PULSE NAME
PCPJack | Cloud Worm Evicts TeamPCP and Steals Credentials at Scale
WHITE AlienVault 2026-05-07 Modified: 2026-05-08
22
IOCs
MEDIUM VOLUME
PCPJack is a sophisticated credential theft framework that propagates across exposed cloud infrastructure while systematically removing artifacts linked to TeamPCP, a threat actor behind notable 2026 supply chain compromises. The toolset harvests credentials from cloud platforms, containers, developer tools, productivity applications, and financial services, exfiltrating data through attacker-controlled infrastructure. It targets exposed Docker, Kubernetes, Redis, MongoDB, RayML services and vulnerable web applications, enabling external propagation and lateral movement. Unlike typical cloud malware, PCPJack deploys no cryptominers, focusing instead on credential theft for monetization through fraud, spam campaigns, extortion, or access resale. The framework uses modular Python scripts orchestrated by a central component, employs Common Crawl data for target selection, and utilizes Telegram for command and control communications.
Indicators of Compromise (22)
All CVE FileHash-MD5 FileHash-SHA1 FileHash-SHA256 URL domain hostname
TYPEINDICATORDESCRIPTIONCREATED
CVE CVE-2025-29927 2026-05-07
CVE CVE-2025-48703 2026-05-07
CVE CVE-2025-55182 2026-05-07
CVE CVE-2025-9501 2026-05-07
CVE CVE-2026-1357 2026-05-07
FileHash-MD5 b8e7288656eca9750a5490aa96d3594b 2026-05-07
FileHash-SHA1 005587975a483876c1fa26b64b418931019be38f 2026-05-07
FileHash-SHA1 01cebc48016395e284ac76afc1816f143ee3e7b6 2026-05-07
FileHash-SHA1 0b86434ca5145636d745222f7e49c903ce6ef538 2026-05-07
FileHash-SHA1 2cd2c5268e41cdece1b0506bcda3b9eba2998119 2026-05-07
FileHash-SHA1 2fab324eb0d927846c8744dc0e217beea65138e0 2026-05-07
FileHash-SHA1 339cbf61c80f757085c5afb7304d69f323bdf87a 2026-05-07
FileHash-SHA1 6060da100b5cd587131a1c11a20d6e0108604744 2026-05-07
FileHash-SHA1 848ef1f638807826586802428a7ebafdc710915c 2026-05-07
FileHash-SHA1 9c7ab48c9fdbbeecdad8433529bdab38584f0e25 2026-05-07
FileHash-SHA1 a20a9924d92c2b06d82b79c0fe87451c650cabec 2026-05-07
FileHash-SHA1 c2dd8051d89c4efa71bd67d2df7d9b4bc3e67810 2026-05-07
FileHash-SHA1 fed52a4bbac7b5b6ae4f76cab3eadd67e79227e3 2026-05-07
FileHash-SHA256 e41c635e4c3514e266d143d544ad1abde5db3dcfe6cccdf9bb7a218003f8ab6a 2026-05-07
URL https://cdn.cloudfront-js.com:8443/u 2026-05-07
domain lastpass-login-help.com 2026-05-07
hostname cdn.cloudfront-js.com 2026-05-07