T1552.004Private Keys
T1552.004 — Private Keys is a MITRE ATT&CK technique in the Credential Access tactic. Clankerusecase tracks 25 detection use cases covering it and 15 threat-intel articles citing it.
Credential Access
25Use cases
15Articles
0Sub-techniques
1Tactic
↑ Parent technique: T1552 · Unsecured Credentials
Use cases covering this technique (25)
[WEEKLY] npm/yarn/pnpm Install-Hook Spawn → Credential-Store Read or Worm-Payload Drop in node_modules [WEEKLY] Package-install lifecycle script harvests local credentials and beacons to a non-baselined domain [WEEKLY] Package-manager child process credential fan-out with public egress (Mini Shai-Hulud / TeamPCP worm chain) Linux Auditd Find Ssh Private Keys Linux Auditd Private Keys and Certificate Enumeration Windows Export Certificate Windows PowerShell Export Certificate Windows PowerShell Export PfxCertificate Windows Private Keys Discovery Linux Auditd Find Private Keys [LLM] keyv npm compromise: gh-token-monitor credential-persistence artifacts (macOS/Linux) [LLM] vault-secrets-webhook mints SA tokens via TokenRequest after admission (CVE-2026-54725) [LLM] anthropickit loot file '/tmp/runner_exfil.json' written to disk [LLM] Python interpreter reading SSH + AWS + Kube credential stores [LLM] Siemens ROX II xz utility misused as cat to read root-owned secrets (CVE-2025-40948) [LLM] DIRAC post-exploit read of dirac.cfg by a shell/read utility (CVE-2026-45579 credential theft) [LLM] Atomic Arch infostealer: build-spawned process harvesting SSH keys, dev tokens and browser/Electron sessions [LLM] s1ngularity Nx compromise: telemetry.js postinstall harvesting tokens via gh auth token [LLM] node child of npm/yarn/pnpm reading cloud and CI credential files (Miasma sweep) [LLM] Megalodon harvester: clustered read of ~/.ssh/id_*, ~/.kube/config, ~/.npmrc, ~/.docker/config.json in one session [LLM] VS Code extension host fan-out reads of developer secrets (.ssh, .aws, .npmrc, ~/.claude/settings.json) [LLM] TeamPCP Linux credential harvest: Python reading /etc/shadow + auth.log + cloud [LLM] Postinstall node child enumerating multiple developer credential stores [LLM] .NET build (dotnet/MSBuild) spawns git config to harvest user.email [LLM] Python interpreter reading SSH/GPG private keys (jeIlyfish key theft)Articles citing this technique (15)
crit Compromised PyPI Package: mrmustard 0.7.4 Steals SSH, Cloud, and Kubernetes Credentials art-193