ctipilot.ch

TeamPCP

actor · actor:teampcp single-source

Threat actor targeting software supply chains; operator of the Mini Shai-Hulud npm worm family and the SANDCLOCK Checkmarx Jenkins-plugin backdoor, with victims including OpenAI.

Coverage timeline
30
first 2026-05-04 → last 2026-06-27
Peak priority
high
13 high · 17 notable
Sources cited
99
46 hosts
Sections touched
10
active-threats, deep-dive, research
Co-occurring entities
12
see Related entities below
ATT&CK techniques
33
pinned v19.1 · see below
2026-05-0430 appearances2026-06-27

ATT&CK techniques

33 techniques observed across 12 entries — derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.1 · compare on the matrix · Navigator layer (JSON)

Reconnaissance TA0043

T1593Search Open Websites/Domains×1

Adversaries may search freely available websites and/or domains for information about victims that can be used during targeting. Information about victims may be available in various online sites, such as social media, new sites, or those hosting information about business operations such as hiring or requested/rewarded contracts.

Evidence: 2026-05-13/mini-shai-hulud-s-github-actions-pwn-request-oidc-token-thef · ATT&CK page ↗

Resource Development TA0042

T1583.001Acquire Infrastructure: Domains×1

Adversaries may acquire domains that can be used during targeting. Domain names are the human readable names used to represent one or more IP addresses. They can be purchased or, in some cases, acquired for free.

Evidence: 2026-05-13/mini-shai-hulud-s-github-actions-pwn-request-oidc-token-thef · ATT&CK page ↗

T1650Acquire Access×1

Adversaries may purchase or otherwise acquire an existing access to a target system or network. A variety of online services and initial access broker networks are available to sell access to previously compromised systems. In some cases, adversary groups may form partnerships to share compromised systems with each other.

Evidence: 2026-05-22/teampcp-mini-shai-hulud-unit-42-and-stepsecurity-confirm-sls · ATT&CK page ↗

Initial Access TA0001

T1078Valid Accounts×1

Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.

Evidence: 2026-05-21/verizon-2026-dbir-vulnerability-exploitation-overtakes-crede · ATT&CK page ↗

T1078.004Valid Accounts: Cloud Accounts×3

Valid accounts in cloud environments may allow adversaries to perform actions to achieve Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Cloud accounts are those created and configured by an organization for use by users, remote support, services, or for administration of resources within a cloud service provider or SaaS application. Cloud Accounts can exist solely in the cloud; alternatively, they may be hybrid-joined between on-premises systems and the cloud through syncing or federation with other identity sources such as Windows Active Directory.

Evidence: 2026-05-21/teampcp-mini-shai-hulud-campaign-github-itself-breached-3-80 · 2026-05-13/mini-shai-hulud-teampcp-worm-hits-tanstack-uipath-mistral-ai · 2026-05-13/mini-shai-hulud-s-github-actions-pwn-request-oidc-token-thef · ATT&CK page ↗

T1190Exploit Public-Facing Application×2

Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.

Evidence: 2026-05-21/verizon-2026-dbir-vulnerability-exploitation-overtakes-crede · 2026-05-12/gtig-ai-threat-tracker-may-2026-first-confirmed-ai-generated · ATT&CK page ↗

T1195Supply Chain Compromise×3

Adversaries may manipulate products or product delivery mechanisms prior to receipt by a final consumer for the purpose of data or system compromise.

Evidence: 2026-05-24/packagist-supply-chain-wave-laravel-lang-autoloader-backdoor · 2026-05-21/verizon-2026-dbir-vulnerability-exploitation-overtakes-crede · 2026-05-12/teampcp-unc6780-pcpjack-ecosystem-backdoors-the-checkmarx-je · ATT&CK page ↗

T1195.002Supply Chain Compromise: Compromise Software Supply Chain×7

Adversaries may manipulate application software prior to receipt by a final consumer for the purpose of data or system compromise. Supply chain compromise of software can take place in a number of ways, including manipulation of the application source code, manipulation of the update/distribution mechanism for that software, or replacing compiled releases with a modified version.

Evidence: 2026-05-28/nx-console-tanstack-daemon-tools-supply-chain-cascade-lands · 2026-05-24/packagist-supply-chain-wave-laravel-lang-autoloader-backdoor · 2026-05-19/teampcp-shai-hulud-first-copycat-wave-phantom-bot-ssh-cloud · 2026-05-15/datadog-security-labs-analyzes-leaked-teampcp-shai-hulud-off · 2026-05-13/mini-shai-hulud-teampcp-worm-hits-tanstack-uipath-mistral-ai · 2026-05-13/mini-shai-hulud-s-github-actions-pwn-request-oidc-token-thef +1 more · ATT&CK page ↗

T1199Trusted Relationship×1

Adversaries may breach or otherwise leverage organizations who have access to intended victims. Access through trusted third party relationship abuses an existing connection that may not be protected or receives less scrutiny than standard mechanisms of gaining access to a network.

Evidence: 2026-05-13/mini-shai-hulud-s-github-actions-pwn-request-oidc-token-thef · ATT&CK page ↗

Execution TA0002

T1059Command and Scripting Interpreter×1

Adversaries may abuse command and script interpreters to execute commands, scripts, or binaries. These interfaces and languages provide ways of interacting with computer systems and are a common feature across many different platforms. Most systems come with some built-in command-line interface and scripting capabilities, for example, macOS and Linux distributions include some flavor of Unix Shell while Windows installations include the Windows Command Shell and PowerShell.

