ctipilot.ch

TeamPCP

actor · actor:teampcp single-source

Threat actor targeting software supply chains; operator of the Mini Shai-Hulud npm worm family and the SANDCLOCK Checkmarx Jenkins-plugin backdoor, with victims including OpenAI.

Coverage timeline
35
first 2026-05-04 → last 2026-08-16
Peak priority
high
13 high · 22 notable
Sources cited
113
55 hosts
Sections touched
11
active-threats, deep-dive, research
Co-occurring entities
8
see Related entities below
ATT&CK techniques
40
pinned v19.2 · see below
2026-05-0435 appearances2026-08-16

ATT&CK techniques

40 techniques observed across 17 entries — derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)

Reconnaissance TA0043

T1593Search Open Websites/Domains×1

Adversaries may search freely available websites and/or domains for information about victims that can be used during targeting. Information about victims may be available in various online sites, such as social media, new sites, or those hosting information about business operations such as hiring or requested/rewarded contracts.

Evidence: 2026-05-13/mini-shai-hulud-s-github-actions-pwn-request-oidc-token-thef · ATT&CK page ↗

Resource Development TA0042

T1583.001Acquire Infrastructure: Domains×1

Adversaries may acquire domains that can be used during targeting. Domain names are the human readable names used to represent one or more IP addresses. They can be purchased or, in some cases, acquired for free.

Evidence: 2026-05-13/mini-shai-hulud-s-github-actions-pwn-request-oidc-token-thef · ATT&CK page ↗

T1650Acquire Access×1

Adversaries may purchase or otherwise acquire an existing access to a target system or network. A variety of online services and initial access broker networks are available to sell access to previously compromised systems. In some cases, adversary groups may form partnerships to share compromised systems with each other.

Evidence: 2026-05-22/teampcp-mini-shai-hulud-unit-42-and-stepsecurity-confirm-sls · ATT&CK page ↗

Initial Access TA0001

T1078Valid Accounts×1

Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.

Evidence: 2026-05-21/verizon-2026-dbir-vulnerability-exploitation-overtakes-crede · ATT&CK page ↗

T1078.004Valid Accounts: Cloud Accounts×6

Valid accounts in cloud environments may allow adversaries to perform actions to achieve Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Cloud accounts are those created and configured by an organization for use by users, remote support, services, or for administration of resources within a cloud service provider or SaaS application. Cloud Accounts can exist solely in the cloud; alternatively, they may be hybrid-joined between on-premises systems and the cloud through syncing or federation with other identity sources such as Windows Active Directory.

Evidence: 2026-08-16/weekly-w33-developer-credential-audits-wrong-artefact · 2026-08-15/trivy-not-litellm-behind-2500-org-credential-collection · 2026-08-08/wiz-cloud-threat-highlights-h1-2026-ai-toolchain-exposure · 2026-05-21/teampcp-mini-shai-hulud-campaign-github-itself-breached-3-80 · 2026-05-13/mini-shai-hulud-teampcp-worm-hits-tanstack-uipath-mistral-ai · 2026-05-13/mini-shai-hulud-s-github-actions-pwn-request-oidc-token-thef · ATT&CK page ↗

T1190Exploit Public-Facing Application×3

Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.

Evidence: 2026-08-08/wiz-cloud-threat-highlights-h1-2026-ai-toolchain-exposure · 2026-05-21/verizon-2026-dbir-vulnerability-exploitation-overtakes-crede · 2026-05-12/gtig-ai-threat-tracker-may-2026-first-confirmed-ai-generated · ATT&CK page ↗

T1195Supply Chain Compromise×3

Adversaries may manipulate products or product delivery mechanisms prior to receipt by a final consumer for the purpose of data or system compromise.

Evidence: 2026-05-24/packagist-supply-chain-wave-laravel-lang-autoloader-backdoor · 2026-05-21/verizon-2026-dbir-vulnerability-exploitation-overtakes-crede · 2026-05-12/teampcp-unc6780-pcpjack-ecosystem-backdoors-the-checkmarx-je · ATT&CK page ↗

T1195.001Supply Chain Compromise: Compromise Software Dependencies and Development Tools×3

Adversaries may manipulate software dependencies and development tools prior to receipt by a final consumer for the purpose of data or system compromise. Applications often depend on external software to function properly. Popular open source projects that are used as dependencies in many applications, such as pip and NPM packages, may be targeted as a means to add malicious code to users of the dependency. This may also include abandoned packages, which in some cases could be re-registered by threat actors after being removed by adversaries. Adversaries may also employ "typosquatting" or name-confusion by choosing names similar to existing popular libraries or packages in order to deceive a user.

Evidence: 2026-08-08/wiz-cloud-threat-highlights-h1-2026-ai-toolchain-exposure · 2026-08-02/weekly-w31-open-source-supply-chain-status · 2026-07-14/talos-serpents-tongue-python-package-code-execution-taxonomy · ATT&CK page ↗

T1195.002Supply Chain Compromise: Compromise Software Supply Chain×10

Adversaries may manipulate application software prior to receipt by a final consumer for the purpose of data or system compromise. Supply chain compromise of software can take place in a number of ways, including manipulation of the application source code, manipulation of the update/distribution mechanism for that software, or replacing compiled releases with a modified version.

Evidence: 2026-08-16/weekly-w33-developer-credential-audits-wrong-artefact · 2026-08-15/trivy-not-litellm-behind-2500-org-credential-collection · 2026-08-02/weekly-w31-open-source-supply-chain-status · 2026-05-28/nx-console-tanstack-daemon-tools-supply-chain-cascade-lands · 2026-05-24/packagist-supply-chain-wave-laravel-lang-autoloader-backdoor · 2026-05-19/teampcp-shai-hulud-first-copycat-wave-phantom-bot-ssh-cloud +4 more · ATT&CK page ↗

T1199Trusted Relationship×2

Adversaries may breach or otherwise leverage organizations who have access to intended victims. Access through trusted third party relationship abuses an existing connection that may not be protected or receives less scrutiny than standard mechanisms of gaining access to a network.

Evidence: 2026-08-02/weekly-w31-open-source-supply-chain-status · 2026-05-13/mini-shai-hulud-s-github-actions-pwn-request-oidc-token-thef · ATT&CK page ↗

Execution TA0002

T1059Command and Scripting Interpreter×1

Adversaries may abuse command and script interpreters to execute commands, scripts, or binaries. These interfaces and languages provide ways of interacting with computer systems and are a common feature across many different platforms. Most systems come with some built-in command-line interface and scripting capabilities, for example, macOS and Linux distributions include some flavor of Unix Shell while Windows installations include the Windows Command Shell and PowerShell.

Evidence: 2026-05-24/packagist-supply-chain-wave-laravel-lang-autoloader-backdoor · ATT&CK page ↗

T1059.004Command and Scripting Interpreter: Unix Shell×2

Adversaries may abuse Unix shell commands and scripts for execution. Unix shells are the primary command prompt on Linux, macOS, and ESXi systems, though many variations of the Unix shell exist (e.g. sh, ash, bash, zsh, etc.) depending on the specific OS or distribution. Unix shells can control every aspect of a system, with certain commands requiring elevated privileges.

Evidence: 2026-05-24/packagist-supply-chain-wave-laravel-lang-autoloader-backdoor · 2026-05-15/datadog-security-labs-analyzes-leaked-teampcp-shai-hulud-off · ATT&CK page ↗

T1059.006Command and Scripting Interpreter: Python×1

Adversaries may abuse Python commands and scripts for execution. Python is a very popular scripting/programming language, with capabilities to perform many functions. Python can be executed interactively from the command-line (via the <code>python.exe</code> interpreter) or via scripts (.py) that can be written and distributed to different systems. Python code can also be compiled into binary executables.

