Signal

PCPJack worm targets cloud infrastructure to steal credentials and evict TeamPCP tools

Evidence first: scan the strongest sources, then decide whether to go deeper.

Published 2026-05-07 10:00 UTCUpdated 2026-05-07 17:45 UTC
rss
cveexploitsmalwarethreat_actorscloud_security
Trend in the last 24h
Source links open
Source links and full evidence are open here. Archive history, compare-over-time, alerts, exports, API, integrations, and workflow are paid.
No card needed for the free brief.
Evidence trail (top sources)
top sources (2 domains)domains are deduped. counts indicate coverage, not truth.
2 top sources shown
limited source diversity in top sources
Overview

PCPJack is a newly discovered credential theft framework that spreads worm-like across exposed cloud infrastructure by exploiting multiple CVEs.

Entities
PCPJackTeamPCPAlex Delamotte
Score total
1.03
Momentum 24h
2
Posts
2
Origins
2
Source types
1
Duplicate ratio
0%
Why now
  • PCPJack was discovered recently in April 2026, exploiting multiple CVEs to spread rapidly.
  • Growing cloud adoption expands the attack surface for worm-like malware.
  • Early detection is crucial to prevent large-scale credential theft and lateral movement.
Why it matters
  • PCPJack targets critical cloud infrastructure, increasing risk of widespread credential theft.
  • Eviction of TeamPCP tools shows active competition among threat actors in cloud environments.
  • Stolen credentials can facilitate fraud, extortion, and further cloud service compromise.
LLM analysis
Topic mix: lowPromo risk: lowSource quality: high
Recurring claims
  • PCPJack spreads worm-like across exposed cloud infrastructure exploiting multiple CVEs.
  • PCPJack steals credentials from cloud, container, developer, productivity, and financial services and exfiltrates data through attacker-controlled infrastructure.
  • PCPJack evicts and deletes artifacts associated with the TeamPCP threat actor to dominate cloud environments.
How sources frame it
  • SentinelOne Labs: neutral
Consolidated key findings from two high-quality sources to provide a clear, concise briefing on PCPJack's cloud threat.
All evidence
All evidence
PCPJack Credential Stealer Exploits 5 CVEs to Spread Worm-Like Across Cloud Systems
thehackernews · thehackernews.com · 2026-05-07 17:45 UTC
PCPJack | Cloud Worm Evicts TeamPCP and Steals Credentials at Scale
SentinelOne Labs · sentinelone.com · 2026-05-07 10:00 UTC
Show filters & breakdown
Posts loaded: 0Publishers: 2Origin domains: 2Duplicates: -
Showing 2 / 0
Top publishers (this list)
  • thehackernews (1)
  • SentinelOne Labs (1)
Top origin domains (this list)
  • thehackernews.com (1)
  • sentinelone.com (1)