Evidence: 2026-05-24/packagist-supply-chain-wave-laravel-lang-autoloader-backdoor · ATT&CK page ↗

T1059.004Command and Scripting Interpreter: Unix Shell×2

Adversaries may abuse Unix shell commands and scripts for execution. Unix shells are the primary command prompt on Linux, macOS, and ESXi systems, though many variations of the Unix shell exist (e.g. sh, ash, bash, zsh, etc.) depending on the specific OS or distribution. Unix shells can control every aspect of a system, with certain commands requiring elevated privileges.

Evidence: 2026-05-24/packagist-supply-chain-wave-laravel-lang-autoloader-backdoor · 2026-05-15/datadog-security-labs-analyzes-leaked-teampcp-shai-hulud-off · ATT&CK page ↗

T1204User Execution×1

An adversary may rely upon specific actions by a user in order to gain execution. Users may be subjected to social engineering to get them to execute malicious code by, for example, opening a malicious document file or link. These user actions will typically be observed as follow-on behavior from forms of Phishing.

Evidence: 2026-05-24/packagist-supply-chain-wave-laravel-lang-autoloader-backdoor · ATT&CK page ↗

T1204.002User Execution: Malicious File×1

An adversary may rely upon a user opening a malicious file in order to gain execution. Users may be subjected to social engineering to get them to open a file that will lead to code execution. This user action will typically be observed as follow-on behavior from Spearphishing Attachment. Adversaries may use several types of files that require a user to execute them, including .doc, .pdf, .xls, .rtf, .scr, .exe, .lnk, .pif, .cpl, .reg, and .iso.

Evidence: 2026-05-24/packagist-supply-chain-wave-laravel-lang-autoloader-backdoor · ATT&CK page ↗

Persistence TA0003

T1078Valid Accounts×1

Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.

Evidence: 2026-05-21/verizon-2026-dbir-vulnerability-exploitation-overtakes-crede · ATT&CK page ↗

T1078.004Valid Accounts: Cloud Accounts×3

Valid accounts in cloud environments may allow adversaries to perform actions to achieve Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Cloud accounts are those created and configured by an organization for use by users, remote support, services, or for administration of resources within a cloud service provider or SaaS application. Cloud Accounts can exist solely in the cloud; alternatively, they may be hybrid-joined between on-premises systems and the cloud through syncing or federation with other identity sources such as Windows Active Directory.

Evidence: 2026-05-21/teampcp-mini-shai-hulud-campaign-github-itself-breached-3-80 · 2026-05-13/mini-shai-hulud-teampcp-worm-hits-tanstack-uipath-mistral-ai · 2026-05-13/mini-shai-hulud-s-github-actions-pwn-request-oidc-token-thef · ATT&CK page ↗

T1505.003Server Software Component: Web Shell×1

Adversaries may backdoor web servers with web shells to establish persistent access to systems. A Web shell is a Web script that is placed on an openly accessible Web server to allow an adversary to access the Web server as a gateway into a network. A Web shell may provide a set of functions to execute or a command-line interface on the system that hosts the Web server.

Evidence: 2026-05-13/mini-shai-hulud-s-github-actions-pwn-request-oidc-token-thef · ATT&CK page ↗

Privilege Escalation TA0004

T1078Valid Accounts×1

Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.

Evidence: 2026-05-21/verizon-2026-dbir-vulnerability-exploitation-overtakes-crede · ATT&CK page ↗

T1078.004Valid Accounts: Cloud Accounts×3

Valid accounts in cloud environments may allow adversaries to perform actions to achieve Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Cloud accounts are those created and configured by an organization for use by users, remote support, services, or for administration of resources within a cloud service provider or SaaS application. Cloud Accounts can exist solely in the cloud; alternatively, they may be hybrid-joined between on-premises systems and the cloud through syncing or federation with other identity sources such as Windows Active Directory.

Evidence: 2026-05-21/teampcp-mini-shai-hulud-campaign-github-itself-breached-3-80 · 2026-05-13/mini-shai-hulud-teampcp-worm-hits-tanstack-uipath-mistral-ai · 2026-05-13/mini-shai-hulud-s-github-actions-pwn-request-oidc-token-thef · ATT&CK page ↗

Stealth TA0005

T1027Obfuscated Files or Information×1

Adversaries may attempt to make an executable or file difficult to discover or analyze by encrypting, encoding, or otherwise obfuscating its contents on the system or in transit. This is common behavior that can be used across different platforms and the network to evade defenses.

Evidence: 2026-05-12/gtig-ai-threat-tracker-may-2026-first-confirmed-ai-generated · ATT&CK page ↗

T1036Masquerading×1

Adversaries may attempt to manipulate features of their artifacts to make them appear legitimate or benign to users and/or security tools. Masquerading occurs when the name or location of an object, legitimate or malicious, is manipulated or abused for the sake of evading defenses and observation. This may include manipulating file metadata, tricking users into misidentifying the file type, and giving legitimate task or service names.

Evidence: 2026-05-24/packagist-supply-chain-wave-laravel-lang-autoloader-backdoor · ATT&CK page ↗

T1036.005Masquerading: Match Legitimate Resource Name or Location×1

Adversaries may match or approximate the name or location of legitimate files, Registry keys, or other resources when naming/placing them. This is done for the sake of evading defenses and observation.

Evidence: 2026-05-24/packagist-supply-chain-wave-laravel-lang-autoloader-backdoor · ATT&CK page ↗

T1078Valid Accounts×1

Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.

