PCPcat is a large-scale credential-harvesting malware campaign targeting internet-exposed Next.js deployments, with reporting also linking it to React-related exploitation. It has been associated with TeamPCP activity and appears within a broader operational ecosystem previously linked by researchers to TA-NATALSTATUS and ShadowRay 2.0-era infrastructure abuse. The campaign has been described as highly automated and capable of compromising large numbers of servers in a short period through exploitation of unauthenticated remote code execution conditions in web application stacks, including CVE-2025-29927 and CVE-2025-66478 as reported.
Operationally, PCPcat conducts broad scanning of public-facing applications, validates exploitable targets, and then executes attacker-supplied commands through a Node.js execution chain using prototype-pollution and command-injection techniques. Following initial access, it harvests sensitive data from compromised hosts, including environment configuration, cloud credentials, SSH material, Docker-related configuration, Git credentials, and shell history. Stolen data is then exfiltrated to attacker-controlled infrastructure.
PCPcat also establishes durable post-compromise access by deploying tunneling and proxy tooling, including GOST and FRP, and by creating auto-restarting services to preserve persistence across reboots or service interruption. Reporting further places PCPcat in a progression of TeamPCP operations that moved from exploitation of exposed infrastructure and Docker APIs toward broader supply-chain and developer-tool compromises. The malware primarily targets Linux-hosted Node.js web infrastructure and cloud-connected server environments where exposed application services can yield credentials and downstream access.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
That progression ran through PCPcat, which peaked around Christmas 2025 against React2Shell targets and exposed Docker APIs. | That progression ran through PCPcat, which peaked around Christmas 2025 against React2Shell targets and exposed Docker APIs, and into the March 2026 compromises of Trivy, Checkmarx's KICS and LiteLLM.
A new malware campaign called PCPcat has successfully compromised more than 59,000 servers in under 48 hours through targeted exploitation of critical vulnerabilities in Next.js and React frameworks.
A new malware campaign called PCPcat has successfully compromised more than 59,000 servers in under 48 hours through targeted exploitation of critical vulnerabilities in Next.js and React frameworks.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
That progression ran through PCPcat, which peaked around Christmas 2025 against React2Shell targets and exposed Docker APIs, and into the March 2026 compromises of Trivy, Checkmarx's KICS and LiteLLM.
That progression ran through PCPcat, which peaked around Christmas 2025 against React2Shell targets and exposed Docker APIs, and into the March 2026 compromises of Trivy, Checkmarx's KICS and LiteLLM.
That progression ran through PCPcat, which peaked around Christmas 2025 against React2Shell targets and exposed Docker APIs, and into the March 2026 compromises of Trivy, Checkmarx's KICS and LiteLLM.
11 distinct techniques documented for this family, organized by ATT&CK tactic.
Find and remove processes or artifacts that match naming conventions referencing TeamPCP or PCPcat process list, services, paths, or containers ... the PCPJack operator even collects success metrics on whether TeamPCP has been evicted from targeted environments in a “PCP replaced” field sent to the C2.
“The stolen information gets sent back to the control server through simple HTTP requests that require no authentication.”
61 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
Other indicator types observed in public reporting.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A self-propagating botnet built from hijacked AI and internet-facing infrastructure, used in the operators' progression from infrastructure exploitation and cryptojacking toward broader supply-chain compromise activity.
A large-scale credential-harvesting operation targeting Next.js deployments, using a C2 API to manage compromised servers and stolen credentials.
Malware campaign exploiting web application vulnerabilities to compromise servers, exfiltrate credentials, and establish persistent tunneling infrastructure.
PCPcat is a server-focused malware/botnet that mass-scans public-facing Next.js applications, exploits unauthenticated RCE via prototype pollution/command injection, steals environment files and credentials (cloud creds, SSH keys, histories), exfiltrates data over HTTP to a C2, and establishes persistence by installing tunneling/proxy tooling (GOST, FRP) and creating auto-restarting system services to maintain long-term access.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.