Evidence: 2026-07-14/talos-serpents-tongue-python-package-code-execution-taxonomy · ATT&CK page ↗

T1204User Execution×1

An adversary may rely upon specific actions by a user in order to gain execution. Users may be subjected to social engineering to get them to execute malicious code by, for example, opening a malicious document file or link. These user actions will typically be observed as follow-on behavior from forms of Phishing.

Evidence: 2026-05-24/packagist-supply-chain-wave-laravel-lang-autoloader-backdoor · ATT&CK page ↗

T1204.002User Execution: Malicious File×1

An adversary may rely upon a user opening a malicious file in order to gain execution. Users may be subjected to social engineering to get them to open a file that will lead to code execution. This user action will typically be observed as follow-on behavior from Spearphishing Attachment. Adversaries may use several types of files that require a user to execute them, including .doc, .pdf, .xls, .rtf, .scr, .exe, .lnk, .pif, .cpl, .reg, and .iso.

Evidence: 2026-05-24/packagist-supply-chain-wave-laravel-lang-autoloader-backdoor · ATT&CK page ↗

T1574.007Hijack Execution Flow: Path Interception by PATH Environment Variable×1

Adversaries may execute their own malicious payloads by hijacking environment variables used to load libraries. The PATH environment variable contains a list of directories (User and System) that the OS searches sequentially through in search of the binary that was called from a script or the command line.

Evidence: 2026-07-14/talos-serpents-tongue-python-package-code-execution-taxonomy · ATT&CK page ↗

Persistence TA0003

T1078Valid Accounts×1

Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.

Evidence: 2026-05-21/verizon-2026-dbir-vulnerability-exploitation-overtakes-crede · ATT&CK page ↗

T1078.004Valid Accounts: Cloud Accounts×6

Valid accounts in cloud environments may allow adversaries to perform actions to achieve Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Cloud accounts are those created and configured by an organization for use by users, remote support, services, or for administration of resources within a cloud service provider or SaaS application. Cloud Accounts can exist solely in the cloud; alternatively, they may be hybrid-joined between on-premises systems and the cloud through syncing or federation with other identity sources such as Windows Active Directory.

Evidence: 2026-08-16/weekly-w33-developer-credential-audits-wrong-artefact · 2026-08-15/trivy-not-litellm-behind-2500-org-credential-collection · 2026-08-08/wiz-cloud-threat-highlights-h1-2026-ai-toolchain-exposure · 2026-05-21/teampcp-mini-shai-hulud-campaign-github-itself-breached-3-80 · 2026-05-13/mini-shai-hulud-teampcp-worm-hits-tanstack-uipath-mistral-ai · 2026-05-13/mini-shai-hulud-s-github-actions-pwn-request-oidc-token-thef · ATT&CK page ↗

T1505.003Server Software Component: Web Shell×1

Adversaries may backdoor web servers with web shells to establish persistent access to systems. A Web shell is a Web script that is placed on an openly accessible Web server to allow an adversary to access the Web server as a gateway into a network. A Web shell may provide a set of functions to execute or a command-line interface on the system that hosts the Web server.

Evidence: 2026-05-13/mini-shai-hulud-s-github-actions-pwn-request-oidc-token-thef · ATT&CK page ↗

Privilege Escalation TA0004

T1078Valid Accounts×1

Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.

Evidence: 2026-05-21/verizon-2026-dbir-vulnerability-exploitation-overtakes-crede · ATT&CK page ↗

T1078.004Valid Accounts: Cloud Accounts×6

Valid accounts in cloud environments may allow adversaries to perform actions to achieve Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Cloud accounts are those created and configured by an organization for use by users, remote support, services, or for administration of resources within a cloud service provider or SaaS application. Cloud Accounts can exist solely in the cloud; alternatively, they may be hybrid-joined between on-premises systems and the cloud through syncing or federation with other identity sources such as Windows Active Directory.

Evidence: 2026-08-16/weekly-w33-developer-credential-audits-wrong-artefact · 2026-08-15/trivy-not-litellm-behind-2500-org-credential-collection · 2026-08-08/wiz-cloud-threat-highlights-h1-2026-ai-toolchain-exposure · 2026-05-21/teampcp-mini-shai-hulud-campaign-github-itself-breached-3-80 · 2026-05-13/mini-shai-hulud-teampcp-worm-hits-tanstack-uipath-mistral-ai · 2026-05-13/mini-shai-hulud-s-github-actions-pwn-request-oidc-token-thef · ATT&CK page ↗

Stealth TA0005

T1027Obfuscated Files or Information×2

Adversaries may attempt to make an executable or file difficult to discover or analyze by encrypting, encoding, or otherwise obfuscating its contents on the system or in transit. This is common behavior that can be used across different platforms and the network to evade defenses.

Evidence: 2026-08-02/weekly-w31-open-source-supply-chain-status · 2026-05-12/gtig-ai-threat-tracker-may-2026-first-confirmed-ai-generated · ATT&CK page ↗

T1036Masquerading×1

Adversaries may attempt to manipulate features of their artifacts to make them appear legitimate or benign to users and/or security tools. Masquerading occurs when the name or location of an object, legitimate or malicious, is manipulated or abused for the sake of evading defenses and observation. This may include manipulating file metadata, tricking users into misidentifying the file type, and giving legitimate task or service names.

Evidence: 2026-05-24/packagist-supply-chain-wave-laravel-lang-autoloader-backdoor · ATT&CK page ↗

T1036.005Masquerading: Match Legitimate Resource Name or Location×1

Adversaries may match or approximate the name or location of legitimate files, Registry keys, or other resources when naming/placing them. This is done for the sake of evading defenses and observation.

Evidence: 2026-05-24/packagist-supply-chain-wave-laravel-lang-autoloader-backdoor · ATT&CK page ↗

T1078Valid Accounts×1

Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.

Evidence: 2026-05-21/verizon-2026-dbir-vulnerability-exploitation-overtakes-crede · ATT&CK page ↗

T1078.004Valid Accounts: Cloud Accounts×6

Valid accounts in cloud environments may allow adversaries to perform actions to achieve Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Cloud accounts are those created and configured by an organization for use by users, remote support, services, or for administration of resources within a cloud service provider or SaaS application. Cloud Accounts can exist solely in the cloud; alternatively, they may be hybrid-joined between on-premises systems and the cloud through syncing or federation with other identity sources such as Windows Active Directory.

Evidence: 2026-08-16/weekly-w33-developer-credential-audits-wrong-artefact · 2026-08-15/trivy-not-litellm-behind-2500-org-credential-collection · 2026-08-08/wiz-cloud-threat-highlights-h1-2026-ai-toolchain-exposure · 2026-05-21/teampcp-mini-shai-hulud-campaign-github-itself-breached-3-80 · 2026-05-13/mini-shai-hulud-teampcp-worm-hits-tanstack-uipath-mistral-ai · 2026-05-13/mini-shai-hulud-s-github-actions-pwn-request-oidc-token-thef · ATT&CK page ↗

T1140Deobfuscate/Decode Files or Information×1

Adversaries may use Obfuscated Files or Information to hide artifacts of an intrusion from analysis. They may require separate mechanisms to decode or deobfuscate that information depending on how they intend to use it. Methods for doing that include built-in functionality of malware or by using utilities present on the system.