Evidence: 2026-05-21/verizon-2026-dbir-vulnerability-exploitation-overtakes-crede · ATT&CK page ↗

T1078.004Valid Accounts: Cloud Accounts×3

Valid accounts in cloud environments may allow adversaries to perform actions to achieve Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Cloud accounts are those created and configured by an organization for use by users, remote support, services, or for administration of resources within a cloud service provider or SaaS application. Cloud Accounts can exist solely in the cloud; alternatively, they may be hybrid-joined between on-premises systems and the cloud through syncing or federation with other identity sources such as Windows Active Directory.

Evidence: 2026-05-21/teampcp-mini-shai-hulud-campaign-github-itself-breached-3-80 · 2026-05-13/mini-shai-hulud-teampcp-worm-hits-tanstack-uipath-mistral-ai · 2026-05-13/mini-shai-hulud-s-github-actions-pwn-request-oidc-token-thef · ATT&CK page ↗

T1140Deobfuscate/Decode Files or Information×1

Adversaries may use Obfuscated Files or Information to hide artifacts of an intrusion from analysis. They may require separate mechanisms to decode or deobfuscate that information depending on how they intend to use it. Methods for doing that include built-in functionality of malware or by using utilities present on the system.

Evidence: 2026-05-24/packagist-supply-chain-wave-laravel-lang-autoloader-backdoor · ATT&CK page ↗

Defense Impairment TA0112

T1553Subvert Trust Controls×1

Adversaries may undermine security controls that will either warn users of untrusted activity or prevent execution of untrusted programs. Operating systems and security products may contain mechanisms to identify programs or websites as possessing some level of trust. Examples of such features would include a program being allowed to run because it is signed by a valid code signing certificate, a program prompting the user with a warning because it has an attribute set from being downloaded from the Internet, or getting an indication that you are about to connect to an untrusted site.

Evidence: 2026-05-12/gtig-ai-threat-tracker-may-2026-first-confirmed-ai-generated · ATT&CK page ↗

T1553.002Subvert Trust Controls: Code Signing×1

Adversaries may create, acquire, or steal code signing materials to sign their malware or tools. Code signing provides a level of authenticity on a binary from the developer and a guarantee that the binary has not been tampered with. The certificates used during an operation may be created, acquired, or stolen by the adversary. Unlike Invalid Code Signature, this activity will result in a valid signature.

Evidence: 2026-05-13/mini-shai-hulud-s-github-actions-pwn-request-oidc-token-thef · ATT&CK page ↗

Credential Access TA0006

T1003.007OS Credential Dumping: Proc Filesystem×1

Adversaries may gather credentials from the proc filesystem or `/proc`. The proc filesystem is a pseudo-filesystem used as an interface to kernel data structures for Linux based systems managing virtual memory. For each process, the `/proc/<PID>/maps` file shows how memory is mapped within the process’s virtual address space. And `/proc/<PID>/mem`, exposed for debugging purposes, provides access to the process’s virtual address space.

Evidence: 2026-05-13/mini-shai-hulud-s-github-actions-pwn-request-oidc-token-thef · ATT&CK page ↗

T1110Brute Force×1

Adversaries may use brute force techniques to gain access to accounts when passwords are unknown or when password hashes are obtained. Without knowledge of the password for an account or set of accounts, an adversary may systematically guess the password using a repetitive or iterative mechanism. Brute forcing passwords can take place via interaction with a service that will check the validity of those credentials or offline against previously acquired credential data, such as password hashes.

Evidence: 2026-05-21/verizon-2026-dbir-vulnerability-exploitation-overtakes-crede · ATT&CK page ↗

T1552Unsecured Credentials×3

Adversaries may search compromised systems to find and obtain insecurely stored credentials. These credentials can be stored and/or misplaced in many locations on a system, including plaintext files (e.g. Shell History), operating system or application-specific repositories (e.g. Credentials in Registry), or other specialized files/artifacts (e.g. Private Keys).

Evidence: 2026-05-24/packagist-supply-chain-wave-laravel-lang-autoloader-backdoor · 2026-05-12/teampcp-unc6780-pcpjack-ecosystem-backdoors-the-checkmarx-je · 2026-05-12/gtig-ai-threat-tracker-may-2026-first-confirmed-ai-generated · ATT&CK page ↗

T1552.001Unsecured Credentials: Credentials In Files×8

Adversaries may search local file systems and remote file shares for files containing insecurely stored credentials. These can be files created by users to store their own credentials, shared credential stores for a group of individuals, configuration files containing passwords for a system or service, or source code/binary files containing embedded passwords.

Evidence: 2026-05-28/nx-console-tanstack-daemon-tools-supply-chain-cascade-lands · 2026-05-24/packagist-supply-chain-wave-laravel-lang-autoloader-backdoor · 2026-05-22/teampcp-mini-shai-hulud-unit-42-and-stepsecurity-confirm-sls · 2026-05-19/teampcp-shai-hulud-first-copycat-wave-phantom-bot-ssh-cloud · 2026-05-15/datadog-security-labs-analyzes-leaked-teampcp-shai-hulud-off · 2026-05-13/mini-shai-hulud-teampcp-worm-hits-tanstack-uipath-mistral-ai +2 more · ATT&CK page ↗

T1606.002Forge Web Credentials: SAML Tokens×1

An adversary may forge SAML tokens with any permissions claims and lifetimes if they possess a valid SAML token-signing certificate. The default lifetime of a SAML token is one hour, but the validity period can be specified in the <code>NotOnOrAfter</code> value of the <code>conditions ...</code> element in a token. This value can be changed using the <code>AccessTokenLifetime</code> in a <code>LifetimeTokenPolicy</code>. Forged SAML tokens enable adversaries to authenticate across services that use SAML 2.0 as an SSO (single sign-on) mechanism.

