Activity timeline
T1567.001 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-08 with 7 reports, and 26 of the 26 threats were reported in the twelve months to 2026-09.
How adversaries use it
T1567.001 Exfiltration to Code Repository is catalogued by MITRE ATT&CK under the Exfiltration tactic in the Enterprise matrix, as a sub-technique of T1567 Exfiltration Over Web Service. Threadlinqs maps 26 of 2623 tracked threats (1%) to it; by severity that is 16 critical, 9 high.
Threats that use T1567.001 most often also use T1552.001 Credentials In Files (23 threats), T1027 Obfuscated Files or Information (20 threats), T1059.007 JavaScript (19 threats), T1528 Steal Application Access Token (19 threats), T1195.002 Compromise Software Supply Chain (18 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.
7 tracked threat actors appear in the threats that use T1567.001; the most frequent are TeamPCP (17), Shai-Hulud (3), APT28 (1), GlassWorm (1), GlassWorm Operators (1).
Mitigations
MITRE ATT&CK lists 1 mitigation for T1567.001.
Data sources
Telemetry that can reveal T1567.001, per MITRE ATT&CK.
- Command — Command Execution
- File — File Access
- Network Traffic — Network Traffic Content, Network Traffic Flow
Threat actors using it
Tracked threats
26 tracked threats use T1567.001.
- Mini Shai-Hulud: Compromised @antv npm Packages Steal Developer and CI/CD Credentials (TeamPCP)high
- Re-Enabled actions-cool GitHub Actions (issues-helper, maintain-one-comment) Resume Executing Mini…high
- GemStuffer: AI Agent Swarm Floods RubyGems With 2,000+ Malicious Packages, Achieves RCE via RubyDoc.info…high
- GemStuffer: OpenAI Autonomous Agents Flood RubyGems With 2,000+ Malicious Packages, Abuse RubyDoc.info Build…high
- Open-Source Supply Chain Poisoning Campaigns Drive CrowdStrike Endpoint-Based Package Interceptionhigh
- npm Supply-Chain Compromise: @7nohe/openapi-react-query-codegen Ships "Trinitite" Credential-Harvesting Wormcritical
- Shai-Hulud npm Supply-Chain Worm: Two Alleged TeamPCP Members Charged by AFP/FBIcritical
- StepSecurity Dev Machine Guard adds fleet-wide developer credential inventory to close blind spot exploited…
- GitHub Actions Supply Chain Attack: tj-actions & reviewdog Compromise (CVE-2025-30066, CVE-2025-30154)critical
- 'ChainDrop' self-propagating worm compromises hundreds of popular npm packages (keyv, cacheable ecosystem)…critical
- ChainDrop npm Supply-Chain Compromise: Self-Propagating Mini Shai-Hulud Credential-Stealing Worm Affecting…critical
- Keyv and Cacheable npm Supply Chain Attack via Compromised Maintainer Account (Shai-Hulud Malware)critical
- GTIG: Threat Actor Usage of AI Tools — 'Just-in-Time' AI-Enabled Malware (PROMPTFLUX, PROMPTSTEAL/LAMEHUG…high
- Miasma Worm Compromises 73 Microsoft GitHub Repositories Across Azure, Azure-Samples, Microsoft &…critical
- Shai-Hulud "Hades" Miasma Worm — New PyPI Wave: 37 Malicious Wheels Across 19 Packages Abuse *-setup.pth…critical
- TrapDoor Crypto Stealer Supply Chain Campaign — 34 Malicious Packages Across npm, PyPI, and Crates.io with…critical
- Nx Console VS Code Extension Backdoored (v18.95.0) — TeamPCP Mini Shai-Hulud Pivot from TanStack npm Worm to…critical
- Backdoored Cemu v2.6 GitHub Release — TeamPCP Supply Chain Campaign Extends to Cemu Nintendo Wii U Emulator…high
- GemStuffer Campaign — RubyGems Registry Abused as Exfiltration Channel for UK Local Government Datahigh
- Mini Shai-Hulud Resurfaces — intercom-client@7.0.4 npm Worm Harvesting GitHub & Cloud Credentials (TeamPCP)critical
- SAP CAP & Cloud MTA npm Packages Compromised — Mini Shai-Hulud (TeamPCP) Bun-Based Credential Stealercritical
- Bitwarden CLI npm Supply Chain Compromise (@bitwarden/cli v2026.4.0) — Shai-Hulud: The Third Coming / TeamPCPcritical
- Coordinated supply chain attacks on Checkmarx and Bitwarden developer tools sharing audit.checkmarx.cx C2…high
- GlassWorm v2 — 73 Open VSX Sleeper Extensions Activate Supply Chain Malware Against VS Code, Cursor…critical
- TeamPCP LiteLLM Supply Chain Attack — Trojaned PyPI Packages (v1.82.7/1.82.8) with Multi-Stage C2 Payloadcritical
- TeamPCP Supply Chain Campaign: LiteLLM PyPI Compromise, CanisterWorm npm Propagation, and Multi-Ecosystem…critical
Detection coverage
Threadlinqs maintains 77 detection rules mapped to T1567.001 (SPL 24, KQL 27, Sigma 25, other 1). Rule content is available to Blue tier accounts and above; this page shows counts only.
Parent technique
T1567 Exfiltration Over Web Service — 572 tracked threats at the technique level.