Evidence: 2026-05-24/packagist-supply-chain-wave-laravel-lang-autoloader-backdoor · ATT&CK page ↗

T1574.007Hijack Execution Flow: Path Interception by PATH Environment Variable×1

Adversaries may execute their own malicious payloads by hijacking environment variables used to load libraries. The PATH environment variable contains a list of directories (User and System) that the OS searches sequentially through in search of the binary that was called from a script or the command line.

Evidence: 2026-07-14/talos-serpents-tongue-python-package-code-execution-taxonomy · ATT&CK page ↗

Defense Impairment TA0112

T1553Subvert Trust Controls×1

Adversaries may undermine security controls that will either warn users of untrusted activity or prevent execution of untrusted programs. Operating systems and security products may contain mechanisms to identify programs or websites as possessing some level of trust. Examples of such features would include a program being allowed to run because it is signed by a valid code signing certificate, a program prompting the user with a warning because it has an attribute set from being downloaded from the Internet, or getting an indication that you are about to connect to an untrusted site.

Evidence: 2026-05-12/gtig-ai-threat-tracker-may-2026-first-confirmed-ai-generated · ATT&CK page ↗

T1553.002Subvert Trust Controls: Code Signing×1

Adversaries may create, acquire, or steal code signing materials to sign their malware or tools. Code signing provides a level of authenticity on a binary from the developer and a guarantee that the binary has not been tampered with. The certificates used during an operation may be created, acquired, or stolen by the adversary. Unlike Invalid Code Signature, this activity will result in a valid signature.

Evidence: 2026-05-13/mini-shai-hulud-s-github-actions-pwn-request-oidc-token-thef · ATT&CK page ↗

Credential Access TA0006

T1003.007OS Credential Dumping: Proc Filesystem×1

Adversaries may gather credentials from the proc filesystem or `/proc`. The proc filesystem is a pseudo-filesystem used as an interface to kernel data structures for Linux based systems managing virtual memory. For each process, the `/proc/<PID>/maps` file shows how memory is mapped within the process’s virtual address space. And `/proc/<PID>/mem`, exposed for debugging purposes, provides access to the process’s virtual address space.

Evidence: 2026-05-13/mini-shai-hulud-s-github-actions-pwn-request-oidc-token-thef · ATT&CK page ↗

T1110Brute Force×1

Adversaries may use brute force techniques to gain access to accounts when passwords are unknown or when password hashes are obtained. Without knowledge of the password for an account or set of accounts, an adversary may systematically guess the password using a repetitive or iterative mechanism. Brute forcing passwords can take place via interaction with a service that will check the validity of those credentials or offline against previously acquired credential data, such as password hashes.

Evidence: 2026-05-21/verizon-2026-dbir-vulnerability-exploitation-overtakes-crede · ATT&CK page ↗

T1552Unsecured Credentials×4

Adversaries may search compromised systems to find and obtain insecurely stored credentials. These credentials can be stored and/or misplaced in many locations on a system, including plaintext files (e.g. Shell History), operating system or application-specific repositories (e.g. Credentials in Registry), or other specialized files/artifacts (e.g. Private Keys).

Evidence: 2026-08-08/wiz-cloud-threat-highlights-h1-2026-ai-toolchain-exposure · 2026-05-24/packagist-supply-chain-wave-laravel-lang-autoloader-backdoor · 2026-05-12/teampcp-unc6780-pcpjack-ecosystem-backdoors-the-checkmarx-je · 2026-05-12/gtig-ai-threat-tracker-may-2026-first-confirmed-ai-generated · ATT&CK page ↗

T1552.001Unsecured Credentials: Credentials In Files×10

Adversaries may search local file systems and remote file shares for files containing insecurely stored credentials. These can be files created by users to store their own credentials, shared credential stores for a group of individuals, configuration files containing passwords for a system or service, or source code/binary files containing embedded passwords.

Evidence: 2026-08-16/weekly-w33-developer-credential-audits-wrong-artefact · 2026-08-15/trivy-not-litellm-behind-2500-org-credential-collection · 2026-05-28/nx-console-tanstack-daemon-tools-supply-chain-cascade-lands · 2026-05-24/packagist-supply-chain-wave-laravel-lang-autoloader-backdoor · 2026-05-22/teampcp-mini-shai-hulud-unit-42-and-stepsecurity-confirm-sls · 2026-05-19/teampcp-shai-hulud-first-copycat-wave-phantom-bot-ssh-cloud +4 more · ATT&CK page ↗

T1552.005Unsecured Credentials: Cloud Instance Metadata API×1

Adversaries may attempt to access the Cloud Instance Metadata API to collect credentials and other sensitive data.

Evidence: 2026-08-16/weekly-w33-developer-credential-audits-wrong-artefact · ATT&CK page ↗

T1606.002Forge Web Credentials: SAML Tokens×1

An adversary may forge SAML tokens with any permissions claims and lifetimes if they possess a valid SAML token-signing certificate. The default lifetime of a SAML token is one hour, but the validity period can be specified in the <code>NotOnOrAfter</code> value of the <code>conditions ...</code> element in a token. This value can be changed using the <code>AccessTokenLifetime</code> in a <code>LifetimeTokenPolicy</code>. Forged SAML tokens enable adversaries to authenticate across services that use SAML 2.0 as an SSO (single sign-on) mechanism.

Evidence: 2026-05-13/mini-shai-hulud-s-github-actions-pwn-request-oidc-token-thef · ATT&CK page ↗

Discovery TA0007

T1083File and Directory Discovery×1

Adversaries may enumerate files and directories or may search in specific locations of a host or network share for certain information within a file system. Adversaries may use the information from File and Directory Discovery during automated discovery to shape follow-on behaviors, including whether or not the adversary fully infects the target and/or attempts specific actions.

Evidence: 2026-05-24/packagist-supply-chain-wave-laravel-lang-autoloader-backdoor · ATT&CK page ↗

Lateral Movement TA0008

T1550.001Use Alternate Authentication Material: Application Access Token×1

Adversaries may use stolen application access tokens to bypass the typical authentication process and access restricted accounts, information, or services on remote systems. These tokens are typically stolen from users or services and used in lieu of login credentials.

Evidence: 2026-08-16/weekly-w33-developer-credential-audits-wrong-artefact · ATT&CK page ↗

T1570Lateral Tool Transfer×1

Adversaries may transfer tools or other files between systems in a compromised environment. Once brought into the victim environment (i.e., Ingress Tool Transfer) files may then be copied from one system to another to stage adversary tools or other files over the course of an operation.

Evidence: 2026-05-21/teampcp-mini-shai-hulud-campaign-github-itself-breached-3-80 · ATT&CK page ↗

Collection TA0009

T1213.003Data from Information Repositories: Code Repositories×1

Adversaries may leverage code repositories to collect valuable information. Code repositories are tools/services that store source code and automate software builds. They may be hosted internally or privately on third party sites such as Github, GitLab, SourceForge, and BitBucket. Users typically interact with code repositories through a web application or command-line utilities such as git.

Evidence: 2026-08-16/weekly-w33-developer-credential-audits-wrong-artefact · ATT&CK page ↗

T1530Data from Cloud Storage×1

Adversaries may access data from cloud storage.

Evidence: 2026-05-28/nx-console-tanstack-daemon-tools-supply-chain-cascade-lands · ATT&CK page ↗

Command and Control TA0011

T1071Application Layer Protocol×1

Adversaries may communicate using OSI application layer protocols to avoid detection/network filtering by blending in with existing traffic. Commands to the remote system, and often the results of those commands, will be embedded within the protocol traffic between the client and server.

