# PCPJack Malware Campaign Targets Cloud Environments While Erasing Traces of TeamPCP Rivals


A sophisticated threat actor has launched an aggressive campaign to displace the notorious TeamPCP hacking group by cleaning infected systems and deploying a new malware framework designed to harvest credentials across cloud infrastructure. Dubbed PCPJack by SentinelOne researchers, the campaign underscores a troubling shift in cloud attack tactics: competitors not just stealing data, but systematically eliminating rival infrastructure to monopolize compromised assets.


## The Threat: A Malware Framework with Purpose


PCPJack is a modular malware framework designed from the ground up to target organizations running cloud-native infrastructure. Operating since late April 2026, the campaign deploys a Python-based orchestration system capable of:


  • Credential theft across dozens of platforms including AWS, Kubernetes, Docker, GitHub, Slack, Office 365, and Google Workspace
  • Lateral movement through extracted SSH keys, stolen cloud tokens, and credential-based propagation
  • Self-propagation via exploitation of known web application vulnerabilities
  • Remote infrastructure scanning using Common Crawl datasets to identify additional targets

  • The framework's modular design reflects professional development practices. Rather than a monolithic payload, PCPJack distributes six independent Python modules that handle specific functions: credential parsing, lateral movement, command-and-control encryption, cloud IP enumeration, cloud environment scanning, and system reconnaissance.


    What sets PCPJack apart from typical malware campaigns is its deliberate targeting of rival infrastructure. Before establishing persistence, the initial deployment script actively searches for and removes artifacts associated with TeamPCP—including processes, configuration files, and tooling deployed by the competing group.


    ## Background and Context: TeamPCP and Cloud Supply Chain Attacks


    To understand PCPJack's emergence, context on TeamPCP is essential. The group gained notoriety through a series of high-visibility supply chain attacks targeting open source software ecosystems in early 2026, following less-publicized campaigns in December 2025. These attacks exploited trusted repositories to distribute backdoored versions of legitimate packages, compromising downstream organizations on a massive scale.


    The publicity surrounding TeamPCP's operations and alleged changes to group membership appear to have created an opportunity. SentinelOne's analysis suggests PCPJack's operator is a former TeamPCP member who possesses intimate knowledge of the group's tools, tactics, and targets. Rather than continuing cooperation, this insider has turned competitive—using deep familiarity with TeamPCP's deployment signatures to surgically remove rival infrastructure while establishing their own foothold.


    This represents an underexamined pattern in the threat landscape: internal defections and competitive consolidation among criminal groups. As initial access becomes increasingly expensive and compromised infrastructure increasingly valuable, threat actors are investing in operational displacement—an adversarial form of infrastructure takeover.


    ## Technical Details: How PCPJack Operates


    Initial Compromise & Cleanup


    PCPJack attacks begin with a Linux shell script that establishes the execution environment. The script performs two critical functions before progressing:


    1. Detection and removal of TeamPCP artifacts, including specific process names and configuration patterns

    2. Creation of a Python virtual environment for isolated module execution


    The script then fetches six additional Python modules from an AWS S3 bucket, renames them to obscure their purpose, and establishes persistence mechanisms to survive system reboots.


    Module Orchestration


    The first module acts as the framework's central orchestrator, importing and controlling the other five modules. SentinelOne's investigation revealed the modules are responsible for:


    | Module Function | Purpose |

    |-----------------|---------|

    | Credential Parsing | Extracts .env files, config files, SSH keys, API tokens, environment variables |

    | Cloud Scanning | Identifies and enumerates accessible cloud services and resources |

    | Lateral Movement | Attempts propagation via stolen credentials and SSH keys |

    | C&C Encryption | Encrypts communications to Telegram-based command channels |

    | IP Range Lookup | Maps cloud provider IP ranges for targeting |


    Credential Harvesting Scope


    PCPJack's credential collection spans an unusually broad threat surface:


  • Cloud platforms: AWS, Kubernetes, Docker, RayML, MongoDB, Redis
  • Development tools: GitHub, GitLab (inferred)
  • Business software: Slack, Office 365/Outlook, Google Workspace
  • Cryptocurrency: Wallet seeds and private keys
  • Other services: WordPress, Gmail, miscellaneous web applications

  • This comprehensive targeting suggests the stolen credentials are being monetized across multiple criminal economies: credential markets, spam campaigns, financial fraud, and extortion operations.


    Exploitation & Propagation


    PCPJack doesn't rely solely on stolen credentials for spreading. The framework includes dedicated modules to exploit known vulnerabilities in widely deployed web applications:


  • CVE-2025-29927 (Next.js) — Remote code execution vulnerability
  • CVE-2025-55182 (React2Shell) — JavaScript framework exploitation
  • CVE-2026-1357 (WPVivid Backup Plugin) — WordPress backup plugin flaw
  • CVE-2025-9501 (W3 Total Cache) — WordPress caching plugin vulnerability
  • CVE-2025-48703 (CentOS Web Panel) — Web hosting control panel exploit

  • The framework downloads datasets from Common Crawl — the publicly available web crawl repository — to identify additional vulnerable targets across the internet and attempt automated infection.


