An aggressive cloud worm, initially programmed to specifically evict tools and artifacts associated with the TeamPCP threat group, traverses exposed cloud infrastructure to systematically harvest credentials from cloud, container, developer, productivity, financial, and messaging services.
Researchers named the toolset PCPJack. Notably, the framework does not deploy cryptominers, a significant departure from standard cloud attack methodologies.
On April 28, 2026, SentinelLABS located a malicious script and subsequently identified the comprehensive credential theft framework. The initial infection vector relies on a script named bootstrap.sh. This script actively downloads functional payloads from an unauthorized Amazon S3 resource hosted at spm-cdn-assets-dist-2026.s3.us-east-2.amazonaws.com.
Once established, PCPJack actively targets and exploits exposed services across the network environment, including Docker, Kubernetes, Redis, MongoDB, RayML, and various vulnerable web applications.
On each compromised host, a script executes a shell pipeline that steals:
To maintain operational persistence and direct the malware, the operators utilize Telegram for external command and control communication.
During the investigation, SentinelLABS also identified a second, distinct toolset hosted on the attacker’s primary payload server. This secondary deployment executes credential harvesting via the check.sh and extractor.py scripts, functioning alongside obfuscated Sliver binaries. It exfiltrates stolen data to a typosquatted domain, cdn.cloudfront-js.com.
Notable targeted services in the second toolset include Anthropic, Digital Ocean, Discord, Google API, Grafana Cloud, HashiCorp Vault, OnePassword, and OpenAI keys.
“ Organizations can defend against these threats by adhering to cloud and web application security best practices ”, the report advises.
A LiteLLM incident that impacted Mercor AI has been linked to TeamPCP. LiteLLM suspects that the compromise originated from the Trivy dependency used in its CI/CD security scanning workflow. Socket also noted that Trivy Docker images pushed to Docker Hub without corresponding GitHub releases contained infostealer IOCs associated with TeamPCP.
Last month, the GrafanaGhost exploit exfiltrated sensitive Grafana business data via indirect prompt injection.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