Evidence: 2026-05-12/gtig-ai-threat-tracker-may-2026-first-confirmed-ai-generated · ATT&CK page ↗

T1071.001Application Layer Protocol: Web Protocols×1

Adversaries may communicate using application layer protocols associated with web traffic to avoid detection/network filtering by blending in with existing traffic. Commands to the remote system, and often the results of those commands, will be embedded within the protocol traffic between the client and server.

Evidence: 2026-05-12/gtig-ai-threat-tracker-may-2026-first-confirmed-ai-generated · ATT&CK page ↗

T1105Ingress Tool Transfer×1

Adversaries may transfer tools or other files from an external system into a compromised environment. Tools or files may be copied from an external adversary-controlled system to the victim network through the command and control channel or through alternate protocols such as ftp. Once present, adversaries may also transfer/spread tools between victim devices within a compromised environment (i.e. Lateral Tool Transfer).

Evidence: 2026-08-02/weekly-w31-open-source-supply-chain-status · ATT&CK page ↗

Exfiltration TA0010

T1041Exfiltration Over C2 Channel×1

Adversaries may steal data by exfiltrating it over an existing command and control channel. Stolen data is encoded into the normal communications channel using the same protocol as command and control communications.

Evidence: 2026-05-19/teampcp-shai-hulud-first-copycat-wave-phantom-bot-ssh-cloud · ATT&CK page ↗

T1567Exfiltration Over Web Service×2

Adversaries may use an existing, legitimate external Web service to exfiltrate data rather than their primary command and control channel. Popular Web services acting as an exfiltration mechanism may give a significant amount of cover due to the likelihood that hosts within a network are already communicating with them prior to compromise. Firewall rules may also already exist to permit traffic to these services.

Evidence: 2026-08-16/weekly-w33-developer-credential-audits-wrong-artefact · 2026-05-28/nx-console-tanstack-daemon-tools-supply-chain-cascade-lands · ATT&CK page ↗

Impact TA0040

T1485Data Destruction×1

Adversaries may destroy data and files on specific systems or in large numbers on a network to interrupt availability to systems, services, and network resources. Data destruction is likely to render stored data irrecoverable by forensic techniques through overwriting files or data on local and remote drives. Common operating system file deletion commands such as <code>del</code> and <code>rm</code> often only remove pointers to files without wiping the contents of the files themselves, making the files recoverable by proper forensic methodology. This behavior is distinct from Disk Content Wipe and Disk Structure Wipe because individual files are destroyed rather than sections of a storage disk or the disk's logical structure.

Evidence: 2026-05-26/teampcp-mini-shai-hulud-framework-open-sourced-microsoft-pyp · ATT&CK page ↗

Story timeline

  1. 2026-08-16Three developer-credential findings this week each show an estate auditing the wrong thing — the wrong package, the wrong incident class, and repositories nobody counted as company assets at all
    weekly-researchW33's supply-chain work was about scoping errors: 95% of one 'breach' traced to a different vendor, and repo theft is a secrets incident
  2. 2026-08-15The '2,500-organisation LiteLLM breach' was mostly not LiteLLM: 95% of the identified victims were collected before the poisoned packages existed, through the Trivy scanner their pipelines pulled unpinned
    active-threatsSOCRadar's row-level re-analysis moves the blast radius upstream to a compromised security scanner — which changes what a CI/CD estate has to audit
  3. 2026-08-08Wiz Cloud Threat Highlights H1 2026: LiteLLM had four separate security events in six months, unauthenticated MCP endpoints turned up across hundreds of environments, and a new extortion actor goes after service accounts rather than people
    researchThe AI toolchain became a cloud attack surface with its own recurring vulnerability cadence, and the credentials it holds are non-human
  4. 2026-08-02Open-source supply-chain wave status: a second vendor assesses the escalation at high confidence, the CI trigger that hands over base-repository secrets is named, and two vendors independently attribute the axios compromise to the same DPRK cluster
    weekly-long-runningSupply-chain status — cross-vendor DPRK attribution on axios, and pull_request_target named as the CI lever
  5. 2026-07-14Cisco Talos maps the full taxonomy of Python-package build-time and import-time code execution ("The Serpent's Tongue")
    researchTalos catalogues where malicious Python packages execute code across the install lifecycle, including persistent .pth and site-hook footholds
  6. 2026-06-27Miasma / "Mini Shai-Hulud" npm worm runs a new wave across LeoPlatform/RStreams packages
    updates
  7. 2026-06-14Shai-Hulud / Miasma supply-chain worm lineage — open-sourced, ported to PyPI, and a 1,500-package AUR wave
    weekly-multi-day
  8. 2026-06-12npm v12 will disable install scripts by default — audit CI/CD pipelines before July
    research
  9. 2026-06-09TeamPCP open-sources its Mini Shai-Hulud framework, spawning a new "Phantom Gyp" derivative
    active-threats
  10. 2026-06-06Miasma supply-chain worm reaches 73 Microsoft GitHub repositories, adds Azure credential collectors
    updates
  11. 2026-06-02"Miasma" worm backdoors 32 Red Hat Cloud Services npm packages via OIDC trusted-publishing abuse
    active-threats
  12. 2026-05-28Nx Console / TanStack / DAEMON Tools supply-chain cascade lands three CISA KEV entries
    deep-dive
  13. 2026-05-26TeamPCP / Mini Shai-Hulud — framework open-sourced, Microsoft PyPI SDK trojanised with a wiper stage, forged Sigstore badges
    updates
  14. 2026-05-25Mini Shai-Hulud / TrapDoor — the supply-chain worm goes cross-ecosystem, open-source and destructive
    weekly-multi-day
  15. 2026-05-25Mini Shai-Hulud / TeamPCP — @antv npm wave and confirmed Maven Central poisoning; Cargo still un-hit
    weekly-long-running
  16. 2026-05-24Packagist supply-chain wave: Laravel-Lang autoloader backdoor and the cross-ecosystem postinstall strand
    deep-dive
  17. 2026-05-24npm ships 2FA-gated "staged publishing" GA in response to the 2026 supply-chain worm waves
    active-threats
  18. 2026-05-22TeamPCP Mini Shai-Hulud — Unit 42 and StepSecurity confirm SLSA Build Level 3 attestation invalidated as integrity gate
    updates
  19. 2026-05-21Verizon 2026 DBIR: vulnerability exploitation overtakes credentials as primary breach vector for the first time in 19 years
    deep-dive
  20. 2026-05-21TeamPCP / Mini Shai-Hulud campaign — GitHub itself breached (~3,800 internal repos via poisoned VS Code extension), Microsoft durabletask PyPI worm propagates via AWS SSM and kubectl exec, Grafana confirms missed-token-rotation root cause
    updatesTeamPCP / Mini Shai-Hulud campaign — GitHub itself breached (~3,800 internal repos via poisoned VS Code extension), Microsoft durabletask PyPI worm propagates
  21. 2026-05-19TeamPCP / Shai-Hulud — first copycat wave (Phantom Bot + SSH/cloud stealers), Checkmarx Jenkins plugin trojanised again, PCPJack rival worm hits exposed cloud services
    updatesTeamPCP / Shai-Hulud — first copycat wave (Phantom Bot + SSH/cloud stealers), Checkmarx Jenkins plugin trojanised again, PCPJack rival worm hits exposed cloud
  22. 2026-05-18TeamPCP / Mini Shai-Hulud / Megalodon — the open-sourced supply-chain worm became commodity infrastructure this week
    weekly-multi-day
  23. 2026-05-15TeamPCP / Mini Shai-Hulud — OpenAI named as victim; code-signing certificate rotation enforced for all macOS apps
    updates
  24. 2026-05-15Sophos 2026 State of Identity Security: Switzerland records highest identity-breach incidence globally; energy and federal government hardest-hit sectors
    research
  25. 2026-05-15Datadog Security Labs analyzes leaked TeamPCP "Shai-Hulud" offensive framework source code
    active-threats
  26. 2026-05-13Mini Shai-Hulud — TeamPCP worm hits TanStack, UiPath, Mistral AI, OpenSearch (160+ package versions)
    updates
  27. 2026-05-13Mini Shai-Hulud's GitHub Actions Pwn-Request → OIDC Token Theft Chain
    deep-dive
  28. 2026-05-12TeamPCP (UNC6780 / PCPJack ecosystem) backdoors the Checkmarx Jenkins AST plugin — third Checkmarx supply-chain compromise in three months, SANDCLOCK exfiltrates every CI secret reachable from the runner
    trending-vulnerabilitiesTeamPCP (UNC6780 / PCPJack ecosystem) backdoors the Checkmarx Jenkins AST plugin — third Checkmarx supply-chain compromise in three months, SANDCLOCK
  29. 2026-05-12GTIG AI Threat Tracker (May 2026): First Confirmed AI-Generated Zero-Day Exploit ITW and the Behavioural Class of AI-Augmented Malware
    deep-dive
  30. 2026-05-11TeamPCP / Mini Shai-Hulud (ShinyHunters / WorldLeaks adjacent) — wave 4 + framework leak + IDE persistence
    weekly-long-running
  31. 2026-05-11TeamPCP / Mini Shai-Hulud npm supply-chain worm — wave 4 + framework source leak
    weekly-multi-day
  32. 2026-05-11Looking ahead — 2026-W20
    weekly-looking-ahead
  33. 2026-05-11Datadog Security Labs — Shai-Hulud framework static analysis
    weekly-annual-reports
  34. 2026-05-11AI tooling SaaS and developer toolchain
    weekly-sector-patterns
  35. 2026-05-04TeamPCP → PCPJack — cloud-worm successor evicting prior operator artefacts
    weekly-long-running

