T1552.001Credentials In Files
T1552.001 — Credentials In Files is a MITRE ATT&CK technique in the Credential Access tactic. Clankerusecase tracks 110 detection use cases covering it and 74 threat-intel articles citing it.
Credential Access
110Use cases
74Articles
0Sub-techniques
1Tactic
↑ Parent technique: T1552 · Unsecured Credentials
Use cases covering this technique (110)
Azure Key Vault keys / secrets read [WEEKLY] Cross-category credential-store enumeration with rapid egress to anonymizing tunnel/CDN [WEEKLY] Developer interpreter / package-manager process exfiltrating tokens to public code-hosting / worker domains [WEEKLY] Install-Triggered Registry Publish or Git Push (Supply-Chain Worm Self-Propagation) [WEEKLY] npm-install spawned process performing cred-file fan-out plus IMDS reach [WEEKLY] npm Install-Time Lifecycle Hook Triggers Outbound Egress to Newly-Seen Domain (Shai-Hulud/Miasma/IronWorm pattern) [WEEKLY] npm/yarn/pnpm Install-Hook Spawn → Credential-Store Read or Worm-Payload Drop in node_modules [WEEKLY] Package install lifecycle hook spawns interpreter that reads developer credential stores [WEEKLY] Package-install lifecycle script harvests local credentials and beacons to a non-baselined domain [WEEKLY] Package-manager child process credential fan-out with public egress (Mini Shai-Hulud / TeamPCP worm chain) [WEEKLY] Package Manager / Dev-Tool Auto-Execution Triggers Non-Registry Egress or Credential-Store Access [WEEKLY] Package-manager install hook spawns interpreter that beacons to non-registry host within 120s [WEEKLY] Package Manager Install Hook Spawns Scripting Interpreter Then Touches Credential Files or Egresses Off-Registry [WEEKLY] Package-Manager Install -> Interpreter Child -> Non-Registry Egress Within 5 Minutes [WEEKLY] Package-manager install-time interpreter spawn with credential-file read and outbound egress within 120s [WEEKLY] Package manager lifecycle hook spawns network-fetching shell or runtime [WEEKLY] Supply-chain repo credential theft → outbound exfil to attacker infra MCP Github Suspicious Operation MCP Sensitive System File Search Potential password in username Shai-Hulud 2 Exfiltration Artifact Files Windows Unusual FileZilla XML Config Access Windows Unusual Intelliform Storage Registry Access Windows WinSCP Configuration Security Access [LLM] Recon tool reading K8s service-account token or /proc/self/environ inside a container [LLM] Rails/libvips worker reading process environment or system secrets (CVE-2026-66066 file-read) [LLM] n8n/Node child command accessing N8N_ENCRYPTION_KEY or host credential stores [LLM] Python interpreter reading SSH + AWS + Kube credential stores [LLM] CI runner process POSTing secrets to GhostAction exfil host via curl/wget/node [LLM] Build/attestation process egress to non-canonical OCI registry (@sigstore/oci cred leak, CVE-2026-59891) [LLM] actions/attest push-to-registry invocation using @sigstore/oci — externally influenced destination (CVE-2026-59891) [LLM] Build/attestation tooling reading ~/.docker/config.json (credential harvest surface, CVE-2026-59891) [LLM] BitLocker recovery key harvesting via manage-bde -protectors -get [LLM] CAV3RN AzureCommunication.dll config file 'logAzure.txt' written to disk [LLM] Leaked SA token / file contents in EnvoyExtensionPolicy status (CVE-2026-53713 disclosure) [LLM] Envoy Gateway ServiceAccount token reuse for anomalous K8s API actions [LLM] Shai-Hulud credential exfiltration: node/npm outbound to webhook.site [LLM] Post-RCE read of DIRAC dirac.cfg / proxy / token stores on FileCatalog host [LLM] DIRAC dirac.cfg/proxy access followed by outbound egress from service process (exfiltration) [LLM] DIRAC