logo

TeamPCP Supply Chain Campaign: Activity Through 2026-05-17, (Mon, May 18th)

ID: 27e6a464-4b61-5ef2-bbe4-5ff006c90dde

STIX ID: report--27e6a464-4b61-5ef2-bbe4-5ff006c90dde

Feed Name: SANS ISC Diary

Threat Score
92/100

Date Published: 2026-05-18

Date Updated: 2026-05-18

...
...

A TeamPCP supply-chain campaign recently escalated: attackers trojanized the Checkmarx Jenkins AST plugin and deployed a self-spreading Mini Shai-Hulud worm that poisoned roughly 170 npm/PyPI packages (including high-download TanStack packages) using TanStack's CI identity and valid SLSA Build Level 3 provenance; the wave included credential theft, developer-tool persistence, and a probabilistic (1-in-6) destructive wipe targeting Israeli and Iranian locales, with confirmed indicators and active exploitation requiring urgent dependency audits, token rotation, and lockfile pinning.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.