# T1567.001 Exfiltration to Code Repository

> As of 2026-10-05, T1567.001 (Exfiltration to Code Repository) appears in 26 tracked threats, first reported 2026-03-24 and most recently 2026-09-30, with linked actors including TeamPCP, Shai-Hulud, APT28; it most often appears alongside T1552.001 (Credentials In Files).

- **Tracked threats:** 26 (16 critical, 9 high)
- **First seen:** 2026-03-24
- **Last seen:** 2026-09-30
- **Threat actors:** 7
- **Detection rules:** 77 (counts only; Blue tier and above)

## Key facts

- **ID:** T1567.001
- **Framework:** MITRE ATT&CK
- **Tactics:** Exfiltration
- **Matrix:** Enterprise
- **Parent:** T1567
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1567/001/

## Activity timeline

T1567.001 first appeared in tracked threats on 2026-03-24 and was most recently reported on 2026-09-30. The busiest month was 2026-08 with 7 reports, and 26 of the 26 threats were reported in the twelve months to 2026-09.

## How adversaries use it

T1567.001 Exfiltration to Code Repository is catalogued by MITRE ATT&CK under the Exfiltration tactic in the Enterprise matrix, as a sub-technique of [T1567 Exfiltration Over Web Service](https://intel.threadlinqs.com/technique/T1567). Threadlinqs maps 26 of 2623 tracked threats (1%) to it; by severity that is 16 critical, 9 high.

Threats that use T1567.001 most often also use [T1552.001 Credentials In Files](https://intel.threadlinqs.com/technique/T1552.001) (23 threats), [T1027 Obfuscated Files or Information](https://intel.threadlinqs.com/technique/T1027) (20 threats), [T1059.007 JavaScript](https://intel.threadlinqs.com/technique/T1059.007) (19 threats), [T1528 Steal Application Access Token](https://intel.threadlinqs.com/technique/T1528) (19 threats), [T1195.002 Compromise Software Supply Chain](https://intel.threadlinqs.com/technique/T1195.002) (18 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

7 tracked threat actors appear in the threats that use T1567.001; the most frequent are [TeamPCP](https://intel.threadlinqs.com/actor/TeamPCP) (17), [Shai-Hulud](https://intel.threadlinqs.com/actor/Shai-Hulud) (3), [APT28](https://intel.threadlinqs.com/actor/APT28) (1), [GlassWorm](https://intel.threadlinqs.com/actor/GlassWorm) (1), [GlassWorm Operators](https://intel.threadlinqs.com/actor/GlassWorm%20Operators) (1).

## Mitigations

MITRE ATT&CK lists 1 mitigation for T1567.001.

- [M1021 Restrict Web-Based Content](https://attack.mitre.org/mitigations/M1021/)

## Data sources

Telemetry that can reveal T1567.001, per MITRE ATT&CK.

- Command — Command Execution
- File — File Access
- Network Traffic — Network Traffic Content, Network Traffic Flow

## Threat actors using it

- [TeamPCP](https://intel.threadlinqs.com/actor/TeamPCP) — 17
- [Shai-Hulud](https://intel.threadlinqs.com/actor/Shai-Hulud) — 3
- [APT28](https://intel.threadlinqs.com/actor/APT28) — 1
- [GlassWorm](https://intel.threadlinqs.com/actor/GlassWorm) — 1
- [GlassWorm Operators](https://intel.threadlinqs.com/actor/GlassWorm%20Operators) — 1
- [Miasma operator](https://intel.threadlinqs.com/actor/Miasma%20operator) — 1
- [Mini Shai-Hulud](https://intel.threadlinqs.com/actor/Mini%20Shai-Hulud) — 1

## Tracked threats

26 tracked threats use T1567.001.