post-exploit read of dirac.cfg by a shell/read utility (CVE-2026-45579 credential theft) [LLM] Backdoored @injectivelabs/sdk-ts 1.20.21 payload file dropped on disk [LLM] TruffleHog secret scanner spawned from an npm/bun package-install context (Sha1-Hulud) [LLM] YesWiki credential access — web user reads wakka.config.php / .env / /etc/passwd [LLM] Nuclio cron pod shell reads Kubernetes service-account token (CVE-2026-52831 credential theft) [LLM] 9router credential dump via GET /api/settings/database (CVE-2026-55500) [LLM] 9router API-key leak via unauthenticated GET /api/usage/stats and /api/usage/request-logs [LLM] Cilium Envoy admin socket abuse: TLS secret / config disclosure via admin.sock (CVE-2026-49445) [LLM] 9router API key / secret exfiltration via /api/settings/database without prior login [LLM] GravitLauncher LaunchServer secret read via unauth path traversal (ecdsa_id/legacySalt/LaunchServer.json) [LLM] TruffleHog secret-scanning spawned by npm/pip during install (Shai-Hulud credential harvest) [LLM] Atomic Arch infostealer: build-spawned process harvesting SSH keys, dev tokens and browser/Electron sessions [LLM] Worm propagation: burst of npm/PyPI publishes from a developer machine [LLM] TruffleHog secret-scan spawned by npm/node install (Shai-Hulud credential harvest) [LLM] Node child of node-gyp/python making outbound to GitHub dead-drop or anomalous web service during install [LLM] Cloud credential file access by node/python runtime [LLM] Process reading /proc/<pid>/mem of GitHub Actions Runner.Worker (in-memory secret extraction) [LLM] Shai-Hulud npm worm: postinstall bundle.js spawns TruffleHog secret scan [LLM] Shai-Hulud npm worm: secret exfiltration to hardcoded webhook.site endpoint [LLM] s1ngularity Nx compromise: results.b64 credential dump written on developer host [LLM] node child of npm/yarn/pnpm reading cloud and CI credential files (Miasma sweep) [LLM] Mini Shai-Hulud npm worm exfil to filev2.getsession.org [LLM] npm/yarn/pnpm postinstall hook spawning credential-harvest tooling [LLM] Non-Codex-CLI node process reading ~/.codex/auth.json (Codex OAuth credential theft) [LLM] npm/bun process writing GitHub Actions workflow files (worm secret-exfil injection) [LLM] Megalodon harvester: bash secret-grep across workspace (API_KEY|SECRET|TOKEN|PRIVATE_KEY|BEGIN RSA) [LLM] Megalodon harvester: clustered read of ~/.ssh/id_*, ~/.kube/config, ~/.npmrc, ~/.docker/config.json in one session [LLM] Developer credential store read by Python or Node spawned from VS Code (Nx Console stealer pattern) [LLM] VS Code extension host fan-out reads of developer secrets (.ssh, .aws, .npmrc, ~/.claude/settings.json) [LLM] Burst credential-file harvest by VS Code / node process (Nx Console stealer behaviour) [LLM] Python Process Reading Multi-Cloud Credential Stores (durabletask Stealer Stage) [LLM] Single process fan-out reading cloud, Vault, SSH and AI-tool credential files [LLM] GitHub Actions Runner.Worker process-memory secret scraping via /proc [LLM] python3 reading /proc/<PID>/mem to scrape Runner.Worker secrets [LLM] Node.js process bulk-reading cloud & SCM credential files in single session [LLM] node.js process staging credential dump in nt-* temp directory [LLM] Node/npm/Bun process enumerating cloud, wallet, AI, and messaging credential file paths [LLM] Mini Shai-Hulud: Bun runtime executing `router_runtime.js` (2nd-stage stealer) [LLM] Mini Shai-Hulud known SHA256 IOC match (setup.mjs / execution.js / runner-memory dumper) [LLM] Node.js postinstall reading .env / .env.