Evidence: 2026-05-13/mini-shai-hulud-s-github-actions-pwn-request-oidc-token-thef · ATT&CK page ↗

Discovery TA0007

T1083File and Directory Discovery×1

Adversaries may enumerate files and directories or may search in specific locations of a host or network share for certain information within a file system. Adversaries may use the information from File and Directory Discovery during automated discovery to shape follow-on behaviors, including whether or not the adversary fully infects the target and/or attempts specific actions.

Evidence: 2026-05-24/packagist-supply-chain-wave-laravel-lang-autoloader-backdoor · ATT&CK page ↗

Lateral Movement TA0008

T1570Lateral Tool Transfer×1

Adversaries may transfer tools or other files between systems in a compromised environment. Once brought into the victim environment (i.e., Ingress Tool Transfer) files may then be copied from one system to another to stage adversary tools or other files over the course of an operation.

Evidence: 2026-05-21/teampcp-mini-shai-hulud-campaign-github-itself-breached-3-80 · ATT&CK page ↗

Collection TA0009

T1530Data from Cloud Storage×1

Adversaries may access data from cloud storage.

Evidence: 2026-05-28/nx-console-tanstack-daemon-tools-supply-chain-cascade-lands · ATT&CK page ↗

Command and Control TA0011

T1071Application Layer Protocol×1

Adversaries may communicate using OSI application layer protocols to avoid detection/network filtering by blending in with existing traffic. Commands to the remote system, and often the results of those commands, will be embedded within the protocol traffic between the client and server.

Evidence: 2026-05-12/gtig-ai-threat-tracker-may-2026-first-confirmed-ai-generated · ATT&CK page ↗

T1071.001Application Layer Protocol: Web Protocols×1

Adversaries may communicate using application layer protocols associated with web traffic to avoid detection/network filtering by blending in with existing traffic. Commands to the remote system, and often the results of those commands, will be embedded within the protocol traffic between the client and server.

Evidence: 2026-05-12/gtig-ai-threat-tracker-may-2026-first-confirmed-ai-generated · ATT&CK page ↗

Exfiltration TA0010

T1041Exfiltration Over C2 Channel×1

Adversaries may steal data by exfiltrating it over an existing command and control channel. Stolen data is encoded into the normal communications channel using the same protocol as command and control communications.

Evidence: 2026-05-19/teampcp-shai-hulud-first-copycat-wave-phantom-bot-ssh-cloud · ATT&CK page ↗

T1567Exfiltration Over Web Service×1

Adversaries may use an existing, legitimate external Web service to exfiltrate data rather than their primary command and control channel. Popular Web services acting as an exfiltration mechanism may give a significant amount of cover due to the likelihood that hosts within a network are already communicating with them prior to compromise. Firewall rules may also already exist to permit traffic to these services.

Evidence: 2026-05-28/nx-console-tanstack-daemon-tools-supply-chain-cascade-lands · ATT&CK page ↗

Impact TA0040

T1485Data Destruction×1

Adversaries may destroy data and files on specific systems or in large numbers on a network to interrupt availability to systems, services, and network resources. Data destruction is likely to render stored data irrecoverable by forensic techniques through overwriting files or data on local and remote drives. Common operating system file deletion commands such as <code>del</code> and <code>rm</code> often only remove pointers to files without wiping the contents of the files themselves, making the files recoverable by proper forensic methodology. This behavior is distinct from Disk Content Wipe and Disk Structure Wipe because individual files are destroyed rather than sections of a storage disk or the disk's logical structure.

Evidence: 2026-05-26/teampcp-mini-shai-hulud-framework-open-sourced-microsoft-pyp · ATT&CK page ↗

