T1552.004Private Keys
T1552.004 — Private Keys is a MITRE ATT&CK technique in the Credential Access tactic. Clankerusecase tracks 26 detection use cases covering it and 16 threat-intel articles citing it.
Credential Access
26Use cases
16Articles
0Sub-techniques
1Tactic
↑ Parent technique: T1552 · Unsecured Credentials
Use cases covering this technique (26)
[WEEKLY] npm/yarn/pnpm Install-Hook Spawn → Credential-Store Read or Worm-Payload Drop in node_modules [WEEKLY] Package-install lifecycle script harvests local credentials and beacons to a non-baselined domain [WEEKLY] Package-manager child process credential fan-out with public egress (Mini Shai-Hulud / TeamPCP worm chain) Linux Auditd Find Ssh Private Keys Linux Auditd Private Keys and Certificate Enumeration Windows Export Certificate Windows PowerShell Export Certificate Windows PowerShell Export PfxCertificate Windows Private Keys Discovery Linux Auditd Find Private Keys [LLM] Non-browser process fan-out reading SSH/npm/Docker/AWS/browser credential stores on Arch host [LLM] Atomic Arch infostealer — bulk reads of SSH/npmrc/Vault/browser-cookie files by non-shell process [LLM] AI coding agent descendant reading developer credentials / env (Agentjacking credential access) [LLM] BitLocker tamper attempt via manage-bde or BitLocker PowerShell after WinRE shell access [LLM] npm install-time process reads .npmrc, SSH key, or cloud-credential file [LLM] nebula-mesh CVE-2026-47724 — cross-tenant host identity hijack via /hosts/{id}/reenroll → /enroll chain [LLM] Claude Code Read tool steered to cloud-credential files on GitHub Actions runner [LLM] Cloud/SSH/npm credential file access by Node or Bun during npm install [LLM] Megalodon harvester: clustered read of ~/.ssh/id_*, ~/.kube/config, ~/.npmrc, ~/.docker/config.json in one session [LLM] VS Code extension host fan-out reads of developer secrets (.ssh, .aws, .npmrc, ~/.claude/settings.json) [LLM] Coder CVE-2026-46354 - Agent token redemption: PKCS#7 POST followed by gitsshkey / external-auth GET [LLM] TeamPCP Linux credential harvest: Python reading /etc/shadow + auth.log + cloud [LLM] AI agent process reads cloud-credential, SSH or dotenv files (skill credential theft) [LLM] Postinstall node child enumerating multiple developer credential stores [LLM] Internal workflows pulling aws-actions/configure-aws-credentials@v4.3.0 during the buggy-release window [LLM] .NET build (dotnet/MSBuild) spawns git config to harvest user.emailArticles citing this technique (16)
crit 400+ AUR Packages Hijacked: What the “Atomic Arch” Campaign Means for Supply-Chain Security art-14