TeamPCP Python Toolkit Uses FIRESCALE and Victim GitHub Accounts to Survive C2 Disruption

Summary
Hunt IO analyzes TeamPCP’s 13-file Python toolkit, detailing its credential theft, layered exfiltration through C2 and GitHub, conditional wiper, and newly identified infrastructure.
Key points
- The toolkit arrives as a second-stage payload linked to trojanized npm and PyPI packages. It exits on non-Linux systems, Russian locales, and machines with four or fewer CPU cores.
- Its hardcoded primary C2 is 83.142.209[.]194. If unreachable, FIRESCALE searches public GitHub commits for a server URL authenticated with an embedded RSA key.
- If network exfiltration fails, the malware can use a stolen GitHub token to create a public repository under the victim’s account and upload collected credentials.
- Collection spans more than 90 file targets and includes environment variables, SSH data, Docker container variables, password managers, and credentials and secrets across AWS, Azure, GCP, Kubernetes, and Vault.
- The toolkit establishes persistence before collection. On systems identified as Israeli or Iranian, a 1-in-6 probability gate may trigger audio playback and deletion of accessible files.
- An HTTP-header fingerprint linked the primary C2 to 35.192.220[.]222 on Google Cloud. Three certificate-associated addresses were flagged as leads, not confirmed actor-controlled infrastructure.
Article Details
- Attack Vectors
- Trojanized npm and PyPI packages deliver a second-stage, modular Python toolkit to developer machines.
- The dropper runs only on Linux, exits on Russian-language locales, and rejects processors with four or fewer cores.
- Collectors harvest credential files, environment variables, SSH material, dotenv files, Terraform state, running-container environments, password-manager entries, and accessible cloud secrets.
- Exfiltration proceeds through a hardcoded primary server, a cryptographically verified GitHub commit-message redirect, or a public repository created with the victim's stolen GitHub token.
- An operator-supplied payload establishes persistence before credential collection and can trigger destructive behavior on systems classified as Israeli or Iranian.
- Defensive Notes
- Blocking the primary server alone does not prevent exfiltration because the toolkit has two additional fallback paths.
- Monitor GitHub commit-search requests containing FIRESCALE and unexpected public-repository creation, credential JSON uploads, and repository cleanup under developer accounts.
- Hunt for the pgsql-monitor.service unit, pgmonitor.py persistence payload, and unexpected credential-file access.
- Review cloud identity permissions: collectors enumerate secrets across every subscription, project, vault, or region accessible to the compromised identity.
- The AWS Parameter Store collector may fail because its request signer incorrectly retains the Secrets Manager service identifier; the article says Secrets Manager collection is unaffected.
- A single sandbox execution can miss the wiper because destruction requires geographic checks, a 1-in-6 random outcome, available audio utilities, and a responding primary server.
- Client certificates are loaded into RAM-backed file objects without filesystem writes, so credential-file creation monitoring and disk-based recovery may miss this activity.
- Investigate the three certificate-linked cloud addresses as unconfirmed leads, not confirmed actor-controlled infrastructure.
- Historical telemetry from November 2025 may expose infrastructure activity preceding the March 2026 supply-chain activity.