    Command & Control Infrastructure


    Rather than traditional C&C servers, PCPJack uses Telegram channels for command delivery and data exfiltration. Communications are encrypted, making network-level detection more difficult and providing the threat actor with a communication channel resistant to takedown efforts.


    ## Secondary Toolset Discovery


    During investigation, SentinelOne identified a second toolset associated with the same threat actor, indicating a parallel operational capability. This toolkit includes:


  • Sliver implants (a Cobalt Strike alternative)
  • Expanded credential theft targeting additional cloud services: Anthropic, DigitalOcean, Discord, and various Google APIs

  • The existence of multiple parallel toolsets suggests a threat actor with significant resources and operational sophistication—someone capable of maintaining multiple attack frameworks simultaneously.


    ## Implications for Organizations


    PCPJack's emergence creates several cascading risks:


    1. Compromised Cloud Credentials at Scale


    Organizations that have been infected by TeamPCP now face re-infection risk from PCPJack. More critically, if both actors have compromised their cloud credentials, organizations may not know which threat actor currently controls their infrastructure.


    2. Supply Chain Risk Persistence


    The original TeamPCP supply chain attacks distributed backdoored packages that may still be in use. Organizations cannot simply remove TeamPCP artifacts; they must audit all dependencies for compromised packages and rebuild from verified sources.


    3. Lateral Movement Through Cloud Native Infrastructure


    PCPJack's focus on Kubernetes, Docker, and container orchestration platforms reflects the reality that modern infrastructure is increasingly containerized. A single compromised container can become a pivot point into the entire cluster.


    4. Credential Theft as Primary Objective


    Unlike malware that seeks to exfiltrate specific data, PCPJack's comprehensive credential harvesting suggests the attacker intends to maintain persistent access across multiple victim environments—a more dangerous posture than one-time data theft.


    ## Recommendations for Defenders


    Immediate Actions


  • Audit for TeamPCP artifacts: Search systems for known TeamPCP tool signatures and IoCs
  • Rotate all cloud credentials: Assume any stored cloud tokens, API keys, or SSH keys may be compromised
  • Review cloud access logs: Check for suspicious API calls, unusual authentication patterns, and lateral movement attempts (particularly in the 6 weeks since late April 2026)

  • Longer-Term Mitigations


  • Implement secrets management: Move away from storing credentials in .env files and configuration files; use dedicated secrets managers (AWS Secrets Manager, HashiCorp Vault, etc.)
  • Enforce principle of least privilege: Limit service account permissions to only required resources; segment Kubernetes and container orchestration access
  • Patch known vulnerabilities: Deploy fixes for CVE-2025-29927, CVE-2025-55182, CVE-2026-1357, CVE-2025-9501, and CVE-2025-48703
  • Monitor for exploitation attempts: Use Web Application Firewalls and intrusion detection systems to identify attack patterns targeting the above vulnerabilities
  • Implement supply chain verification: For open source dependencies, verify package integrity and consider vendoring critical dependencies from verified sources

  • ---


    ## HackWire Analysis


    PCPJack represents a maturation of cloud-targeted malware that most reporting has yet to fully grapple with: the transition from theft to operational control. Where earlier cloud threats (like container escape exploits or Kubernetes RBAC bypasses) were dramatic but tactical, PCPJack's approach is administrative—it doesn't break into systems dramatically, it inherits them from competitors and consolidates control.


    The fact that a former TeamPCP insider is now running PCPJack is not incidental detail; it's the story. It suggests that the criminal underground's initial excitement about TeamPCP's supply chain approach has given way to internecine conflict. Competitors aren't just fighting over initial access—they're eliminating each other's infrastructure to capture entire victim environments.


    This has a concrete implication: organizations that were compromised by TeamPCP but thought they'd remediated by removing TeamPCP tools have likely simply handed their infrastructure to PCPJack. Without verification that the attacker has been *completely* evicted—not just that one known tool is gone—these organizations remain compromised.


    The secondary toolset discovery (Sliver implants plus expanded credential targets) also deserves emphasis. This operator isn't just displaced TeamPCP members trying to survive; they're building a sophisticated, multi-tool operation capable of supporting different attack scenarios. That level of investment suggests either well-funded sponsorship or credential monetization at serious scale.


    For defenders, the critical lesson: assume that if TeamPCP accessed your environment, a successor threat actor now has. The cleanup cannot stop at removing known artifacts—it must include full credential rotation, access log auditing, and verification that no persistence mechanisms remain. — *HackWire Editorial*


    ---


    ## Related Coverage


  • Read more in our [Tools](https://www.hackwire.news/category/tools) coverage
  • Cross-reference with [Breaches](https://www.hackwire.news/category/breaches) and [Vulnerabilities](https://www.hackwire.news/category/vulnerabilities)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)