216.73.217.22

PCPJack | Cloud Worm Evicts TeamPCP and Steals Credentials at Scale

· Published 07/05/2026 23:33 · Modified 08/05/2026 09:21

Export JSON

Essential information

Published
07/05/2026 23:33
Modified
08/05/2026 09:21
Source / Author
AlienVault
Confidence
100/100
Report type(s)
threat-report
Labels / Tags
container worm docker compromise kubernetes exploitation pcpjack sliver teampcp
Tags
2026-05-07 container worm docker compromise kubernetes exploitation pcpjack sliver teampcp
Related entities
5 vulnerabilities (cve), 4 indicators, 4 observables, 24 techniques (mitre), 2 malware, 2 others

Description

is a sophisticated credential theft framework that propagates across exposed cloud infrastructure while systematically removing artifacts linked to , a threat actor behind notable 2026 supply chain compromises. The toolset harvests credentials from cloud platforms, containers, developer tools, productivity applications, and financial services, exfiltrating data through attacker-controlled infrastructure. It targets exposed Docker, Kubernetes, Redis, MongoDB, RayML services and vulnerable web applications, enabling external propagation and lateral movement. Unlike typical cloud malware, deploys no cryptominers, focusing instead on credential theft for monetization through fraud, spam campaigns, extortion, or access resale. The framework uses modular Python scripts orchestrated by a central component, employs Common Crawl data for target selection, and utilizes Telegram for command and control communications.

External references