logo

After Replacing TeamPCP Malware, 'PCPJack' Steals Cloud Secrets

ID: d3562615-054a-5899-ab97-cbb35a30d2c3

STIX ID: report--d3562615-054a-5899-ab97-cbb35a30d2c3

Feed Name: Dark Reading

Threat Score
75/100

Date Published: 2026-05-07

Date Updated: 2026-05-07

Author: Nate Nelson

...
...

PCPJack is a modular Python-based cloud worm reported by SentinelLabs that steals a wide range of secrets (cloud, container, developer, productivity, financial services, and crypto wallets) and removes competing TeamPCP tooling; it establishes persistence via a bootstrap module, disguises activity through monitoring, sorts stolen secrets, moves laterally across Kubernetes, Docker, SSH and Redis, and uniquely leverages Common Crawl parquet files for pre-validated target discovery — it lacks cryptomining and appears optimized for rapid credential and wallet theft, so organizations should enforce secret vaults, MFA for service accounts, and cloud security best practices.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.