Relationships explore in graph

Typed, source-stated connections from the entity registry — each edge cites the entry whose reporting establishes it.

attributed activity

Where this entity is cited

  • updates8
  • deep-dive5
  • active-threats5
  • weekly-long-running4
  • weekly-multi-day4
  • research4
  • weekly-sector-patterns1
  • weekly-annual-reports1
  • weekly-looking-ahead1
  • trending-vulnerabilities1
  • weekly-research1

Source distribution

  • thehackernews.com14 (12%)
  • attack.mitre.org12 (11%)
  • wiz.io7 (6%)
  • helpnetsecurity.com6 (5%)
  • nvd.nist.gov5 (4%)
  • socket.dev5 (4%)
  • securityweek.com4 (4%)
  • bleepingcomputer.com3 (3%)
  • other57 (50%)

Co-occurring entities

Derived — referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.

All cited sources (113)

Entries about TeamPCP (35)

2026-08-16 · view entry permalink →

NOTABLENATOB2

Three developer-credential findings this week each show an estate auditing the wrong thing — the wrong package, the wrong incident class, and repositories nobody counted as company assets at all

Supply-chain research usually asks how the attacker got in. Three findings this week ask a different question, and give the same unwelcome answer: the organisations that responded to these incidents looked in the wrong place, and their audits came back clean for that reason.

The clearest case is a correction to a story most estates have already closed. SOCRadar re-analysed the exposure dataset behind the widely reported compromise of around 2,500 organisations through LiteLLM and found that 2,085 of the 2,188 identified organisations — 95% — show collection activity beginning before the poisoned LiteLLM packages reached PyPI on 24 March. The collection instead tracks the compromise of Aqua Security's Trivy scanner, whose poisoned release LiteLLM's own continuous-integration pipeline pulled unpinned (SOCRadar, 2026-08-13), a re-attribution SecurityWeek reported independently (SecurityWeek, 2026-08-14). The operational consequence is specific and awkward: an estate that asked "did we install the affected LiteLLM versions on 24 March" asked about the wrong package on the wrong date, got a negative answer, and closed a genuine exposure. The artefact that actually needed auditing is a security scanner — a tool most CI pipelines pull by mutable tag precisely because it is a security tool and expected to be current.

Wiz's Customer Incident Response Team published the second, a technical playbook for a campaign run against multiple customer organisations that abused compromised GitHub Personal Access Tokens for mass repository exfiltration. The attack shape is worth knowing because it is loud in exactly one place: reconnaissance through GitHub API queries to enumerate everything the token could reach, a small number of validation clones, then bulk theft — "Between 09:14 and 14:55 UTC, the actor used 102 AWS IP addresses located in the ca-central-1 region to clone up to thousands of repositories per organization" (Wiz, 2026-08-13). Wiz's framing is the part that changes response practice: "Repository exfiltration should be treated as more than source code theft. Repositories frequently contain cloud credentials, SaaS tokens, internal documentation, private keys, and sensitive data that can significantly increase the impact of a compromise." An organisation that scopes this as intellectual-property loss writes a legal assessment; an organisation that scopes it as a secrets incident rotates cloud credentials and hunts for their use, which is the difference between the incident ending and continuing. A companion Wiz post reports that across the Forbes AI 50 the firm found "56% of company-impacting secrets lived in employees' personal repositories, where most security programs have no visibility" (Wiz, 2026-08-13) — a third scoping error, this time in what counts as a company asset at all.

The week's third finding supplies the substrate the other two run on. CERT Intrinsec's forensic-artefact series for autonomous coding-agent command-line tools documents that these tools write their state to predictable per-user paths — OpenCode keeping a database of sessions, messages and workspaces alongside a file holding authentication information including API keys, and OpenAI Codex keeping authentication material in auth.json with the operator's prompt history in history.jsonl (CERT Intrinsec, 2026-07-31). Read as an investigator's map that is useful; read as an attacker's inventory it says that any foothold on a developer or build host now reaches cleartext provider credentials at a known location, without touching a keychain or a secrets manager.

Triage: the GitHub-side observable is a shape rather than an indicator, and it is one legitimate tooling does not produce. Enterprise audit-log events showing a single token or principal issuing a burst of repository-clone or archive-download calls, spanning many repositories including ones that principal has never touched, from source addresses distributed across a narrow cloud-provider range within a short window, is anomalous by construction: continuous-integration systems clone repeatedly but from a small, stable set of known egress addresses and against the repositories they build, and a developer clones interactively at human rates. The preceding phase is quieter and worth pairing with it — a rise in API enumeration calls from a token that normally only clones. On developer and build hosts, the corresponding host-side signal is any process other than the agent itself reading those documented credential paths.

Between 09:14 and 14:55 UTC, the actor used 102 AWS IP addresses located in the ca-central-1 region to clone up to thousands of repositories per organization.

Repository exfiltration should be treated as more than source code theft. Repositories frequently contain cloud credentials, SaaS tokens, internal documentation, private keys, and sensitive data that can significantly increase the impact of a compromise.

Wiz (Customer Incident Response Team) 2026-08-13

56% of company-impacting secrets lived in employees' personal repositories, where most security programs have no visibility.