Story timeline

  1. 2026-06-27Miasma / "Mini Shai-Hulud" npm worm runs a new wave across LeoPlatform/RStreams packages
    updates
  2. 2026-06-14Shai-Hulud / Miasma supply-chain worm lineage — open-sourced, ported to PyPI, and a 1,500-package AUR wave
    weekly-multi-day
  3. 2026-06-12npm v12 will disable install scripts by default — audit CI/CD pipelines before July
    research
  4. 2026-06-09TeamPCP open-sources its Mini Shai-Hulud framework, spawning a new "Phantom Gyp" derivative
    active-threats
  5. 2026-06-06Miasma supply-chain worm reaches 73 Microsoft GitHub repositories, adds Azure credential collectors
    updates
  6. 2026-06-02"Miasma" worm backdoors 32 Red Hat Cloud Services npm packages via OIDC trusted-publishing abuse
    active-threats
  7. 2026-05-28Nx Console / TanStack / DAEMON Tools supply-chain cascade lands three CISA KEV entries
    deep-dive
  8. 2026-05-26TeamPCP / Mini Shai-Hulud — framework open-sourced, Microsoft PyPI SDK trojanised with a wiper stage, forged Sigstore badges
    updates
  9. 2026-05-25Mini Shai-Hulud / TrapDoor — the supply-chain worm goes cross-ecosystem, open-source and destructive
    weekly-multi-day
  10. 2026-05-25Mini Shai-Hulud / TeamPCP — @antv npm wave and confirmed Maven Central poisoning; Cargo still un-hit
    weekly-long-running
  11. 2026-05-24Packagist supply-chain wave: Laravel-Lang autoloader backdoor and the cross-ecosystem postinstall strand
    deep-dive
  12. 2026-05-24npm ships 2FA-gated "staged publishing" GA in response to the 2026 supply-chain worm waves
    active-threats
  13. 2026-05-22TeamPCP Mini Shai-Hulud — Unit 42 and StepSecurity confirm SLSA Build Level 3 attestation invalidated as integrity gate
    updates
  14. 2026-05-21Verizon 2026 DBIR: vulnerability exploitation overtakes credentials as primary breach vector for the first time in 19 years
    deep-dive
  15. 2026-05-21TeamPCP / Mini Shai-Hulud campaign — GitHub itself breached (~3,800 internal repos via poisoned VS Code extension), Microsoft durabletask PyPI worm propagates via AWS SSM and kubectl exec, Grafana confirms missed-token-rotation root cause
    updatesTeamPCP / Mini Shai-Hulud campaign — GitHub itself breached (~3,800 internal repos via poisoned VS Code extension), Microsoft durabletask PyPI worm propagates
  16. 2026-05-19TeamPCP / Shai-Hulud — first copycat wave (Phantom Bot + SSH/cloud stealers), Checkmarx Jenkins plugin trojanised again, PCPJack rival worm hits exposed cloud services
    updatesTeamPCP / Shai-Hulud — first copycat wave (Phantom Bot + SSH/cloud stealers), Checkmarx Jenkins plugin trojanised again, PCPJack rival worm hits exposed cloud
  17. 2026-05-18TeamPCP / Mini Shai-Hulud / Megalodon — the open-sourced supply-chain worm became commodity infrastructure this week
    weekly-multi-day
  18. 2026-05-15TeamPCP / Mini Shai-Hulud — OpenAI named as victim; code-signing certificate rotation enforced for all macOS apps
    updates
  19. 2026-05-15Sophos 2026 State of Identity Security: Switzerland records highest identity-breach incidence globally; energy and federal government hardest-hit sectors
    research
  20. 2026-05-15Datadog Security Labs analyzes leaked TeamPCP "Shai-Hulud" offensive framework source code
    active-threats
  21. 2026-05-13Mini Shai-Hulud — TeamPCP worm hits TanStack, UiPath, Mistral AI, OpenSearch (160+ package versions)
    updates
  22. 2026-05-13Mini Shai-Hulud's GitHub Actions Pwn-Request → OIDC Token Theft Chain
    deep-dive
  23. 2026-05-12TeamPCP (UNC6780 / PCPJack ecosystem) backdoors the Checkmarx Jenkins AST plugin — third Checkmarx supply-chain compromise in three months, SANDCLOCK exfiltrates every CI secret reachable from the runner
    trending-vulnerabilitiesTeamPCP (UNC6780 / PCPJack ecosystem) backdoors the Checkmarx Jenkins AST plugin — third Checkmarx supply-chain compromise in three months, SANDCLOCK
  24. 2026-05-12GTIG AI Threat Tracker (May 2026): First Confirmed AI-Generated Zero-Day Exploit ITW and the Behavioural Class of AI-Augmented Malware
    deep-dive
  25. 2026-05-11TeamPCP / Mini Shai-Hulud (ShinyHunters / WorldLeaks adjacent) — wave 4 + framework leak + IDE persistence
    weekly-long-running
  26. 2026-05-11TeamPCP / Mini Shai-Hulud npm supply-chain worm — wave 4 + framework source leak
    weekly-multi-day
  27. 2026-05-11Looking ahead — 2026-W20
    weekly-looking-ahead
  28. 2026-05-11Datadog Security Labs — Shai-Hulud framework static analysis
    weekly-annual-reports
  29. 2026-05-11AI tooling SaaS and developer toolchain
    weekly-sector-patterns
  30. 2026-05-04TeamPCP → PCPJack — cloud-worm successor evicting prior operator artefacts
    weekly-long-running

Where this entity is cited

  • updates8
  • deep-dive5
  • weekly-multi-day4
  • active-threats4
  • weekly-long-running3
  • research2
  • weekly-sector-patterns1
  • weekly-annual-reports1
  • weekly-looking-ahead1
  • trending-vulnerabilities1

Source distribution

  • thehackernews.com14 (14%)
  • attack.mitre.org12 (12%)
  • helpnetsecurity.com6 (6%)
  • nvd.nist.gov5 (5%)
  • socket.dev5 (5%)
  • wiz.io4 (4%)
  • bleepingcomputer.com3 (3%)
  • github.blog3 (3%)
  • other47 (47%)

Related entities

All cited sources (99)

Entries about TeamPCP (30)

2026-06-27 · view entry permalink →

HIGHupdate

Miasma / "Mini Shai-Hulud" npm worm runs a new wave across LeoPlatform/RStreams packages

UPDATE · originally covered TeamPCP open-sources its Mini Shai-Hulud framework, spawning a new "Phantom Gyp" derivative (2026-06-09)

The Miasma / Mini Shai-Hulud / Hades supply-chain worm — last seen backdooring @redhat-cloud-services packages and the TeamPCP "Phantom Gyp" framework — ran a fresh wave on 2026-06-24: 23+ malicious versions across the LeoPlatform and RStreams serverless-data-pipeline npm ecosystems (leo-sdk, leo-auth, leo-aws, leo-cli) after the czirker publisher account was compromised, plus a Go-module compromise of Verana Blockchain (Socket Security, 2026-06-25).

