news.mlab.sh
Back to the feed
supply-chain

TeamPCP Supply Chain Campaign: Activity Through 2026-06-07, (Mon, Jun 8th)

High
Summary

This report details the ongoing TeamPCP supply chain campaign, which has recently seen increased activity and expanded impact. CISA has formally acknowledged and addressed the campaign, adding vulnerabilities to its Known Exploited Vulnerabilities catalog and issuing an advisory. Simultaneously, the open-source Mini Shai-Hulud framework has been weaponized, leading to a significant npm supply chain attack dubbed "Miasma" targeting Red Hat packages, followed by a rapid proliferation of a "Phantom Gyp" variant. The shift indicates a move from direct TeamPCP attribution to a broader ecosystem of attackers utilizing the framework's techniques.

The TeamPCP supply chain campaign, initially tracked by the SANS Internet Storm Center, has escalated significantly in June 2026. CISA’s belated response, adding vulnerabilities like CVE-2026-45321 and CVE-2026-48027 to its KEV catalog and issuing a standalone advisory, marks a crucial shift in the campaign’s trajectory. This action directly addresses the previously identified gaps in government response and provides critical remediation guidance. The campaign now involves the widespread deployment of the Mini Shai-Hulud framework, demonstrating its operational viability beyond its initial open-source release.

The most immediate impact stems from the "Miasma" attack, a credential-stealing worm targeting Red Hat npm packages. This attack leveraged a compromised GitHub account to inject malicious GitHub Actions workflows, resulting in the compromise of over 32 packages with a combined download volume of approximately 80,000 per week. The attack utilized a preinstall script and cloud-identity collectors, highlighting the sophistication of the attackers. Following this, a faster-spreading variant, "Phantom Gyp," further amplified the threat, compromising an additional 57 packages within a short timeframe. These incidents underscore the potential for rapid dissemination of malicious code within supply chain environments.

CISA’s actions and the deployment of the Mini Shai-Hulud framework represent a significant evolution in the campaign. The focus has shifted from direct attribution to a broader ecosystem of attackers leveraging the framework’s techniques. This indicates a move towards a more decentralized and adaptable threat model, where the same tradecraft – subverted build pipelines and install-time credential theft – can be deployed by various actors without necessarily originating from TeamPCP. The campaign now emphasizes ecosystem-scale worming rather than targeted extortion.

Read the full article at SANS Internet Storm Center