Signal
PCPJack worm targets cloud infrastructure to steal credentials and evict TeamPCP tools
Evidence first: scan the strongest sources, then decide whether to go deeper.
Published 2026-05-07 10:00 UTCUpdated 2026-05-07 17:45 UTC
rss
cveexploitsmalwarethreat_actorscloud_security
Trend in the last 24h
Source links open
Source links and full evidence are open here. Archive history, compare-over-time, alerts, exports, API, integrations, and workflow are paid.
No card needed for the free brief.
Evidence trail (top sources)
top sources (2 domains)domains are deduped. counts indicate coverage, not truth.2 top sources shown
limited source diversity in top sources
Overview
PCPJack is a newly discovered credential theft framework that spreads worm-like across exposed cloud infrastructure by exploiting multiple CVEs.
Entities
PCPJackTeamPCPAlex Delamotte
Score total
1.03
Momentum 24h
2
Posts
2
Origins
2
Source types
1
Duplicate ratio
0%
Why now
- PCPJack was discovered recently in April 2026, exploiting multiple CVEs to spread rapidly.
- Growing cloud adoption expands the attack surface for worm-like malware.
- Early detection is crucial to prevent large-scale credential theft and lateral movement.
Why it matters
- PCPJack targets critical cloud infrastructure, increasing risk of widespread credential theft.
- Eviction of TeamPCP tools shows active competition among threat actors in cloud environments.
- Stolen credentials can facilitate fraud, extortion, and further cloud service compromise.
LLM analysis
Topic mix: lowPromo risk: lowSource quality: high
Recurring claims
- PCPJack spreads worm-like across exposed cloud infrastructure exploiting multiple CVEs.
- PCPJack steals credentials from cloud, container, developer, productivity, and financial services and exfiltrates data through attacker-controlled infrastructure.
- PCPJack evicts and deletes artifacts associated with the TeamPCP threat actor to dominate cloud environments.
How sources frame it
- SentinelOne Labs: neutral
Consolidated key findings from two high-quality sources to provide a clear, concise briefing on PCPJack's cloud threat.
All evidence
All evidence
PCPJack Credential Stealer Exploits 5 CVEs to Spread Worm-Like Across Cloud Systems
thehackernews · thehackernews.com · 2026-05-07 17:45 UTC
PCPJack | Cloud Worm Evicts TeamPCP and Steals Credentials at Scale
SentinelOne Labs · sentinelone.com · 2026-05-07 10:00 UTC
Show filters & breakdown
Posts loaded: 0Publishers: 2Origin domains: 2Duplicates: -
Showing 2 / 0
Top publishers (this list)
- thehackernews (1)
- SentinelOne Labs (1)
Top origin domains (this list)
- thehackernews.com (1)
- sentinelone.com (1)