logo

New PCPJack worm steals credentials, cleans TeamPCP infections

ID: 15f2fe83-dde4-52ff-9294-41567db61cae

STIX ID: report--15f2fe83-dde4-52ff-9294-41567db61cae

Feed Name: Bleeping Computer

Threat Score
78/100

Date Published: 2026-05-07

Date Updated: 2026-05-07

Author: Bill Toulas

...
...

**PCPJack: cloud-focused credential theft and cleanup of rival infections** — SentinelLabs reports a new Linux-based malware framework, PCPJack, that compromises exposed cloud services (Docker, Kubernetes, Redis, MongoDB, RayML, vulnerable web apps), removes TeamPCP artifacts, harvests credentials and SSH keys, moves laterally, establishes persistence (systemd, cron, Redis rewrites, privileged containers), exfiltrates encrypted credentials to Telegram, and deploys a Sliver-based backdoor; researchers link its tooling to a possible former TeamPCP affiliate and provide mitigation recommendations including MFA, IMDSv2, least-privilege, and avoiding plaintext secrets.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.