Indicators of compromise
| Type | Indicator | Context |
|---|---|---|
| IPV4 | 136[.]115[.]211[.]254 | Unconfirmed infrastructure lead linked to the suspected cloud C2 through TLS certificate relationships; actor control is not established. |
| IPV4 | 34[.]66[.]134[.]145 | Unconfirmed infrastructure lead linked to the suspected cloud C2 through TLS certificate relationships; actor control is not established. |
| IPV4 | 35[.]188[.]190[.]218 | Unconfirmed infrastructure lead linked to the suspected cloud C2 through a distinct TLS certificate; actor control is not established. |
| IPV4 | 35[.]192[.]220[.]222 | Suspected additional or backup C2 identified through an HTTP header fingerprint matching the primary C2; observed during April 2026. |
| IPV4 | 83[.]142[.]209[.]11 | Reported TeamPCP C2 with AdaptixC2 observed on port 2222. |
| IPV4 | 83[.]142[.]209[.]194 | Hardcoded primary C2 used for operator tasking, credential exfiltration, and wiper audio delivery. |
| IPV4 | 83[.]142[.]209[.]203 | Reported TeamPCP C2 associated with a poisoned Xinference package. |
| SHA256 | 03cdeb175f6f3d79aeca171841f83d10fff83143b2bc61a22c15f1ccfe484f27 | Toolkit AWS collector targeting Secrets Manager and SSM across 19 regions and all configured profiles. |
| SHA256 | 0eb70f94b82aa24ae8f69d6644f17ca1173b1318a0d30af142d8f76a5175aa49 | Toolkit Vault collector supporting environment variables, token files, AppRole, and CLI authentication. |
| SHA256 | 3b48fb6375ca66dba4b38c001a635b53a4e9ebee233a4ff3ac6352674f4ddc38 | Toolkit SigV4 request-signing component with the hardcoded Secrets Manager header defect. |
| SHA256 | 4c37f2239888b689d67a193bbd7864d33641c9343574412470b4f882aefbff5c | Toolkit cloud collector supporting service account credentials, refresh tokens, and instance metadata authentication. |
| SHA256 | 50d88c81cac859cb0f446a30229b64336ef4f682a1ed12e1f4cfa03758d57042 | Toolkit collector for local files, environment variables, SSH, dotenv files, Docker, VPN configurations, and Terraform state. |
| SHA256 | 552b159317005417fe2755ff502e05c618a2f568d646d8aa61edad9e02cf16b1 | Toolkit component implementing orchestration, FIRESCALE, and the exfiltration chain. |
| SHA256 | 630333cc3950387605ad09a528506053e4ff36cee08547b8424958d742a5eac7 | Toolkit password_managers.py component. |
| SHA256 | a3784a1502fbe0546f7195706a40628ec7bbe9825b0f54dd7ab7a8713874d65b | Toolkit persistence, wiper, and audio component. |
| SHA256 | c234e6e5f5366cf1a703e62a995a7a0511583ca703c7c9d0590965342eb4c4e8 | Toolkit dropper component implementing platform, locale, CPU checks, and dependency installation. |
| SHA256 | c93668ea2a7ac2e53e52989c22cdfceea2fbe5262a865b59a3a896c108492d0e | TLS certificate fingerprint associated with two unconfirmed cloud infrastructure leads linked to the suspected additional C2. |
| SHA256 | e3e63c89e8ca0628da5aed9340a9c0e95e6007d60a0217f8017c0e5f5fa95423 | TLS certificate fingerprint linking an unconfirmed cloud infrastructure lead to the suspected additional C2. |
| SHA256 | ec629e05a4e39b589826519254e85582f43376204804963b047db904fb296b2e | Redacted HTTP header fingerprint used to link the primary C2 to a suspected additional cloud C2. |
| SHA256 | ed81603bb88d8060deb46b474a515d49bb71ca0832a3f6d854b4b886bff25842 | Toolkit Kubernetes collector implementing kubeconfig parsing, in-memory certificates, and automatic kubectl download. |
| SHA256 | eeee34f2db5cb3eb5e5877c93e2250d44128c470d24fad38885bbfdab452de09 | Toolkit component implementing parallel collector dispatch. |
| URL | hxxps[:]//83[.]142[.]209[.]194/audio[.]mp3 | C2-hosted audio downloaded before the wiper deletes accessible files. |
| URL | hxxps[:]//83[.]142[.]209[.]194/v1/models | Primary C2 beacon and operator communication endpoint. |
| URL | hxxps[:]//83[.]142[.]209[.]194/v1/weights | Primary C2 credential exfiltration endpoint. |
MITRE ATT&CK
T1005 · Data from Local SystemThe toolkit collects local configuration files, environment variables, SSH material, and project secrets from the compromised machine.T1027 · Obfuscated Files or InformationFIRESCALE commit messages encode the replacement server address and its signature in two base64 segments.T1041 · Exfiltration Over C2 ChannelCompressed and encrypted credential harvests are uploaded to the primary C2 or the server resolved through FIRESCALE.T1059.006 · PythonThe second-stage toolkit executes its collection, exfiltration, persistence, and wiper logic through Python components.T1102.001 · Dead Drop ResolverFIRESCALE searches public GitHub commit messages for a signed replacement server address when the primary C2 is unavailable.T1119 · Automated CollectionAutomatically discovered collector modules run in parallel and merge their harvested results into a single output object.T1129 · Shared ModulesThe orchestrator automatically discovers and loads available Python collection modules at startup.T1195.001 · Compromise Software Dependencies and Development ToolsTrojanized npm and PyPI packages deliver the toolkit to developer machines.T1485 · Data DestructionThe wiper deletes all accessible files after geographic checks, a 1-in-6 probability gate, and successful audio-utility checks.T1497.001 · System ChecksThe dropper checks the platform, locale, and processor core count, exiting on systems with four or fewer cores to avoid analysis environments.T1543.002 · Systemd ServiceThe persistence component installs pgsql-monitor.service with automatic restart, selecting system-level or user-level installation according to privileges.T1552.001 · Credentials In FilesCollectors read cloud credential files, SSH keys, dotenv files, Terraform state, and cached CLI tokens.T1552.007 · Container APIThe local collector connects to the Docker daemon socket to retrieve environment variables from running containers, falling back to the Docker CLI.T1564.006 · Run Virtual InstanceThe Kubernetes collector uses RAM-backed file objects and /proc/self/fd paths to load client certificates without writing certificate bytes to disk.T1567.001 · Exfiltration to Code RepositoryWhen server-based exfiltration fails, stolen GitHub tokens create a public repository under the victim's account and upload credentials as JSON.T1573.002 · Asymmetric CryptographyThe exfiltration pipeline wraps its AES-GCM encryption key with 4096-bit RSA-OAEP so only the operator can recover it.T1580 · Cloud Infrastructure DiscoveryCloud collectors enumerate accessible Azure subscriptions and Key Vaults, GCP projects, and AWS secret stores across configured regions.T1613 · Container and Resource DiscoveryThe local collector enumerates running Docker containers to collect their environment variables.
Threat Actors
Malware
Vendors
Ghosty Networks LLCAll three addresses in the subnet resolve to the same autonomous system: AS205759, operated by Ghosty Networks LLC, registered in Luxembourg. This is a dedicated hosting provider with no legitimate business presence,Googleto a Google Cloud hostname in the googleusercontent.com space, placing it in AS396982 operated by Google LLC in the United States. The matching header fingerprint was active on this address from April 16 to April
Products
1Passworddeveloper tokens, database passwords, and AI coding tool credentialsPassword Manager Traversal: 1Password, Bitwarden, pass, and gopassAWSThe AWS collection module covers all 19 regions in its target list, including us-gov-east-1 and us-gov-west-1.AWS Secrets ManagerFor each credential set found, the module queries both AWS Secrets Manager and AWS Systems Manager Parameter Store across all 19 regions in its target list. Secrets stored in the Parameter Store with encryption enabledAWS Systems Manager Parameter StoreFor each credential set found, the module queries both AWS Secrets Manager and AWS Systems Manager Parameter Store across all 19 regions in its target list. Secrets stored in the Parameter Store with encryption enabledAzureThe Azure collection module attempts to obtain an access token through four different paths, tried in priority order. The first path looks for client credentials in environment variables. If those are absent, the secondAzure CLIauthentication assertion. If neither succeeds, the third path reads cached tokens directly from the Azure CLI's on-disk token store without making any outbound network call to Azure. The fourth path, used on AzureBitwardentokens, database passwords, and AI coding tool credentialsPassword Manager Traversal: 1Password, Bitwarden, pass, and gopassClaude Desktoppasswords, CI/CD secrets, VPN configs, and credential files for eight AI coding tools, including Claude Desktop, Cursor, VS Code, Codeium, Continue, Zed, Opencode, and Kilo, the module performs four additionalCodeiumVPN configs, and credential files for eight AI coding tools, including Claude Desktop, Cursor, VS Code, Codeium, Continue, Zed, Opencode, and Kilo, the module performs four additional operations that expand theContinuethe malware attempts to reach this address first. A successful connection allows normal execution to continue. If the server is unavailable for any reason, whether due to IP blocking, infrastructure takedown, or aCursorCI/CD secrets, VPN configs, and credential files for eight AI coding tools, including Claude Desktop, Cursor, VS Code, Codeium, Continue, Zed, Opencode, and Kilo, the module performs four additional operations thatDockerSSH keys and config, walks the entire home directory for dotenv files, and pulls credentials from running Docker containers.EC2are configured simultaneously. Environment variables are also checked, and a fallback path