- [Mini Shai-Hulud: Compromised @antv npm Packages Steal Developer and CI/CD Credentials (TeamPCP)](https://intel.threadlinqs.com/threat/TL-2026-2806) — high — 2026-09-30
- [Re-Enabled actions-cool GitHub Actions (issues-helper, maintain-one-comment) Resume Executing Mini…](https://intel.threadlinqs.com/threat/TL-2026-2661) — high — 2026-09-26
- [GemStuffer: AI Agent Swarm Floods RubyGems With 2,000+ Malicious Packages, Achieves RCE via RubyDoc.info…](https://intel.threadlinqs.com/threat/TL-2026-2462) — high — 2026-09-12
- [GemStuffer: OpenAI Autonomous Agents Flood RubyGems With 2,000+ Malicious Packages, Abuse RubyDoc.info Build…](https://intel.threadlinqs.com/threat/TL-2026-2458) — high — 2026-09-12
- [Open-Source Supply Chain Poisoning Campaigns Drive CrowdStrike Endpoint-Based Package Interception](https://intel.threadlinqs.com/threat/TL-2026-2294) — high — 2026-09-02
- [npm Supply-Chain Compromise: @7nohe/openapi-react-query-codegen Ships "Trinitite" Credential-Harvesting Worm](https://intel.threadlinqs.com/threat/TL-2026-2193) — critical — 2026-08-28
- [Shai-Hulud npm Supply-Chain Worm: Two Alleged TeamPCP Members Charged by AFP/FBI](https://intel.threadlinqs.com/threat/TL-2026-2186) — critical — 2026-08-28
- [StepSecurity Dev Machine Guard adds fleet-wide developer credential inventory to close blind spot exploited…](https://intel.threadlinqs.com/threat/TL-2026-2160) — 2026-08-25
- [GitHub Actions Supply Chain Attack: tj-actions & reviewdog Compromise (CVE-2025-30066, CVE-2025-30154)](https://intel.threadlinqs.com/threat/TL-2026-2130) — critical — 2026-08-24
- ['ChainDrop' self-propagating worm compromises hundreds of popular npm packages (keyv, cacheable ecosystem)…](https://intel.threadlinqs.com/threat/TL-2026-2822) — critical — 2026-08-04
- [ChainDrop npm Supply-Chain Compromise: Self-Propagating Mini Shai-Hulud Credential-Stealing Worm Affecting…](https://intel.threadlinqs.com/threat/TL-2026-1875) — critical — 2026-08-04
- [Keyv and Cacheable npm Supply Chain Attack via Compromised Maintainer Account (Shai-Hulud Malware)](https://intel.threadlinqs.com/threat/TL-2026-1861) — critical — 2026-08-04
- [GTIG: Threat Actor Usage of AI Tools — 'Just-in-Time' AI-Enabled Malware (PROMPTFLUX, PROMPTSTEAL/LAMEHUG…](https://intel.threadlinqs.com/threat/TL-2026-1508) — high — 2026-07-19
- [Miasma Worm Compromises 73 Microsoft GitHub Repositories Across Azure, Azure-Samples, Microsoft &…](https://intel.threadlinqs.com/threat/TL-2026-0719) — critical — 2026-06-08
- [Shai-Hulud "Hades" Miasma Worm — New PyPI Wave: 37 Malicious Wheels Across 19 Packages Abuse *-setup.pth…](https://intel.threadlinqs.com/threat/TL-2026-0709) — critical — 2026-06-07
- [TrapDoor Crypto Stealer Supply Chain Campaign — 34 Malicious Packages Across npm, PyPI, and Crates.io with…](https://intel.threadlinqs.com/threat/TL-2026-0576) — critical — 2026-05-24
- [Nx Console VS Code Extension Backdoored (v18.95.0) — TeamPCP Mini Shai-Hulud Pivot from TanStack npm Worm to…](https://intel.threadlinqs.com/threat/TL-2026-0547) — critical — 2026-05-21
- [Backdoored Cemu v2.6 GitHub Release — TeamPCP Supply Chain Campaign Extends to Cemu Nintendo Wii U Emulator…](https://intel.threadlinqs.com/threat/TL-2026-0515) — high — 2026-05-14
- [GemStuffer Campaign — RubyGems Registry Abused as Exfiltration Channel for UK Local Government Data](https://intel.threadlinqs.com/threat/TL-2026-0505) — high — 2026-05-13
- [Mini Shai-Hulud Resurfaces — intercom-client@7.0.4 npm Worm Harvesting GitHub & Cloud Credentials (TeamPCP)](https://intel.threadlinqs.com/threat/TL-2026-0446) — critical — 2026-04-30
- [SAP CAP & Cloud MTA npm Packages Compromised — Mini Shai-Hulud (TeamPCP) Bun-Based Credential Stealer](https://intel.threadlinqs.com/threat/TL-2026-0439) — critical — 2026-04-30
- [Bitwarden CLI npm Supply Chain Compromise (@bitwarden/cli v2026.4.0) — Shai-Hulud: The Third Coming / TeamPCP](https://intel.threadlinqs.com/threat/TL-2026-0429) — critical — 2026-04-27
- [Coordinated supply chain attacks on Checkmarx and Bitwarden developer tools sharing audit.checkmarx.cx C2…](https://intel.threadlinqs.com/threat/TL-2026-0424) — high — 2026-04-25
- [GlassWorm v2 — 73 Open VSX Sleeper Extensions Activate Supply Chain Malware Against VS Code, Cursor…](https://intel.threadlinqs.com/threat/TL-2026-0421) — critical — 2026-04-24
- [TeamPCP LiteLLM Supply Chain Attack — Trojaned PyPI Packages (v1.82.7/1.82.8) with Multi-Stage C2 Payload](https://intel.threadlinqs.com/threat/TL-2026-0304) — critical — 2026-03-31
- [TeamPCP Supply Chain Campaign: LiteLLM PyPI Compromise, CanisterWorm npm Propagation, and Multi-Ecosystem…](https://intel.threadlinqs.com/threat/TL-2026-0279) — critical — 2026-03-24

## Related CVEs

CVEs referenced by the tracked threats that use T1567.001, most frequent first.

- [CVE-2026-33634](https://intel.threadlinqs.com/cve/CVE-2026-33634)
- [CVE-2026-45321](https://intel.threadlinqs.com/cve/CVE-2026-45321)
- [CVE-2026-48027](https://intel.threadlinqs.com/cve/CVE-2026-48027)
- [CVE-2023-48022](https://intel.threadlinqs.com/cve/CVE-2023-48022)
- [CVE-2025-29927](https://intel.threadlinqs.com/cve/CVE-2025-29927)
- [CVE-2025-30066](https://intel.threadlinqs.com/cve/CVE-2025-30066)
- [CVE-2025-30154](https://intel.threadlinqs.com/cve/CVE-2025-30154)
- [CVE-2025-55182](https://intel.threadlinqs.com/cve/CVE-2025-55182)

## Detection coverage

Threadlinqs maintains 77 detection rules mapped to T1567.001 (SPL 24, KQL 27, Sigma 25, other 1). Rule content is available to Blue tier accounts and above; this page shows counts only.

77 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Parent technique

[T1567 Exfiltration Over Web Service](https://intel.threadlinqs.com/technique/T1567) — 572 tracked threats at the technique level.

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1567.001
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
