After Replacing TeamPCP Malware, 'PCPJack' Steals Cloud Secrets

2026-05-08T02:52:01Zfca8b7be2b54ec12d3d164b5ce39d1062d2aeeba34fde105cd2577064f8ae89b
App-Bound EncryptionCLIChromeClaudeCopilotGeminiMFA-bypass','CloudZ RAT','Pheno','Silver Fox','ABCDoor','ValleyRMicrosoft EdgePCPJackRMMSAP-packagesTeamPCPTrustFallVoidStealerWindows Phone Linkactive-exploitauth-bypasscPanelcloud-secretscode-executionnpm-compromiseparquet-filespassword-leakphishingsupply-chain

What happened

This collection highlights an escalation in cloud- and supply-chain-focused attacks and several active exploit vectors: a new TeamPCP variant called PCPJack uses Parquet files for stealthy, pre-validated discovery to steal cloud secrets; TeamPCP supply-chain compromises (including npm and SAP packages) continue to expand; the TrustFall issue enables code execution via malicious repos in multiple LLM/CLI tools (Claude Code, Cursor CLI, Gemini CLI, Copilot CLI); VoidStealer authors bypassed Google App-Bound Encryption to aid infostealers; a critical cPanel authentication-bypass is being actively

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
darkreading
Record identifier
fca8b7be2b54ec12d3d164b5ce39d1062d2aeeba34fde105cd2577064f8ae89b
Enrichment time
2026-05-08T02:52:01Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.