal group responsible for large-scale software supply chain attacks targeting trusted developer and security tools, including Trivy, KICS, LiteLLM, and the Telnyx Python SDK. By injecting malicious code into legitimate packages...
This allowed the threat actors to push trojanized updates that appeared normal but secretly installed credential-stealing malware and persistent backdoors.
threat actors leveraged credentials stolen through the Trivy supply chain compromise... to breach Cisco's internal development environment.
CanisterWorm: designed to harvest sensitive information, including cloud access tokens, credentials, API keys, and other authentication material associated with services such as Amazon Web Services (AWS), Google Cloud Platform (GCP), and Microsoft Azure.
extracting sensitive data, including but not limited to cloud access tokens, SSH keys, and Kubernetes secrets
SANDCLOCK: a credential stealing tool used by TeamPCP that extracts AWS credentials, Kubernetes ServiceAccount tokens, local environment variables, and cryptocurrency wallet data.
The payload swept AWS credentials, Google Cloud configurations, Kubernetes tokens, environment variables, SSH keys, API keys, and database credentials... The malicious payload ... exfiltrated GitHub tokens, npm tokens, SSH material, AWS/GCP/Azure secrets, GitHub Actions secrets, and AI tooling configuration files.
CERT-EU revealed that the threat actors used the stolen AWS secret to exfiltrate data from the Commission's cloud environment. This included data relating to websites hosted for up to 71 clients of the Europa web hosting service and outbound email communications.
The malicious payload contained the string "Shai-Hulud: The Third Coming" ... and exfiltrated GitHub tokens, npm tokens, SSH material, AWS/GCP/Azure secrets, GitHub Actions secrets, and AI tooling configuration files to public GitHub repositories created under victim accounts.
43 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
18 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Malware used in TeamPCP supply chain compromises as part of credential theft and persistent access operations.
Credential and data stealing malware that extracts AWS credentials, Kubernetes service account tokens, environment variables, and cryptocurrency wallet data.
Credential and data stealer that extracts AWS credentials, Kubernetes ServiceAccount tokens, local environment variables, and cryptocurrency wallet data.
A credential stealer used in software supply chain compromises to extract AWS keys and GitHub tokens from build environments.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.