New Cloud Worm Evicts TeamPCP Malware to Steal Credentials
Security researchers at SentinelOne have identified a new malicious worm, dubbed PCPJack, that actively removes competitor malware known as TeamPCP from compromised cloud instances before taking control. Discovered in late April 2026, this automated framework targets exposed services such as Docker, Kubernetes, Redis, and MongoDB. Unlike previous campaigns reliant on human actors, PCPJack spreads autonomously by scanning for vulnerable environments and executing shell scripts to eliminate TeamPCP artifacts. Once established, the worm harvests sensitive credentials, including SSH keys, environment variables, and cloud tokens, encrypting them for exfiltration. The absence of cryptomining modules suggests the attackers intend to use stolen data for financial fraud, spam campaigns, or selling access to other criminal groups. This development follows TeamPCP's notable supply chain attack involving the Trivy vulnerability scanner. The discovery highlights an escalating conflict among cybercriminal groups fighting for dominance over compromised infrastructure, shifting from simple infection to active eviction of rivals to maximize credential theft opportunities in cloud environments.
Wire timeline
New Cloud Worm Evicts TeamPCP Malware to Steal Credentials
Security researchers at SentinelOne have identified a new malicious worm, dubbed PCPJack, that actively removes competitor malware known as TeamPCP from compromised cloud instances before taking control. Discovered in late April 2026, this automated framework targets exposed services such as Docker, Kubernetes, Redis, and MongoDB. Unlike previous campaigns reliant on human actors, PCPJack spreads autonomously by scanning for vulnerable environments and executing shell scripts to eliminate TeamPCP artifacts. Once established, the worm harvests sensitive credentials, including SSH keys, environment variables, and cloud tokens, encrypting them for exfiltration. The absence of cryptomining modules suggests the attackers intend to use stolen data for financial fraud, spam campaigns, or selling access to other criminal groups. This development follows TeamPCP's notable supply chain attack involving the Trivy vulnerability scanner. The discovery highlights an escalating conflict among cybercriminal groups fighting for dominance over compromised infrastructure, shifting from simple infection to active eviction of rivals to maximize credential theft opportunities in cloud environments.
www.theregister.com - Articles