StepSecurity Dev Machine Guard adds fleet-wide developer credential inventory to close blind spot exploited by supply-chain attacks — Threadlinqs Intelligence
As of 2026-08-26, StepSecurity Dev Machine Guard adds fleet-wide developer credential inventory to close blind spot exploited by supply-chain attacks is a info-severity threat intel threat attributed to TeamPCP, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 20 indicators of compromise.
Threat ID: TL-2026-2160 · Severity: INFO · Status: ACTIVE · Category: THREAT_INTEL
Attribution: TeamPCP · FINANCIAL
StepSecurity's Dev Machine Guard agent v1.16.0 (August 25, 2026) adds fleet-wide inventory of thirteen developer-credential source types (AWS, GitHub, SSH, git-credentials, npm, PyPI, Docker, Vault,
On August 25, 2026, StepSecurity shipped Dev Machine Guard agent v1.16.0, extending its developer-endpoint monitoring product with a credential-location inventory capability. The feature enumerates thirteen credential source types across cloud (AWS credentials/config, gcloud application-default credentials), source control (GitHub tokens, git-credentials, SSH keys), package registries (npm .npmrc, Python .pypirc), containers (Docker config), and infrastructure tooling (Vault tokens, kubeconfig, netrc) in both default and relocated file locations. For each device it records file existence, quantity of material present, and — for SSH keys specifically — whether the private key is passphrase-protected, while explicitly never serializing, logging, storing, displaying, or exfiltrating credential values, fragments, hashes, digests, fingerprints, or parser output.
The vendor grounds the release in a real and still-unfolding attacker technique class: systematic enumeration and harvesting of exactly these credential storage locations across developer machines and CI/CD runners, as demonstrated in a cluster of April 2026 open-source supply-chain compromises attributed with varying confidence to TeamPCP (tracked by Google's Threat Intelligence Group as UNC6780, credential stealer 'SANDCLOCK'). On April 22, 2026, three concurrent compromises hit npm, PyPI, and Docker Hub within roughly 48 hours: the xinference PyPI package (versions 2.6.0-2.6.2) shipped a two-stage credential stealer injected into its top-level __init__.py that executed on every import; the official @bitwarden/cli npm package (version 2026.4.0) was briefly republished with a Bun-runtime-staged, AI-tool-aware credential stealer after a Bitwarden engineer's GitHub account was compromised and the npm publish workflow was rewritten to abuse OIDC Trusted Publishing; and the checkmarx/kics Docker Hub image was overwritten with a build that both exfiltrated IaC scan output and delivered a secondary payload via trojanized VS Code extensions. Analysis published by SANS ISC (the 'Update 008' campaign diary) further ties these events to a cascading failure — Bitwarden's own Dependabot automation pulled the poisoned checkmarx/kics image, propagating the compromise into the CLI release — and to a parallel npm worm ('CanisterSprawl') first identified April 21 across multiple publisher namespaces, which self-propagates via postinstall hooks and can pivot from npm to PyPI when it finds a PyPI publish token on an infected host.
No CVE has been assigned to any of the referenced package/image compromises; this record documents a defensive-tooling release, not a vulnerability. It is included because the vendor's stated rationale — closing the visibility gap that active supply-chain campaigns already exploit to enumerate developer-credential storage — maps directly onto SOC detection and hunting priorities for credential-theft TTPs on developer endpoints, and the underlying incidents provide concrete, sourced attacker TTPs, IOCs, and file paths that defenders can hunt for independent of whether they adopt this specific tool.
Weaknesses (CWE)
CWE-522, CWE-829, CWE-494
Target sectors: technology, software development, cloud infrastructure, devops ci-cd
Target regions: Global
Timeline
- TeamPCP-linked litellm PyPI package compromise, part of the same actor's earlier campaign activity.
- Telnyx PyPI compromise disclosed; the TeamPCP campaign then enters an approximately 26-day pause characterized as a credential-monetization phase.
- CanisterSprawl npm worm first identified across at least 16 malicious package versions spanning the @automagik, pgserve, @fairwords, and @openwebconcept publisher namespaces.
- At 12:35 UTC, attackers use valid Checkmarx credentials to push malicious checkmarx/kics Docker Hub images (overwriting 5 tags, adding 2 new ones) for an approximately 84-minute window, exfiltrating IaC scan output to audit.checkmarx.cx and delivering a secondary payload via trojanized VS Code extensions.
- Bitwarden's Dependabot automation pulls the poisoned checkmarx/kics image during the compromise window; @bitwarden/cli 2026.4.0 is published to npm between 5:57 PM and 7:30 PM ET with a Bun-staged credential stealer, reaching roughly 334 downloads before removal.
- xinference PyPI versions 2.6.0, 2.6.1, and 2.6.2 are published in a single day, each carrying a base64-encoded two-stage credential stealer marked '# hacked by teampcp' in xinference/__init__.py.
- SANS ISC publishes 'Update 008,' consolidating the Checkmarx KICS, Bitwarden CLI, and xinference compromises plus the CanisterSprawl npm worm into a single campaign narrative and attributing the operators to Google GTIG's UNC6780 (credential stealer SANDCLOCK).
- StepSecurity ships Dev Machine Guard agent v1.16.0, adding fleet-wide inventory of the thirteen developer-credential source types targeted in the April 2026 campaign, explicitly citing TeamPCP/xinference and the hijacked Bitwarden CLI as motivating incidents.
Detections & IOCs
As of 2026-09-06, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 20 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
Community OSINT corroboration
3 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.
THREAT_INTEL, INFO, threat intelligence, cybersecurity, T1583.001, T1195.001, T1195.002, T1078.004, T1059.006, T1059.007, T1027, T1036.005, T1552.001, T1552.005