supply-chain 'Hades' Campaign Against PyPI Puts New Spin on Shai-Hulud A new wave of attacks, dubbed the 'Hades' campaign, has targeted the Python Package Index (PyPI) with a variant of the Shai-Hulud worm. This campaign involved compromising 37 PyPI wheels and 19 code packages, utilizing a… Dark Reading · Jun 8, 2026 High USsupply-chainpythonopen-source
threat-intel ⚡ Weekly Recap: Instagram Account Hacks, Android Zero-Day, GitHub Worm and More This week’s security news highlights a series of attacks and vulnerabilities, including a supply chain attack targeting Microsoft GitHub repositories via the Miasma Worm, a zero-day exploit in Android, and ongoing cyberc… The Hacker News · Jun 8, 2026 High CVE-2025-48595CVE-2026-28318CVE-2026-39210CHUSGEsupply-chainzero-daycybercrime
supply-chain Miasma Worm Hits 73 Microsoft GitHub Repositories in Major Supply Chain Attack A sophisticated supply chain attack, dubbed Miasma, has compromised 73 Microsoft GitHub repositories, including several within the Azure and Microsoft organizations. The attack leverages a re-compromised PyPI package, du… The Hacker News · Jun 6, 2026 High supply chaingithubopen source
threat-intel PCPJack Hijacks 230 AWS, Google Cloud, and Azure Servers for Covert SMTP Relay Network PCPJack, a threat actor initially linked to TeamPCP, has established a covert SMTP email relay network by hijacking 230 cloud servers across AWS, Google Cloud, and Azure. The operation involved converting business server… The Hacker News · Jun 5, 2026 High USUKDEsmtp relaycloud proxyc2
supply-chain New IronWorm malware hits 36 packages in npm supply-chain attack A new supply-chain attack leveraging the IronWorm malware has compromised 36 npm packages, targeting developers and CI environments with infostealer capabilities. The malware utilizes stolen credentials and a sophisticat… BleepingComputer · Jun 4, 2026 High supply chainnpmrust
threat-intel Researcher publishes GitHub token-stealing exploit, blames Microsoft’s disclosure process A security researcher, Ammar Askar, released a GitHub token-stealing exploit for Microsoft's VS Code, citing frustration with the company's vulnerability disclosure process. This follows a recent breach of GitHub reposit… The Record · Jun 4, 2026 High githubvulnerabilitydisclosure
supply-chain Red Hat removes tainted packages after software pipeline compromise Red Hat removed numerous software packages from its distribution pipeline after a compromised GitHub account was used to distribute credential-stealing malware. The attack, utilizing a variant of the Mini Shai-Hulud worm… The Record · Jun 2, 2026 High NOUKsupply chaingithubmalware
supply-chain Red Hat npm packages compromised to steal developer credentials A supply-chain attack targeting Red Hat npm packages resulted in the distribution of a new variant of the Shai-Hulud credential-stealing malware, dubbed 'Miasma'. The attackers compromised a Red Hat employee's GitHub acc… BleepingComputer · Jun 1, 2026 High USsupply chaincredential theftgithub
supply-chain Miasma Supply Chain Attack Compromises Red Hat npm Packages with Credential-Stealing Worm A new supply chain attack, dubbed Miasma, has compromised Red Hat npm packages, utilizing a self-propagating worm to steal credentials and secrets from developer machines. The attack, leveraging techniques similar to the… The Hacker News · Jun 1, 2026 High USsupply chain attackcredential theftgithub actions
threat-intel Containers on fire: from container escapes to supply chain attacks This Securelist article examines the evolving threat landscape targeting container environments, highlighting key attack vectors used by groups like TeamPCP. The analysis focuses on vulnerabilities, supply chain attacks… Securelist · Jun 1, 2026 High CVE-2019-5736CVE-2022-0492CVE-2024-21626UScontainerskubernetessupply chain
threat-intel Out of the Crypt: The Evolving Cyber Extortion Economy This report from Palo Alto Unit 42 highlights a significant shift in the cyber extortion landscape, moving away from ransomware-based pressure towards pure data theft and extortion. The trend is driven by factors like ad… Palo Alto Unit 42 · May 27, 2026 High USdata theftextortionsupply chain
supply-chain Feeding Frenzy: 'Megalodon' Malware Infects Thousands of GitHub Repos A six-hour malware campaign, dubbed 'Megalodon,' targeted over 5,500 GitHub repositories, injecting malicious commits containing credential-stealing payloads. The campaign, orchestrated by an unknown threat actor potenti… Dark Reading · May 26, 2026 High githubsupply-chainmalware
threat-intel The Hackers Behind Shai-Hulud: Lucky or Skilled? The cybercrime group TeamPCP has been identified as a primary driver behind the Shai-Hulud worm, causing significant damage to the open-source ecosystem through exploiting vulnerabilities like React2Shell and misconfigur… Dark Reading · May 26, 2026 High USsupply-chainopen-sourcedeveloper-tooling
threat-intel ⚡ Weekly Recap: Linux Flaws, Defender 0-Days, Router Botnets, and Supply Chain Chaos This week’s security news highlights a significant GitHub breach orchestrated by TeamPCP, stemming from a compromised developer’s device and leveraging vulnerabilities exposed by the TanStack supply chain attack. Simulta… The Hacker News · May 25, 2026 High CVE-2026-46333CVE-2026-41091CVE-2026-45498USGBsupply-chainlinuxgithub
supply-chain TeamPCP Supply Chain Campaign: Activity Through 2026-05-24, (Mon, May 25th) TeamPCP, a threat actor, launched a sophisticated supply chain campaign involving the malicious publication of compromised code extensions and SDKs across multiple platforms, including GitHub, npm, and PyPI. This campaig… SANS Internet Storm Center · May 25, 2026 High CVE-2026-45321supply chaincredential theftdeveloper tools
supply-chain TeamPCP Supply Chain Campaign: Activity Through 2026-05-24, (Mon, May 25th) TeamPCP, a threat actor, launched a sophisticated supply chain campaign involving the trojanization of multiple software packages, impacting GitHub, Microsoft, OpenAI, Grafana Labs, and Mistral AI. The campaign utilized… SANS Internet Storm Center · May 25, 2026 High CVE-2026-45321supply chain attackcredential theftpublisher badge
supply-chain Over 5,500 GitHub Repositories Infected in ‘Megalodon’ Supply Chain Attack A sophisticated supply chain attack, dubbed Megalodon, has infected over 5,500 GitHub repositories by injecting malicious code into automated workflows. The attack leverages compromised versions of the Tiledesk package t… SecurityWeek · May 25, 2026 High supply chaingithubmalware
supply-chain npm Adds 2FA-Gated Publishing and Package Install Controls Against Supply Chain Attacks npm has implemented a new staged publishing feature to bolster the security of its software supply chain, addressing concerns about malicious package releases. This system requires maintainers to verify releases with a t… The Hacker News · May 23, 2026 High supply-chain2fasecurity
supply-chain Megalodon GitHub Attack Targets 5,561 Repos with Malicious CI/CD Workflows A sophisticated cyberattack, dubbed Megalodon, has targeted over 5,500 GitHub repositories using malicious CI/CD workflows. The attacker leveraged throwaway accounts and forged author identities to exfiltrate sensitive d… The Hacker News · May 22, 2026 Critical IRILci/cdgithubsupply chain
supply-chain GitHub links repo breach to TanStack npm supply-chain attack A supply-chain attack targeting GitHub originated with a malicious version of the Nx Console VS Code extension, facilitated by the TeamPCP threat group. The attack compromised over 3,800 internal repositories and extende… BleepingComputer · May 21, 2026 High USsupply-chainnpmvscode