* during package install [LLM] Credential archive staging — trin.tar.gz created by python process [LLM] Shai-Hulud preinstall: node/npm spawning git/curl/gh pushing to attacker repo or GitHub API [LLM] Read of /proc/<pid>/mem targeting GitHub Runner.Worker (TeamPCP credential dump) [LLM] hackerbot-claw token exfiltration: curl POST with GITHUB_TOKEN to recv.hackmoltrepeat.com [LLM] Access to OpenClaw credential store (~/.openclaw/credentials/, ~/.openclaw/config.json5) [LLM] In-cluster Kubernetes secret enumeration with Python user-agent (litellm stealer K8s pivot) [LLM] TeamPCP exfiltration archive — tpcp.tar.gz file creation on host [LLM] GitHub Actions runner credential stealer: python3 base64-decoded payload reading /proc/<pid>/mem [LLM] TeamPCP Linux credential harvest: Python reading /etc/shadow + auth.log + cloud [LLM] Exfiltration to kubernetes-el attacker webhook.site UUIDs (Pwn Request payload) [LLM] npm/node post-install (telemetry.js) spawning credential CLIs (gh auth token / npm whoami) — s1ngularity Nx [LLM] Local AI coding agents (claude/gemini/q) launched with permission-bypass flags during package install — s1ngularity [LLM] tj-actions/changed-files compromise: memdump.py secret-exfiltration shell pattern on runner (CVE-2025-30066) [LLM] AI agent skill leaks Stripe key or card PAN/CVC verbatim in curl command line [LLM] AI session-log harvest via prompt-log extract.sh writing markdown with embedded secrets [LLM] AI agent skill exfiltrates GitHub token / env secrets via dynamic-context shell-out [LLM] Nx s1ngularity: npm postinstall weaponizes AI CLI tools (claude/gemini/q) for credential recon [LLM] Nx s1ngularity exfiltration via public GitHub repo 's1ngularity-repository' [LLM] tj-actions/changed-files: CI runner pipes gist memdump.py to python to scrape secrets [LLM] Shai-Hulud 3.0 'Goldox-T3chs' GitHub exfiltration marker observed [LLM] TruffleHog secret-scanner execution on developer / CI host (SHA1-Hulud credential harvest) [LLM] TruffleHog secret-scanner executed by node/npm postinstall context [LLM] Postinstall node child enumerating multiple developer credential stores [LLM] AI coding agent CLI (claude/gemini/q) invoked with permission-bypass flags [LLM] Runner.Worker process memory dumped via /proc/PID/mem read on Linux runner [LLM] Container PID 1 environment harvest via /proc/1/environ read [LLM] Assets running vulnerable crypto-js (<4.2.0) or crypto-es (<2.1.0) — CVE-2023-46233 / CVE-2023-46133 [LLM] Storage account key retrieval (listKeys) inside an ARM/Bicep deployment — secret-in-output leak vector [LLM] npm/node install hook exfiltrating /etc/passwd, kube config & krb5 ticket via wget --post-file [LLM] Environment-variable exfiltration to hacktask C2 (npm.hacktask.net) [LLM] Gradle plugin-publish run with verbose logging leaks pre-signed AWS URL (CVE-2020-7599)Articles citing this technique (74)
crit Critical Rails Flaw Could Let Unauthenticated Attackers Read Server Files via Image Uploads art-06
high Find Unused, Stale, and OIDC-Replaceable GitHub Actions Secrets Across Your GitHub Organization art-114
crit 400+ AUR Packages Hijacked: What the “Atomic Arch” Campaign Means for Supply-Chain Security art-316
high Miasma and Hades Are Spreading Now: Detect Them on Developer Machines with Suspicious Files art-317
high GitHub breached via a malicious VS Code extension: why developer devices are the real target art-412
high The AntV Supply Chain Campaign Expands: Microsoft's `durabletask` PyPI Package Compromised art-422
high Microsoft's durabletask package on PyPi Compromised. Mini Shai Hulud attacks again... again! art-423
crit Malicious node-ipc versions published to npm in suspected maintainer account compromise art-431
high Malicious Release of elementary-data PyPI Package Steals Cloud Credentials from Data Engineers art-475