logo

PCPJack | Cloud Worm Evicts TeamPCP and Steals Credentials at Scale

Threat Score
80/100

Date Published: 2026-05-07

Date Updated: 2026-07-27

Author: Alex Delamotte

...
...

SentinelLABS describes PCPJack, a modular credential-harvesting worm that spreads across exposed cloud infrastructure (Docker, Kubernetes, Redis, MongoDB, RayML, vulnerable web apps) by scanning cloud IP ranges and parsing Common Crawl parquet data; it evicts TeamPCP artifacts, harvests a wide range of secrets, exfiltrates data via Telegram and typosquatted domains, employs Sliver beacons for C2, and includes detailed indicators (IPs, domains, file hashes) and mitigation recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.