Briefing

New PCPJack worm steals credentials, cleans TeamPCP infections

security
by Bill Toulas · CVE-2025-29927 CVE-2025-48703 CVE-2025-55182 CVE-2025-9501 CVE-2026-1357

Scan cloud infrastructure for PCPJack bootstrap.sh, remove TeamPCP artifacts, enforce MFA, and secure Docker/Kubernetes credentials.

What to do now

Remove any PCPJack bootstrap.sh files, delete TeamPCP processes and containers, enforce MFA, secure Docker/Kubernetes credentials, and patch vulnerable services.

Summary

A new malware framework called PCPJack, first reported on May 7, 2026, steals credentials from exposed cloud infrastructure while actively removing TeamPCP infections. PCPJack infects Linux‑based cloud systems via a bootstrap.sh script that creates a hidden working directory, installs Python dependencies, downloads modules, establishes persistence, and launches monitor.py. The framework explicitly checks for TeamPCP tooling and deletes all related processes, services, containers, files, and persistence artifacts to claim the compromise for itself. PCPJack targets Docker, Kubernetes, Redis, MongoDB, RayML, and vulnerable web applications, and exploits a list of known CVEs including CVE‑2025‑29927, CVE‑2025‑55182, CVE‑2026‑1357, CVE‑2025‑9501, and CVE‑2025‑48703. Credentials are exfiltrated to Telegram channels after encryption with X25519 ECDH and ChaCha20‑Poly1305, split into 2800‑byte chunks to fit message limits. The malware also propagates by scanning external cloud infrastructure for exposed services, downloading hostname data from Common Crawl, and using Sliver‑based backdoors for various architectures. Inside compromised environments, PCPJack harvests SSH keys, enumerates Kubernetes clusters and Docker daemons, and establishes persistence via systemd services, cron jobs, Redis cron rewrites, or privileged containers. To mitigate the risk, researchers recommend enforcing MFA, using IMDSv2 in AWS, securing Docker and Kubernetes authentication, following least‑privilege principles, and avoiding storing secrets in plaintext.

Key changes

  • PCPJack uses a bootstrap.sh script to install dependencies, create a hidden working directory, and launch monitor.py
  • It explicitly checks for TeamPCP tooling and deletes all related processes, services, containers, files, and persistence artifacts
  • PCPJack targets Docker, Kubernetes, Redis, MongoDB, RayML, and vulnerable web applications, exploiting CVE‑2025‑29927, CVE‑2025‑55182, CVE‑2026‑1357, CVE‑2025‑9501, and CVE‑2025‑48703
  • Credentials are exfiltrated to Telegram channels after encryption with X25519 ECDH and ChaCha20‑Poly1305, split into 2800‑byte chunks
  • The malware propagates by scanning external cloud infrastructure for exposed services and uses Sliver‑based backdoors for x86_64, x86, and ARM
  • Inside compromised environments it harvests SSH keys, enumerates Kubernetes clusters and Docker daemons, and establishes persistence via systemd services, cron jobs, Redis cron rewrites, or privileged containers

Affects

none

Customer impact

Analyzing matches…

Ask about this story

Impact on an agency? Which customers? Compare historically Risks of waiting