Wiz 2026-08-13

Builds on: 2026-08-15/trivy-not-litellm-behind-2500-org-credential-collection · 2026-08-10/coding-agent-forensic-artefacts-opencode-codex-credentials · 2026-08-10/coding-agent-ci-harness-trust-boundary-shared-checkout

research16 Aug 23:59Zmulti-sourceOpen finding ↗

2026-08-15 · view entry permalink →

NOTABLENATOB1

The '2,500-organisation LiteLLM breach' was mostly not LiteLLM: 95% of the identified victims were collected before the poisoned packages existed, through the Trivy scanner their pipelines pulled unpinned

The widely reported figure — more than 2,500 organisations compromised through poisoned LiteLLM packages — turns out to describe the wrong artifact for almost all of them. SOCRadar re-analysed the exposure dataset row by row and found that "For 2,085 organizations, or 95% of the 2,188 that were identified, data collection activity ended before March 24, when the poisoned LiteLLM packages were published to the registry" (SecurityWeek, 2026-08-14 · SOCRadar, 2026-08-13). Collection that stops before the malicious packages exist cannot have come from them. SOCRadar times the start against the upstream event instead: the earliest collection record sits eighteen minutes after the poisoned Trivy build published, activity surged while malicious Trivy images were live on Docker Hub, and it closed once the registry quarantined the LiteLLM packages (SecurityWeek, 2026-08-14).

The upstream compromise is documented by the vendor itself. Aqua Security's incident advisory records that on 19 March "The attacker force-pushed 76 of 77 version tags in the aquasecurity/trivy-action repository and all 7 tags in aquasecurity/setup-trivy, redirecting trusted references to malicious commits", publishing a malicious Trivy build at the same time (Aqua Security, 2026-04-01). LiteLLM's own maintainers state the connection plainly: "We believe that the compromise originated from the Trivy dependency used in our CI/CD security scanning workflow" (LiteLLM, 2026-03-24). A security scanner is an unusually good place to put credential-stealing code, because it is a tool organisations deliberately run inside their build systems with access to the material they are scanning.

One detail from Aqua's write-up deserves to outlive this incident. The poisoned tags carried GitHub's "Immutable" badge: "The attacker may have deliberately published immutable releases after force-pushing, locking in the malicious state. Organizations should not rely solely on the 'Immutable' indicator. Pinning to full commit SHAs remains the only truly immutable protection" (Aqua Security, 2026-04-01). A control that displayed as satisfied while being subverted is worse than an absent one, because it ends the review.

What the correction is worth to this constituency is visible in one of the confirmed victims. CERT-EU assesses "with high confidence that initial access was obtained through the Trivy supply-chain compromise, which was publicly attributed to a threat actor known as TeamPCP", in an intrusion into a European Commission cloud account from which "A significant volume of data (about 91.7 GB compressed) was exfiltrated ... including personal data such as names, email addresses, and email content" (CERT-EU, 2026-04-02). That is an EU institution reached through a build-pipeline dependency, not through a package a developer chose to install.

Triage: a security scanner reaching out during a build is normal behaviour, so egress from the runner is not by itself the discriminator. What separates this from a healthy pipeline is the pairing of a scanner invocation with credential-store and environment reads it has no reason to make, and outbound traffic to a destination that is not the scanner's own update or vulnerability-database endpoint — with the reference in the workflow file being a mutable tag rather than a commit SHA as the precondition that made it possible.

For 2,085 organizations, or 95% of the 2,188 that were identified, data collection activity ended before March 24, when the poisoned LiteLLM packages were published to the registry.

SecurityWeek, citing SOCRadar

March 19, 2026 (~17:43 UTC): The attacker force-pushed 76 of 77 version tags in the aquasecurity/trivy-action repository and all 7 tags in aquasecurity/setup-trivy, redirecting trusted references to malicious commits.

Aqua Security 2026-04-01

We believe that the compromise originated from the Trivy dependency used in our CI/CD security scanning workflow.

LiteLLM (BerriAI) 2026-03-24

GitHub's release UI displayed "Immutable" badges next to each poisoned tag. The attacker may have deliberately published immutable releases after force-pushing, locking in the malicious state. Organizations should not rely solely on the "Immutable" indicator. Pinning to full commit SHAs remains the only truly immutable protection.

Aqua Security 2026-04-01

We assess with high confidence that initial access was obtained through the Trivy supply-chain compromise, which was publicly attributed to a threat actor known as TeamPCP.

CERT-EU 2026-04-02

Builds on: 2026-08-06/litellm-callback-hook-post-inference-tool-call-forgery

threat15 Aug 06:20Zmulti-sourceOpen finding ↗

2026-08-08 · view entry permalink →

NOTABLENATOB2

Wiz Cloud Threat Highlights H1 2026: LiteLLM had four separate security events in six months, unauthenticated MCP endpoints turned up across hundreds of environments, and a new extortion actor goes after service accounts rather than people

Wiz Research's semi-annual cloud threat report covers January to June 2026, and its value for this constituency is the named inventory rather than the trend lines: it says concretely which AI infrastructure attracted attacker and researcher attention, and what the resulting exposure looks like in a cloud estate.

The AI toolchain now has its own vulnerability cadence. LiteLLM — an AI gateway Wiz says is present in over a third of the cloud environments it monitors — "had four separate security events in six months: a supply-chain compromise, an SQL injection vulnerability exploited in the wild, a privilege escalation chain and an authentication bypass", while Dify, Langflow, n8n and Ollama "each had critical unauthenticated vulnerabilities of their own" (Wiz Research, 2026-08-06). That list is worth reading as an asset-inventory prompt: these are components teams stand up quickly, often outside the change process that governs the rest of the estate, and three of the five have already reached this pipeline's coverage through separate exploited-vulnerability events.

The exposure finding is sharper than the vulnerability one. On Model Context Protocol servers, Wiz reports: "We found unauthenticated MCP endpoints across hundreds of environments, each one a pre-authenticated proxy holding backend credentials and bridging multiple services" (Wiz Research, 2026-08-06). The reason that shape matters is that an MCP server is not a data store to be broken into — it is a component that already holds the credentials for everything behind it and exists to act on their behalf, so reaching it unauthenticated is not a step toward access, it is the access.

On the actor side, Wiz profiles JINX-0163, a cloud-native extortion group it began tracking in 2026 and that "consistently targets non-human identities - service accounts and IAM roles - rather than end users", in some cases leveraging a single over-privileged identity or an exposed state file to pivot to a full inventory (Wiz Research, 2026-08-06). An extortion group that skips human identity entirely bypasses most of the control stack organisations have spent two years building — phishing-resistant MFA, conditional access, helpdesk verification — none of which applies to a service account.

On supply chain, Wiz records that notable supply-chain attacks "went from making up about 10% of significant incidents in H2 2025 to 25% in H1 2026", with TeamPCP, North Korea and at least three independent operations running campaigns concurrently across npm, PyPI, Composer, VSCode extensions, Jenkins plugins and AUR, several of which had not been targeted this way before (Wiz Research, 2026-08-06). It also notes that malicious packages' shrinking availability window is what makes an install cooldown policy effective — declining to download packages published less than 24 hours ago — which is a specific, cheap control rather than a general recommendation.

We found unauthenticated MCP endpoints across hundreds of environments, each one a pre-authenticated proxy holding backend credentials and bridging multiple services.

They went from making up about 10% of significant incidents in H2 2025 to 25% in H1 2026.