The wave reuses the previously documented binding.gyp/node-gyp install-time execution to stage a Bun runtime that harvests .env files, npm/GitHub/cloud tokens, SSH keys and IDE/AI-agent configs, scraping GitHub Actions CI secrets (JFrog, 2026-06-26), and again carries the RevokeAndItGoesKaboom campaign marker that Socket ties to the earlier codfish/semantic-release-action compromise (documented by StepSecurity), where the malicious action searched GitHub commit messages bearing that string as an operator dead-drop channel (Socket Security, 2026-06-25). Any CH/EU team consuming these packages in CI should rotate all exposed CI/cloud credentials since 2026-06-20 and alert on node-gyp evaluating JavaScript from binding.gyp.

threat27 Jun 05:17Zmulti-sourceOpen finding ↗

2026-06-14 · view entry permalink →

NOTABLE

Shai-Hulud / Miasma supply-chain worm lineage — open-sourced, ported to PyPI, and a 1,500-package AUR wave

The supply-chain-worm family the W23 weekly consolidated under the Miasma/IronWorm banner spent this week proliferating across ecosystems and operators. On 9 June a SANS ISC handler tracked TeamPCP open-sourcing its Mini Shai-Hulud framework, immediately spawning a "Phantom Gyp" derivative (SANS ISC; daily 06-09). On 10 June the lineage opened a PyPI front dubbed "Hades" — 37 malicious wheels across 19 packages (The Hacker News; daily 06-10).

The week's largest wave hit the Arch User Repository. "Atomic Arch" began with roughly 400 orphaned AUR packages adopted and re-pointed to a Rust credential-stealer plus eBPF rootkit (The Hacker News; Sonatype; daily 06-13); a second wave around 12 June expanded the count further (tracker estimates range from the 400+ in primary reporting to ~1,500) and swapped some PKGBUILD delivery from npm dependency injection to bun install js-digest — active operator iteration against detection. The npm delivery mechanism has been linked by SANS ISC and subsequent reporting to the broader Shai-Hulud supply-chain family. Official Arch core/extra repositories were not affected; only adopted AUR packages. For defenders the through-line is constant: install-time script execution is the kill chain, and npm/bun/AUR build steps need to be treated as untrusted code execution in CI/CD.

synthesis14 Jun 23:57Zmulti-sourceOpen finding ↗

2026-06-12 · view entry permalink →

NOTABLE

npm v12 will disable install scripts by default — audit CI/CD pipelines before July

GitHub announced that npm v12 (expected July 2026) disables dependency lifecycle scripts (preinstall/install/postinstall, including implicit node-gyp builds) by default, requires npm approve-scripts for explicit opt-in, and blocks Git/remote-URL dependencies without --allow-git/--allow-remote (GitHub Changelog, 2026-06-09). This is a structural response to the install-script abuse that powered this spring's npm worm wave (Shai-Hulud/Miasma, IronWorm, TeamPCP — coverage 2026-06-06 through 2026-06-10) and brings npm in line with other package managers that already block install scripts by default (BleepingComputer, 2026-06-11). The warnings are live today in npm ≥ 11.16.0. Defender takeaway: this is a breaking change with a security upside — run npm install under 11.16.0 now to enumerate deprecation warnings, build the script allow-list before v12 ships, and treat any pipeline that must keep scripts enabled wholesale as a finding.

research12 Jun 05:00Zmulti-sourceOpen finding ↗

Earlier coverage (27)

