SentinelLABS reported that attackers are deploying PCPJack, a modular Linux- and Python-based cloud worm built to steal credentials at scale from exposed cloud infrastructure. The framework targets cloud, container, developer, productivity, and financial environments, then spreads laterally through Docker, Kubernetes, Redis, MongoDB, RayML, SSH, and vulnerable web applications. Researchers said the malware removes TeamPCP-related artifacts from compromised systems, indicating it is designed to replace or evict earlier TeamPCP infections rather than coexist with them.
The campaign used a staging server hosting two related toolsets: the main PCPJack framework and a secondary credential-harvesting shell script paired with Sliver beacons. Stolen data was exfiltrated through Telegram and to a typosquatted CloudFront-like domain, suggesting an operation focused on credential theft and follow-on abuse rather than cryptomining. SentinelLABS found overlaps with historical TeamPCP targeting and tooling, but said the available evidence does not conclusively show that PCPJack operators are members of TeamPCP.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
SentinelLABS said timing evidence indicates the PCPJack campaign began around the week of 2026-04-20. The report also noted the malware’s operators appeared focused on replacing TeamPCP infections and monetizing stolen credentials and cryptocurrency wallets rather than cryptomining.
Based on the absence of cryptomining behavior, SentinelLABS assessed the campaign as likely monetizing through credential theft, fraud, spam, extortion, or resale of stolen access. The researchers noted overlaps with TeamPCP targeting and tooling history but said there was no conclusive evidence directly linking PCPJack to TeamPCP membership.
SentinelLABS identified a separate toolset on the same staging server consisting of a credential-harvesting shell script and Sliver beacons. This tooling exfiltrated data to a typosquatted CloudFront-like domain, indicating additional post-compromise capability tied to the infrastructure.
The analysis found PCPJack using a Linux bootstrap script and Python modules to steal credentials from cloud, container, developer, productivity, and financial environments. It was also observed spreading through Docker, Kubernetes, Redis, MongoDB, RayML, SSH, and vulnerable web applications, with exfiltration via Telegram.
SentinelLABS reported discovering PCPJack, a modular credential-theft framework targeting exposed cloud infrastructure. The toolset was observed removing TeamPCP-related artifacts, suggesting it was designed to replace or evict prior TeamPCP infections rather than conduct cryptomining.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
5 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcetheregister.com
Open sourcethehackernews.com
Open sourcedarkreading.com
Open sourcesentinelone.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.