Wiz Research 2026-08-06
annual-report08 Aug 05:22Zsingle-sourceOpen finding ↗
Sources: Wiz Research

Earlier coverage (32)

2026-08-02NOTABLEupdateNATOB1Open-source supply-chain wave status: a second vendor assesses the escalation at high confidence, the CI trigger that hands over base-repository secrets is named, and two vendors independently attribute the axios compromise to the same DPRK clusterStatus update on the npm and developer-ecosystem supply-chain wave prior weeklies tracked from install-hook evasion through CI/CD trust abuse to poisoned AI-assistant tool configurations. Two developments this week. Amazon attributed the September 2025 debug and chalk compromises and the March 2026 axios compromise to a DPRK-linked cluster at medium confidence, finding maintainer access came from social engineering rather than a platform flaw in every case, and assessing a small March 2025 package compromise as a testing ground for what followed. Google's threat-intelligence group independently credits the same actor with the axios compromise under its own tracking name, and names the specific CI mechanism another cluster abused: the pull_request_target GitHub Actions trigger, used to obtain base-repository secrets and write permissions. The transferable levers are concrete — audit that trigger, and impose a release-age cooldown on installs.2026-07-14NOTABLENATOB2Cisco Talos maps the full taxonomy of Python-package build-time and import-time code execution ("The Serpent's Tongue")Cisco Talos published a lifecycle survey of code-execution paths in Python packaging — from setup.py running at install time to persistent .pth files, site-hook modules and PYTHONPATH hijacking that fire on every subsequent Python invocation — tying the taxonomy to real TeamPCP supply-chain compromises (litellm, lightning). It is a reference for supply-chain defenders and a concrete hunt surface for teams running Python build/CI pipelines.2026-06-27HIGHupdateMiasma / "Mini Shai-Hulud" npm worm runs a new wave across LeoPlatform/RStreams packages"Miasma/Mini Shai-Hulud" npm worm runs a new wave across 23+ LeoPlatform/RStreams packages, again using binding.gyp install-time execution to harvest CI and cloud secrets (Socket, 2026-06-25).2026-06-14NOTABLEShai-Hulud / Miasma supply-chain worm lineage — open-sourced, ported to PyPI, and a 1,500-package AUR waveThe supply-chain-worm family the W23 weekly consolidated under the Miasma/IronWorm banner spent this week proliferating across ecosystems and operators. On 9 June a SANS ISC handler tracked TeamPCP open-sourcing its Mini Shai-Hulud framework, immediately spawning a "Phantom Gyp" derivative (SANS ISC; daily 06-09).2026-06-12NOTABLEnpm v12 will disable install scripts by default — audit CI/CD pipelines before JulyGitHub announced that npm v12 (expected July 2026) disables dependency lifecycle scripts (preinstall/install/postinstall, including implicit node-gyp builds) by default, requires npm approve-scripts for explicit opt-in, and blocks Git/remote-URL dependencies without --allow-git/--allow-remote (GitHub …2026-06-09HIGHTeamPCP open-sources its Mini Shai-Hulud framework, spawning a new "Phantom Gyp" derivativeTeamPCP open-sources its Mini Shai-Hulud supply-chain framework on GitHub, spawning a new "Phantom Gyp" derivative and underscoring that valid SLSA provenance does not survive a subverted build environment (SANS ISC, 2026-06-08).2026-06-06NOTABLEupdateMiasma supply-chain worm reaches 73 Microsoft GitHub repositories, adds Azure credential collectorsUPDATE (originally covered 2026-06-02): The Miasma worm — the TeamPCP-spawned descendant of the Mini Shai-Hulud lineage first covered against the Red Hat @redhat-cloud-services npm namespace — recompromised the durabletask package and propagated into the Microsoft GitHub estate.2026-06-02HIGH"Miasma" worm backdoors 32 Red Hat Cloud Services npm packages via OIDC trusted-publishing abuse"Miasma" supply-chain worm compromised 32 @redhat-cloud-services npm packages via a hijacked maintainer GitHub account and OIDC trusted-publishing abuse, adding new GCP and Azure cloud-identity collectors (Wiz, 2026-06-01).2026-05-28HIGHexploitedNx Console / TanStack / DAEMON Tools supply-chain cascade lands three CISA KEV entriesCISA added three supply-chain CVEs to KEV on 2026-05-27 — the Nx Console / TanStack / DAEMON Tools cascade. The Nx Console v18.95.0 VS Code extension compromise (CVE-2026-48027) ultimately traces to a TanStack Router npm supply-chain bug (CVE-2026-45321) that exfiltrated a contributor's GitHub CLI OAuth token; GitHub later confirmed that roughly 3,800 internal repositories and Grafana Labs were also breached. Separately, CVE-2026-8398 covers a six-week trojanisation of signed DAEMON Tools Lite builds 12.5.0.2421–12.5.0.2434 from the official vendor build pipeline.2026-05-26NOTABLEupdateTeamPCP / Mini Shai-Hulud — framework open-sourced, Microsoft PyPI SDK trojanised with a wiper stage, forged Sigstore badgesUPDATE (originally covered 2026-05-21, consolidated weekly update): SANS ISC handler Kenneth Hartman documents three material escalations in the TeamPCP / Mini Shai-Hulud supply-chain campaign through 2026-05-24 (SANS Internet Storm Center, 2026-05-25).2026-05-25NOTABLEMini Shai-Hulud / TeamPCP — @antv npm wave and confirmed Maven Central poisoning; Cargo still un-hitBeyond the in-window TrapDoor and framework-open-sourcing covered in § 2, horizon research surfaced a development the dailies missed.2026-05-25HIGHMini Shai-Hulud / TrapDoor — the supply-chain worm goes cross-ecosystem, open-source and destructiveSupply-chain worm widens — Mini Shai-Hulud goes cross-ecosystem, open-source and destructive. TrapDoor spans npm/PyPI/crates, the framework was open-sourced with a wiper stage, and Maven Central poisoning via mvnpm is now confirmed — one of last week's two un-hit registries. (daily, Wiz)2026-05-24HIGHPackagist supply-chain wave: Laravel-Lang autoloader backdoor and the cross-ecosystem postinstall strandA Packagist (PHP/Composer) supply-chain wave hit the Laravel-Lang ecosystem — 700+ version tags rewritten to point at attacker forks, an autoload.files backdoor that executes on every request, and a separate 8-package package.json postinstall strand dropping a Linux implant. Full mechanics in today's deep dive (Socket, 2026-05-23).2026-05-24NOTABLEnpm ships 2FA-gated "staged publishing" GA in response to the 2026 supply-chain worm wavesUPDATE (supply-chain worm wave, originally covered 2026-05-23): GitHub announced on 2026-05-22 that npm staged publishing is now Generally Available — a maintainer must run npm stage publish (npm CLI 11.15.0+), which uploads the version to a consumer-invisible staging queue, then pass a separate 2FA …2026-05-22NOTABLEupdateTeamPCP Mini Shai-Hulud — Unit 42 and StepSecurity confirm SLSA Build Level 3 attestation invalidated as integrity gateUPDATE (originally covered 2026-05-19, updated 2026-05-21): Unit 42 (Palo Alto Networks) and StepSecurity published concurrent technical analyses on 2026-05-21 of the TeamPCP Mini Shai-Hulud npm supply-chain campaign, establishing the defining novelty of this wave: the first documented case of malicious npm …2026-05-21HIGHVerizon 2026 DBIR: vulnerability exploitation overtakes credentials as primary breach vector for the first time in 19 yearsVerizon 2026 DBIR (today's deep dive): vulnerability