logo

TeamPCP Supply Chain Campaign: Activity Through 2026-05-24, (Mon, May 25th)

ID: 4b45830d-7eb3-5c0c-b9de-d3c011c54a1c

STIX ID: report--4b45830d-7eb3-5c0c-b9de-d3c011c54a1c

Feed Name: SANS ISC Diary

Threat Score
92/100

Date Published: 2026-05-25

Date Updated: 2026-05-25

...
...

A sophisticated supply-chain campaign (attributed to TeamPCP / Mini Shai-Hulud) trojanized components across multiple ecosystems—Visual Studio Marketplace (Nx Console extension), PyPI (Microsoft's durabletask SDK), and the @antv npm ecosystem—resulting in exfiltration of ~3,800 GitHub-internal repositories, widespread credential theft across cloud and developer tooling, and reports of a Linux disk wiper; the report describes attack timelines, affected packages, IOCs, operational details, and defensive actions such as credential rotation and lockfile verification.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.