logo

TeamPCP Supply Chain Campaign: Activity Through 2026-06-07, (Mon, Jun 8th)

ID: 5af9aa95-60b1-5492-99c5-eab55dcb7d05

STIX ID: report--5af9aa95-60b1-5492-99c5-eab55dcb7d05

Feed Name: SANS ISC Diary

Threat Score
85/100

Date Published: 2026-06-08

Date Updated: 2026-06-09

...
...

This diary reports that CISA added multiple TeamPCP-related CVEs to the KEV catalog and issued an advisory after Nx Console and GitHub repository compromises, while the public release of the Mini Shai-Hulud framework coincided with large npm waves (Wiz’s "Miasma" and StepSecurity’s "Phantom Gyp") that delivered credential-stealing worms via subverted CI pipelines and install-time hooks (including binding.gyp/node-gyp abuse), impacting dozens of packages and many malicious versions; vendors confirm Mini Shai-Hulud lineage but warn copycats are possible, and defenders are advised to rotate CI/CD secrets, review logs, and monitor install-time behavior beyond package.json.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.