exploitation overtakes credentials as the leading breach initial-access vector for the first time in the report's 19-year history — 31 % per Verizon's press release (Verizon, 2026-05-19) vs 13 % credentials per Help Net Security's reading of the full DBIR (Help Net Security, 2026-05-20); only 26 % of CISA KEV entries fully remediated (down from 38 %); supply-chain breaches +60 % YoY.2026-05-21HIGHupdateTeamPCP / Mini Shai-Hulud campaign — GitHub itself breached (~3,800 internal repos via poisoned VS Code extension), Microsoft durabletask PyPI worm propagates via AWS SSM and kubectl exec, Grafana confirms missed-token-rotation root causeTeamPCP breaches GitHub itself — ~3,800 internal repositories exfiltrated via a poisoned VS Code extension installed on a GitHub employee device; in parallel, the Mini Shai-Hulud worm compromised the official Microsoft durabletask PyPI package and propagates across AWS via Systems Manager SendCommand and across Kubernetes via kubectl exec (Help Net Security, 2026-05-20; Wiz, 2026-05-20).2026-05-19HIGHupdateTeamPCP / Shai-Hulud — first copycat wave (Phantom Bot + SSH/cloud stealers), Checkmarx Jenkins plugin trojanised again, PCPJack rival worm hits exposed cloud servicesTeamPCP/Shai-Hulud copycat wave begins — first imitator drops Phantom Bot DDoS and SSH/cloud-credential stealers in four typosquatted npm packages (OX Security, 2026-05-17). chalk-tempalte is a direct clone of the leaked Shai-Hulud worm source code that Datadog Security Labs analysed on 2026-05-13.2026-05-18NOTABLEexploitedTeamPCP / Mini Shai-Hulud / Megalodon — the open-sourced supply-chain worm became commodity infrastructure this weekThis is the week's defining chain. After the worm framework was open-sourced on 2026-05-12, the window saw it move from a single operator's tool to commodity capability, escalating almost daily:2026-05-15NOTABLEDatadog Security Labs analyzes leaked TeamPCP "Shai-Hulud" offensive framework source codeUPDATE (2026-05-13 — follows TeamPCP coverage 2026-05-13): Datadog Security Labs published an analysis of the TeamPCP "Shai-Hulud" offensive worm source code on 2026-05-13, after the complete framework was briefly accessible as a public GitHub repository on 2026-05-12 before the account was removed (Datadog …2026-05-15NOTABLEupdateTeamPCP / Mini Shai-Hulud — OpenAI named as victim; code-signing certificate rotation enforced for all macOS appsUPDATE (originally covered 2026-05-13): OpenAI disclosed on approximately 2026-05-13 that two employee devices were compromised through the TanStack npm supply-chain attack (Mini Shai-Hulud / TeamPCP, first covered in this brief series on 2026-05-12 and 2026-05-13) and that the compromise affected OpenAI's macOS …2026-05-15NOTABLESophos 2026 State of Identity Security: Switzerland records highest identity-breach incidence globally; energy and federal government hardest-hit sectorsSophos published its State of Identity Security 2026 survey on 2026-05-14, drawing on responses from IT and cybersecurity leaders across 17 countries (Help Net Security, 2026-05-14).2026-05-13NOTABLEMini Shai-Hulud's GitHub Actions Pwn-Request → OIDC Token Theft ChainBackground. Mini Shai-Hulud (the TeamPCP self-propagating npm worm) first surfaced in coverage on 2026-05-10 as a SAP CAP-package compromise.2026-05-13HIGHupdateMini Shai-Hulud — TeamPCP worm hits TanStack, UiPath, Mistral AI, OpenSearch (160+ package versions)Mini Shai-Hulud worm re-detonates. TeamPCP poisoned 160+ npm package versions including @tanstack/ (42 packages, ~12M weekly downloads), @uipath/ (60+), @mistralai/* and @opensearch-project/opensearch via a pull_request_target → pnpm-cache poisoning → /proc/<pid>/mem OIDC-token theft chain that produced valid SLSA Build Level 3 provenance on the trojanised tarballs. UiPath is widely used in EU public-sector RPA; SAP HotNews #3747787 acknowledges CAP-package impact (StepSecurity, 2026-05-11; TanStack post-mortem, 2026-05-12).2026-05-12HIGHGTIG AI Threat Tracker (May 2026): First Confirmed AI-Generated Zero-Day Exploit ITW and the Behavioural Class of AI-Augmented MalwareGoogle Threat Intelligence Group confirms first AI-generated zero-day exploit observed in the wild. A criminal campaign used an LLM-generated Python exploit (semantic-logic 2FA bypass in an unnamed widely-deployed open-source sysadmin tool) before responsible disclosure cut it short (Google Cloud Threat Intelligence, 2026-05-11). Same report documents AI-augmented malware families (CANFAIL, LONGSTREAM, PROMPTFLUX, HONESTCUE) and state-actor Gemini abuse — full treatment in § 5 Deep Dive.2026-05-12HIGHexploitedTeamPCP (UNC6780 / PCPJack ecosystem) backdoors the Checkmarx Jenkins AST plugin — third Checkmarx supply-chain compromise in three months, SANDCLOCK exfiltrates every CI secret reachable from the runnerTeamPCP (UNC6780) backdoors the Checkmarx Jenkins AST plugin — third Checkmarx supply-chain compromise in three months. Malicious plugin build 2026.5.09 published to the Jenkins Marketplace on 2026-05-09–10 deploys SANDCLOCK to exfiltrate every CI secret reachable from the runner (cloud keys, container-registry credentials, Checkmarx API tokens) (The Hacker News, 2026-05-11; Checkmarx — Ongoing Security Updates, last update 2026-05-09). Treat any pipeline that auto-updated in the window as a full secrets-compromise event.2026-05-11NOTABLELooking ahead — 2026-W20Microsoft Exchange CVE-2026-42897 — Microsoft permanent patch and out-of-band advisory on DEVCORE Pwn2Own three-bug chain pending.2026-05-11NOTABLETeamPCP / Mini Shai-Hulud (ShinyHunters / WorldLeaks adjacent) — wave 4 + framework leak + IDE persistenceFull coverage in § 2 (multi-day chain).2026-05-11NOTABLEDatadog Security Labs — Shai-Hulud framework static analysisDatadog Security Labs published a static analysis of the leaked Shai-Hulud framework source on 2026-05-13 (covered daily 2026-05-15).2026-05-11NOTABLEAI tooling SaaS and developer toolchainThe Mini Shai-Hulud / TeamPCP propagation across @tanstack, @uipath, @mistralai, @opensearch-project, @guardrails-ai, and OpenAI consolidates a sector pattern first surfaced in W19: AI-evaluation, AI-observability, AI-agent-orchestration, and AI-tooling SaaS vendors all sit on architectures that …2026-05-11HIGHexploitedTeamPCP / Mini Shai-Hulud npm supply-chain worm — wave 4 + framework source leakTeamPCP Mini Shai-Hulud wave 4 compromised 170+ npm packages / 400+ malicious versions per daily-brief tracking (TanStack, UiPath, Mistral AI, OpenSearch, OpenAI named); Datadog static analysis of the leaked Shai-Hulud framework source (2026-05-12 leak) surfaces previously-undocumented IDE-persistence hooks targeting .claude/settings.json and .vscode/tasks.json, plus OIDC token extraction from /proc/<pid>/mem to forge Sigstore provenance attestations. Provenance-only verification no longer separates malicious from legitimate publications. (Datadog Security Labs · Wiz Blog · daily 2026-05-13 UPDATE · daily 2026-05-15 UPDATE)2026-05-04NOTABLEexploitedTeamPCP → PCPJack — cloud-worm successor evicting prior operator artefactsCurrent state: SentinelLabs documented PCPJack on 2026-05-07 as a worm-class framework that evicts and deletes existing TeamPCP artefacts on compromise (giving the framework its name), then deploys six Python modules harvesting credentials from Docker, Kubernetes, Redis, MongoDB, RayML, and dozens of cloud / SaaS …