The PCPJack worm highlights how exposed cloud infrastructure can quickly become a large-scale credential theft and lateral movement problem. According to public reporting, PCPJack targets Linux-based cloud systems and exposed services such as Docker, Kubernetes, Redis, MongoDB, RayML, and vulnerable web applications. Once inside, it steals credentials, searches for secrets, establishes persistence, and can move laterally across reachable systems.

What makes this campaign especially concerning is the range of credentials it reportedly targets, including SSH keys, database credentials, Slack tokens, WordPress configurations, OpenAI keys, Anthropic keys, cloud credentials, and developer secrets. The malware also removes TeamPCP artifacts from already-compromised systems, which should not be mistaken for “cleaning.” It is simply one attacker replacing another, the cybercrime version of changing the lock after stealing the house. 

Organizations must treat exposed cloud services, developer systems, and unmanaged workloads as high-risk assets. Protection should include restricting public access to Docker, Kubernetes, Redis, MongoDB, and similar services, enforcing MFA, using least-privilege access, avoiding plaintext secrets, rotating exposed credentials, and monitoring unusual outbound connections. 

This incident is also a strong reminder that credential theft is often the first step toward larger compromise. Security teams need visibility across network traffic, DNS activity, web access, application behavior, and outbound communication to detect suspicious access and command-and-control activity before stolen credentials are abused further.


A new malware framework called PCPJack is stealing credentials from exposed cloud infrastructure while actively removing TeamPCP's access to the systems. [...]

Source: New PCPJack worm steals credentials, cleans TeamPCP infections via Bleeping Computer — published 07 May 2026.