TeamPCP Supply Chain Campaign: Activity Through 2026-06-07, (Mon, Jun 8th)
ID: 5af9aa95-60b1-5492-99c5-eab55dcb7d05
STIX ID: report--5af9aa95-60b1-5492-99c5-eab55dcb7d05
Feed Name: SANS ISC Diary
This diary reports that CISA added multiple TeamPCP-related CVEs to the KEV catalog and issued an advisory after Nx Console and GitHub repository compromises, while the public release of the Mini Shai-Hulud framework coincided with large npm waves (Wiz’s "Miasma" and StepSecurity’s "Phantom Gyp") that delivered credential-stealing worms via subverted CI pipelines and install-time hooks (including binding.gyp/node-gyp abuse), impacting dozens of packages and many malicious versions; vendors confirm Mini Shai-Hulud lineage but warn copycats are possible, and defenders are advised to rotate CI/CD secrets, review logs, and monitor install-time behavior beyond package.json.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