queries the EC2 instance metadata service for machines running inside AWS with attached IAM roles.GCPThe GCP collection module covers three authentication scenarios without using any Google-provided libraries. For service account key files, the module constructs and signs a cryptographic assertion using only standardGitHubWhen the primary C2 is unavailable, the malware searches all public GitHub commit messages worldwide for a signed alternative server URL, verified against an embedded 4096-bit RSA key.GitHub CLIThe local collection module targets the GitHub CLI's credential store and several environment variables commonly used to hold GitHub personal access tokens. If the GitHub CLI is installed and has an active authenticatedGoogle Cloudthe stored refresh token and exchanges it directly. For virtual machines and containers running on Google Cloud infrastructure, the module queries the instance metadata server, which provides a service accountGoogle Cloud Secret ManagerOnce authenticated, the module retrieves all secrets from Google Cloud Secret Manager for every project the resolved identity has permission to access.gopasspasswords, and AI coding tool credentialsPassword Manager Traversal: 1Password, Bitwarden, pass, and gopassGovCloudGovCloud is explicitly targeted. The AWS collection module covers all 19 regions in its target list, including us-gov-east-1 and us-gov-west-1.HashiCorp VaultThe HashiCorp Vault collection module attempts to obtain a client token through four sequential methods: a dedicated environment variable, the token file that the Vault CLI writes to the home directory after aKey Vaultfrom any of these paths, the module enumerates every subscription accessible to the identity, every Key Vault within each subscription, and every secret in every vault. An overprivileged managed identity on aKiloeight AI coding tools, including Claude Desktop, Cursor, VS Code, Codeium, Continue, Zed, Opencode, and Kilo, the module performs four additional operations that expand the collection scope substantially.KubernetesThe Kubernetes collection module handles two scenarios: developer workstations with kubeconfig files and active pods running inside a live cluster. On workstations, the module parses kubeconfig files using its own YAMLLinuxpayload logic, the dropper performs three sequential environment checks. If the operating system is not Linux, the process exits immediately and silently. If the system locale is configured for the Russian language,OpenCodefiles for eight AI coding tools, including Claude Desktop, Cursor, VS Code, Codeium, Continue, Zed, Opencode, and Kilo, the module performs four additional operations that expand the collection scope substantially.passdatabase passwords, and AI coding tool credentialsPassword Manager Traversal: 1Password, Bitwarden, pass, and gopassTailscaleBeyond these four operations, the module also collects Tailscale and WireGuard VPN configuration files and recursively searches the home directory for Terraform state files. Terraform state stores the plaintextTerraformTailscale and WireGuard VPN configuration files and recursively searches the home directory for Terraform state files. Terraform state stores the plaintext attributes of every cloud resource that TerraformUbuntu 22.04The dropper uses a pip installation flag designed to bypass a restriction introduced in Ubuntu 22.04 that prevents pip from modifying the system Python environment. Without this flag, installation wouldVS Codesecrets, VPN configs, and credential files for eight AI coding tools, including Claude Desktop, Cursor, VS Code, Codeium, Continue, Zed, Opencode, and Kilo, the module performs four additional operations that expandWireGuardBeyond these four operations, the module also collects Tailscale and WireGuard VPN configuration files and recursively searches the home directory for Terraform state files. Terraform state stores the plaintextZedcredential files for eight AI coding tools, including Claude Desktop, Cursor, VS Code, Codeium, Continue, Zed, Opencode, and Kilo, the module performs four additional operations that expand the collection scope
Tools
Countries
Irancollection begins. This component evaluates whether the compromised machine is located in Israel or Iran by examining the system timezone configuration, timezone data files, and locale settings.Israelcredential collection begins. This component evaluates whether the compromised machine is located in Israel or Iran by examining the system timezone configuration, timezone data files, and locale settings.United Stateshostname in the googleusercontent.com space, placing it in AS396982 operated by Google LLC in the United States. The matching header fingerprint was active on this address from April 16 to April 22, 2026, a period