A new cybersecurity threat has emerged in the form of PCPJack, a sophisticated malware framework designed to steal credentials from exposed cloud infrastructure while actively removing traces of another notorious group, TeamPCP. Security researchers at SentinelLabs first identified the malware, which appears to be the work of a former TeamPCP operator or affiliate leveraging insider knowledge of the group’s tactics. The discovery underscores the escalating risks of cloud-based credential theft and the evolving tactics of cybercriminals in the digital arms race.
PCPJack targets a broad range of cloud services, including Docker, Kubernetes, Redis, MongoDB and vulnerable web applications. Unlike traditional malware campaigns, this framework is notable for its dual-purpose approach: while it steals credentials for financial gain—through fraud, spam, or credential resale—it also systematically clears out any remnants of TeamPCP’s tools, effectively “claiming” compromised systems for itself. This behavior suggests a deliberate strategy to monopolize access and evade detection, according to SentinelLabs’ analysis.
The malware operates by infecting Linux-based cloud systems via a shell script called bootstrap.sh. Upon execution, it creates hidden directories, installs Python dependencies, and downloads additional modules to establish persistence. A key feature is its ability to detect and delete TeamPCP-related tooling, ensuring no competing malware operates on the same infrastructure. The orchestrator module, monitor.py, coordinates these activities, making PCPJack a highly automated and adaptive threat.
Who Is Behind PCPJack?
SentinelLabs researchers hypothesize that PCPJack may have been developed by a former TeamPCP affiliate or member. TeamPCP, a cloud-focused threat group, has gained notoriety for high-profile supply-chain breaches, including attacks on Aqua Security’s Trivy scanner, the LiteLMM and Telnyx PyPI packages, and more recently, SAP npm packages. The similarities between PCPJack’s targeting and TeamPCP’s earlier campaigns—particularly those from late 2025—support the theory of an insider pivot.
“Many of the services targeted by the PCPJack framework are similar to the early TeamPCP/PCPCat campaigns from December 2025,” the researchers note. “We believe this could be a former operator who is deeply familiar with the group’s tooling.” This insider knowledge may explain why PCPJack is so effective at evading detection and outmaneuvering competing malware.
How PCPJack Operates: A Technical Breakdown
PCPJack’s attack chain begins with the deployment of bootstrap.sh, a script that automates the infection process. Once executed, it:
- Creates a hidden working directory to avoid detection.
- Installs Python dependencies required for its operations.
- Downloads additional malicious modules to expand its capabilities.
- Establishes persistence on the system to ensure long-term access.
- Launches monitor.py, the main orchestrator that manages credential theft and lateral movement.
The malware’s ability to actively remove TeamPCP’s tooling is particularly noteworthy. By deleting competing malware, PCPJack ensures that it retains exclusive control over compromised systems. This behavior aligns with a broader trend in cybercrime, where threat actors increasingly compete for access to high-value targets, leading to a form of digital turf wars.
Targeted Services and Potential Impact
PCPJack’s targeting of cloud services like Docker, Kubernetes, Redis, and MongoDB reflects the growing reliance on containerized and cloud-native environments. These services are often used to host critical business applications, making them prime targets for credential theft. Once credentials are stolen, attackers can:
- Gain unauthorized access to cloud accounts and databases.
- Deploy ransomware or other malware to further exploit the system.
- Resell stolen credentials on the dark web for financial gain.
- Launch spam or phishing campaigns using compromised infrastructure.
The impact of such attacks can be severe, particularly for organizations that rely on cloud infrastructure for their operations. Financial fraud, data breaches, and reputational damage are all potential consequences of a PCPJack infection.
Who Is Affected?
While PCPJack appears to target large-scale cloud environments, the risk extends to any organization using exposed cloud services. This includes:

- Enterprise businesses relying on Docker, Kubernetes, or other containerized platforms.
- Developers and DevOps teams managing cloud-based applications.
- Financial institutions storing sensitive customer data in cloud databases.
- E-commerce platforms handling transactions through cloud services.
Smaller organizations may also be at risk if they share infrastructure with larger clients or use third-party cloud services that have been compromised. The malware’s ability to move laterally across networks means that a single breach could potentially spread within an organization’s entire cloud environment.
What Can Organizations Do to Protect Themselves?
Given the sophistication of PCPJack, organizations must adopt a multi-layered approach to cybersecurity. Key steps include:
- Regular audits of cloud infrastructure to identify and patch exposed services.
- Implementing zero-trust security models to limit lateral movement by unauthorized actors.
- Monitoring for unusual activity, such as unexpected script executions or hidden directories.
- Using advanced threat detection tools capable of identifying malware like PCPJack.
- Educating employees about phishing and social engineering tactics used to deploy malware.
organizations should stay informed about the latest threats by following updates from cybersecurity firms like SentinelLabs and subscribing to alerts from platforms such as CISA (Cybersecurity and Infrastructure Security Agency).
Looking Ahead: The Next Steps in Cybersecurity
The emergence of PCPJack highlights the need for continuous vigilance in the cybersecurity landscape. As threat actors evolve their tactics, organizations must adapt by investing in proactive defense strategies. This includes:

- Adopting AI-driven threat detection to identify anomalies in real time.
- Enhancing incident response plans to quickly contain and mitigate breaches.
- Collaborating with cybersecurity communities to share threat intelligence.
- Regulating third-party cloud providers to ensure compliance with security best practices.
While PCPJack is a concerning development, it also serves as a wake-up call for organizations to prioritize cybersecurity. By staying ahead of emerging threats and implementing robust defenses, businesses can reduce their risk of falling victim to credential theft and other cyberattacks.
Key Takeaways
- PCPJack is a new malware framework designed to steal credentials from exposed cloud infrastructure while removing traces of TeamPCP.
- It targets services like Docker, Kubernetes, Redis, and MongoDB, making it a significant threat to cloud-based operations.
- The malware is believed to be the work of a former TeamPCP operator, leveraging insider knowledge of the group’s tactics.
- Organizations must conduct regular audits, implement zero-trust security, and monitor for unusual activity to mitigate risks.
- Proactive cybersecurity measures, including AI-driven detection and incident response planning, are essential to counter evolving threats.
The next confirmed checkpoint for updates on PCPJack and related threats will likely come from cybersecurity firms like SentinelLabs or regulatory bodies such as CISA. For the latest advisories, readers are encouraged to monitor official channels and stay informed through trusted cybersecurity resources.
Have you or your organization experienced unusual activity in your cloud infrastructure? Share your thoughts and concerns in the comments below, or spread the word to help raise awareness about this growing threat.
Related reading