Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

TeamPCP Supply Chain Campaign: Activity Through 2026-06-07, (Mon, Jun 8th)

0
Medium
Vulnerabilityrce
Published: 06/08/2026 (06/08/2026, 17:07:37 UTC)
Source: SANS ISC Handlers Diary

Description

This diary continues the Internet Storm Center&&#x23&#x3b;x26&#x3b;&#x23&#x3b;39&#x3b;s tracking of the TeamPCP supply chain campaign, first documented in the SANS white paper When the Security Scanner Became the Weapon and most recently in the handler diary Activity Through 2026-05-24. Since that update, the story moved into two new places: the United States government, which formally caught up to the campaign, and the wider population of attackers now wielding the Mini Shai-Hulud framework that TeamPCP open-sourced last month.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 06/08/2026, 17:18:49 UTC

Technical Analysis

The TeamPCP supply chain campaign, tracked by SANS ISC and formally acknowledged by CISA, exploits subverted build pipelines to distribute malicious artifacts, including the Mini Shai-Hulud credential-stealing worm. Key vulnerabilities (CVE-2026-45321 and CVE-2026-48027) were added to CISA's KEV catalog with a remediation deadline of 2026-06-10. The campaign's open-sourced framework has led to copycat attacks compromising at least 32 Red Hat npm packages (Miasma wave) and a follow-on Phantom Gyp wave affecting 57 additional packages. Attackers used a compromised Red Hat employee GitHub account to inject malicious GitHub Actions workflows, resulting in valid SLSA provenance attestations despite the malicious payload. Phantom Gyp introduced install-time evasion by abusing binding.gyp and node-gyp hooks, bypassing monitors focused on package.json scripts. Attribution is ambiguous due to the public availability of the Mini Shai-Hulud framework. The campaign's monetization channels remain dormant, focusing currently on ecosystem-scale worming rather than targeted extortion.

Potential Impact

The campaign enables attackers to distribute malicious code through trusted supply chain components, leading to credential theft and potential further compromise of cloud and CI/CD environments. The subversion of build pipelines allows attackers to produce validly signed malicious artifacts, undermining trust in provenance attestations. The compromise of widely used npm packages affects thousands of users and organizations relying on these packages, increasing the risk of widespread credential exposure and unauthorized access. The use of advanced install-time evasion techniques complicates detection and mitigation efforts. Although no active extortion or ransomware activity is currently observed, the campaign poses a significant medium-level threat to software supply chain integrity and cloud security.

Mitigation Recommendations

A fix is available as per CISA advisories with a remediation deadline of 2026-06-10 for CVE-2026-45321 and CVE-2026-48027. Defenders should confirm removal of the compromised Nx Console v18.95.0 and remediation of TanStack-related exposures. Rotate all CI/CD-accessible secrets and cloud credentials and review CI/CD logs and cloud audit trails as recommended by CISA. Inventory and pin affected npm packages (@redhat-cloud-services, @vapi-ai/server-sdk, and others) to known-good versions rebuilt from trusted sources. Enhance detection to monitor install-time execution beyond package.json scripts, including binding.gyp and node-gyp hooks, and consider disabling install scripts in CI environments where feasible. Do not rely solely on SLSA provenance attestations; implement build environment integrity controls and behavioral monitoring. Enforce two-factor authentication on registry maintainer accounts, narrowly scope publish tokens, and alert on anomalous workflow changes in source repositories. Monitor for further advisories and updates from vendors and government agencies.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Article Source
{"url":"https://isc.sans.edu/diary/rss/33060","fetched":true,"fetchedAt":"2026-06-08T17:18:40.167Z","wordCount":1473}

Threat ID: 6a26f970e29bf47b504ccaae

Added to database: 06/08/2026, 17:18:40 UTC

Last enriched: 06/08/2026, 17:18:49 UTC

Last updated: 07/30/2026, 11:01:07 UTC

Views: 139

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses