supply-chain
TeamPCP Supply Chain Campaign: Activity Through 2026-05-17, (Mon, May 18th)
Critical
Summary
The TeamPCP supply chain campaign intensified significantly on May 17th, 2026, marked by the confirmed compromise of a Checkmarx Jenkins plugin and the emergence of a new Mini Shai-Hulud worm. This campaign targeted npm and PyPI, impacting numerous packages including TanStack components, and introduced novel techniques such as SLSA Build Level 3 provenance malware and destructive disk-wipe capabilities. The NHS England issued an alert, highlighting the need for enhanced security practices within CI environments.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data