2026-06-09HIGHTeamPCP open-sources its Mini Shai-Hulud framework, spawning a new "Phantom Gyp" derivativeTeamPCP open-sources its Mini Shai-Hulud supply-chain framework on GitHub, spawning a new "Phantom Gyp" derivative and underscoring that valid SLSA provenance does not survive a subverted build environment (SANS ISC, 2026-06-08).2026-06-06NOTABLEupdateMiasma supply-chain worm reaches 73 Microsoft GitHub repositories, adds Azure credential collectorsUPDATE (originally covered 2026-06-02): The Miasma worm — the TeamPCP-spawned descendant of the Mini Shai-Hulud lineage first covered against the Red Hat @redhat-cloud-services npm namespace — recompromised the durabletask package and propagated into the Microsoft GitHub estate.2026-06-02HIGH"Miasma" worm backdoors 32 Red Hat Cloud Services npm packages via OIDC trusted-publishing abuse"Miasma" supply-chain worm compromised 32 @redhat-cloud-services npm packages via a hijacked maintainer GitHub account and OIDC trusted-publishing abuse, adding new GCP and Azure cloud-identity collectors (Wiz, 2026-06-01).2026-05-28HIGHexploitedNx Console / TanStack / DAEMON Tools supply-chain cascade lands three CISA KEV entriesCISA added three supply-chain CVEs to KEV on 2026-05-27 — the Nx Console / TanStack / DAEMON Tools cascade. The Nx Console v18.95.0 VS Code extension compromise (CVE-2026-48027) ultimately traces to a TanStack Router npm supply-chain bug (CVE-2026-45321) that exfiltrated a contributor's GitHub CLI OAuth token; GitHub later confirmed that roughly 3,800 internal repositories and Grafana Labs were also breached. Separately, CVE-2026-8398 covers a six-week trojanisation of signed DAEMON Tools Lite builds 12.5.0.2421–12.5.0.2434 from the official vendor build pipeline.2026-05-26NOTABLEupdateTeamPCP / Mini Shai-Hulud — framework open-sourced, Microsoft PyPI SDK trojanised with a wiper stage, forged Sigstore badgesUPDATE (originally covered 2026-05-21, consolidated weekly update): SANS ISC handler Kenneth Hartman documents three material escalations in the TeamPCP / Mini Shai-Hulud supply-chain campaign through 2026-05-24 (SANS Internet Storm Center, 2026-05-25).2026-05-25NOTABLEMini Shai-Hulud / TeamPCP — @antv npm wave and confirmed Maven Central poisoning; Cargo still un-hitBeyond the in-window TrapDoor and framework-open-sourcing covered in § 2, horizon research surfaced a development the dailies missed.2026-05-25HIGHMini Shai-Hulud / TrapDoor — the supply-chain worm goes cross-ecosystem, open-source and destructiveSupply-chain worm widens — Mini Shai-Hulud goes cross-ecosystem, open-source and destructive. TrapDoor spans npm/PyPI/crates, the framework was open-sourced with a wiper stage, and Maven Central poisoning via mvnpm is now confirmed — one of last week's two un-hit registries. (daily, Wiz)2026-05-24HIGHPackagist supply-chain wave: Laravel-Lang autoloader backdoor and the cross-ecosystem postinstall strandA Packagist (PHP/Composer) supply-chain wave hit the Laravel-Lang ecosystem — 700+ version tags rewritten to point at attacker forks, an autoload.files backdoor that executes on every request, and a separate 8-package package.json postinstall strand dropping a Linux implant. Full mechanics in today's deep dive (Socket, 2026-05-23).2026-05-24NOTABLEnpm ships 2FA-gated "staged publishing" GA in response to the 2026 supply-chain worm wavesUPDATE (supply-chain worm wave, originally covered 2026-05-23): GitHub announced on 2026-05-22 that npm staged publishing is now Generally Available — a maintainer must run npm stage publish (npm CLI 11.15.0+), which uploads the version to a consumer-invisible staging queue, then pass a separate 2FA …2026-05-22NOTABLEupdateTeamPCP Mini Shai-Hulud — Unit 42 and StepSecurity confirm SLSA Build Level 3 attestation invalidated as integrity gateUPDATE (originally covered 2026-05-19, updated 2026-05-21): Unit 42 (Palo Alto Networks) and StepSecurity published concurrent technical analyses on 2026-05-21 of the TeamPCP Mini Shai-Hulud npm supply-chain campaign, establishing the defining novelty of this wave: the first documented case of malicious npm …2026-05-21HIGHVerizon 2026 DBIR: vulnerability exploitation overtakes credentials as primary breach vector for the first time in 19 yearsVerizon 2026 DBIR (today's deep dive): vulnerability exploitation overtakes credentials as the leading breach initial-access vector for the first time in the report's 19-year history — 31 % per Verizon's press release (Verizon, 2026-05-19) vs 13 % credentials per Help Net Security's reading of the full DBIR (Help Net Security, 2026-05-20); only 26 % of CISA KEV entries fully remediated (down from 38 %); supply-chain breaches +60 % YoY.2026-05-21HIGHupdateTeamPCP / Mini Shai-Hulud campaign — GitHub itself breached (~3,800 internal repos via poisoned VS Code extension), Microsoft durabletask PyPI worm propagates via AWS SSM and kubectl exec, Grafana confirms missed-token-rotation root causeTeamPCP breaches GitHub itself — ~3,800 internal repositories exfiltrated via a poisoned VS Code extension installed on a GitHub employee device; in parallel, the Mini Shai-Hulud worm compromised the official Microsoft durabletask PyPI package and propagates across AWS via Systems Manager SendCommand and across Kubernetes via kubectl exec (Help Net Security, 2026-05-20; Wiz, 2026-05-20).2026-05-19HIGHupdateTeamPCP / Shai-Hulud — first copycat wave (Phantom Bot + SSH/cloud stealers), Checkmarx Jenkins plugin trojanised again, PCPJack rival worm hits exposed cloud servicesTeamPCP/Shai-Hulud copycat wave begins — first imitator drops Phantom Bot DDoS and SSH/cloud-credential stealers in four typosquatted npm packages (OX Security, 2026-05-17). chalk-tempalte is a direct clone of the leaked Shai-Hulud worm source code that Datadog Security Labs analysed on 2026-05-13.2026-05-18NOTABLEexploitedTeamPCP / Mini Shai-Hulud / Megalodon — the open-sourced supply-chain worm became commodity infrastructure this weekThis is the week's defining chain. After the worm framework was open-sourced on 2026-05-12, the window saw it move from a single operator's tool to commodity capability, escalating almost daily:2026-05-15NOTABLEDatadog Security Labs analyzes leaked TeamPCP "Shai-Hulud" offensive framework source codeUPDATE (2026-05-13 — follows TeamPCP coverage 2026-05-13): Datadog Security Labs published an analysis of the TeamPCP "Shai-Hulud" offensive worm source code on 2026-05-13, after the complete framework was briefly accessible as a public GitHub repository on 2026-05-12 before the account was removed (Datadog …2026-05-15NOTABLEupdateTeamPCP / Mini Shai-Hulud — OpenAI named as victim; code-signing certificate rotation enforced for all macOS appsUPDATE (originally covered 2026-05-13): OpenAI disclosed on approximately 2026-05-13 that two employee devices were compromised through the TanStack npm supply-chain attack (Mini Shai-Hulud / TeamPCP, first covered in this brief series on 2026-05-12 and 2026-05-13) and that the compromise affected OpenAI's macOS …2026-05-15NOTABLESophos 2026 State of Identity Security: Switzerland records highest identity-breach incidence globally; energy and federal government hardest-hit sectorsSophos published its State of Identity Security 2026 survey on 2026-05-14, drawing on responses from IT and cybersecurity leaders across 17 countries (Help Net Security, 2026-05-14).2026-05-13NOTABLEMini Shai-Hulud's GitHub Actions Pwn-Request → OIDC Token Theft ChainBackground. Mini Shai-Hulud (the TeamPCP self-propagating npm worm) first surfaced in coverage on 2026-05-10 as a SAP CAP-package compromise.2026-05-13HIGHupdateMini Shai-Hulud — TeamPCP worm hits TanStack, UiPath, Mistral AI, OpenSearch (160+ package versions)Mini Shai-Hulud worm re-detonates. TeamPCP poisoned 160+ npm package versions including @tanstack/ (42 packages, ~12M weekly downloads), @uipath/ (60+), @mistralai/* and @opensearch-project/opensearch via a pull_request_target → pnpm-cache poisoning → /proc/<pid>/mem OIDC-token theft chain that produced valid SLSA Build Level 3 provenance on the trojanised tarballs. UiPath is widely used in EU public-sector RPA; SAP HotNews #3747787 acknowledges CAP-package impact (StepSecurity, 2026-05-11; TanStack post-mortem, 2026-05-12).2026-05-12HIGHGTIG AI Threat Tracker (May 2026): First Confirmed AI-Generated Zero-Day Exploit ITW and the Behavioural Class of AI-Augmented MalwareGoogle Threat Intelligence Group confirms first AI-generated zero-day exploit observed in the wild. A criminal campaign used an LLM-generated Python exploit (semantic-logic 2FA bypass in an unnamed widely-deployed open-source sysadmin tool) before responsible disclosure cut it short (Google Cloud Threat Intelligence, 2026-05-11). Same report documents AI-augmented malware families (CANFAIL, LONGSTREAM, PROMPTFLUX, HONESTCUE) and state-actor Gemini abuse — full treatment in § 5 Deep Dive.2026-05-12HIGHexploitedTeamPCP (UNC6780 / PCPJack ecosystem) backdoors the Checkmarx Jenkins AST plugin — third Checkmarx supply-chain compromise in three months, SANDCLOCK exfiltrates every CI secret reachable from the runnerTeamPCP (UNC6780) backdoors the Checkmarx Jenkins AST plugin — third Checkmarx supply-chain compromise in three months. Malicious plugin build 2026.5.09 published to the Jenkins Marketplace on 2026-05-09–10 deploys SANDCLOCK to exfiltrate every CI secret reachable from the runner (cloud keys, container-registry credentials, Checkmarx API tokens) (The Hacker News, 2026-05-11; Checkmarx — Ongoing Security Updates, last update 2026-05-09). Treat any pipeline that auto-updated in the window as a full secrets-compromise event.2026-05-11NOTABLELooking ahead — 2026-W20Microsoft Exchange CVE-2026-42897 — Microsoft permanent patch and out-of-band advisory on DEVCORE Pwn2Own three-bug chain pending.2026-05-11NOTABLETeamPCP / Mini Shai-Hulud (ShinyHunters / WorldLeaks adjacent) — wave 4 + framework leak + IDE persistenceFull coverage in § 2 (multi-day chain).2026-05-11NOTABLEDatadog Security Labs — Shai-Hulud framework static analysisDatadog Security Labs published a static analysis of the leaked Shai-Hulud framework source on 2026-05-13 (covered daily 2026-05-15).2026-05-11NOTABLEAI tooling SaaS and developer toolchainThe Mini Shai-Hulud / TeamPCP propagation across @tanstack, @uipath, @mistralai, @opensearch-project, @guardrails-ai, and OpenAI consolidates a sector pattern first surfaced in W19: AI-evaluation, AI-observability, AI-agent-orchestration, and AI-tooling SaaS vendors all sit on architectures that …2026-05-11HIGHexploitedTeamPCP / Mini Shai-Hulud npm supply-chain worm — wave 4 + framework source leakTeamPCP Mini Shai-Hulud wave 4 compromised 170+ npm packages / 400+ malicious versions per daily-brief tracking (TanStack, UiPath, Mistral AI, OpenSearch, OpenAI named); Datadog static analysis of the leaked Shai-Hulud framework source (2026-05-12 leak) surfaces previously-undocumented IDE-persistence hooks targeting .claude/settings.json and .vscode/tasks.json, plus OIDC token extraction from /proc/<pid>/mem to forge Sigstore provenance attestations. Provenance-only verification no longer separates malicious from legitimate publications. (Datadog Security Labs · Wiz Blog · daily 2026-05-13 UPDATE · daily 2026-05-15 UPDATE)2026-05-04NOTABLEexploitedTeamPCP → PCPJack — cloud-worm successor evicting prior operator artefactsCurrent state: SentinelLabs documented PCPJack on 2026-05-07 as a worm-class framework that evicts and deletes existing TeamPCP artefacts on compromise (giving the framework its name), then deploys six Python modules harvesting credentials from Docker, Kubernetes, Redis, MongoDB, RayML, and dozens of cloud / SaaS …