threat-intel GitHub Internal Repositories Breached via Malicious Nx Console VS Code Extension GitHub experienced a breach of its internal repositories due to a compromised employee device utilizing a malicious VS Code extension, the Nx Console. The attack, orchestrated by TeamPCP, leveraged a supply chain vulnera… The Hacker News · May 21, 2026 High CVE-2026-45321CVE-2026-48027supply chainvscodeopen source
threat-intel GitHub Confirms Breach, 4K Internal Repos Stolen GitHub experienced a data breach where approximately 4,000 internal code repositories were stolen by the threat actor TeamPCP. The breach originated from a poisoned VS Code extension compromising an employee's device, an… Dark Reading · May 20, 2026 High vscodeopen sourcedeveloper tooling
threat-intel GitHub Breached — Employee Device Hack Led to Exfiltration of 3,800+ Internal Repos GitHub experienced a breach originating from an employee device compromised by a poisoned Microsoft Visual Studio Code extension. The attacker exfiltrated over 3,800 internal repositories, facilitated by the threat actor… The Hacker News · May 20, 2026 High USILIRsupply chaincredential theftinfostealer
supply-chain GitHub confirms breach of 3,800 repos via malicious VSCode extension GitHub experienced a breach affecting approximately 3,800 internal repositories after an employee installed a malicious VS Code extension. The incident is linked to a broader supply chain attack by TeamPCP, who are deman… BleepingComputer · May 20, 2026 High supply chainvscodeextension
threat-intel GitHub investigates internal repositories breach claimed by TeamPCP GitHub is investigating a breach of its internal repositories following a claim by the TeamPCP hacker group, who gained access to approximately 4,000 private code repositories. The incident highlights a vulnerability wit… BleepingComputer · May 20, 2026 High supply-chaingithubmalware
supply-chain Mini Shai-Hulud Pushes Malicious AntV npm Packages via Compromised Maintainer Account A sophisticated supply chain attack, dubbed Mini Shai-Hulud, is targeting npm packages within the @antv ecosystem. The attack leverages a compromised maintainer account to inject malicious code – specifically a credentia… The Hacker News · May 19, 2026 High USsupply chainnpmcredential theft
supply-chain TeamPCP Supply Chain Campaign: Activity Through 2026-05-17, (Mon, May 18th) The TeamPCP supply chain campaign intensified significantly on May 17th, 2026, marked by the confirmed compromise of a Checkmarx Jenkins plugin and the emergence of a new Mini Shai-Hulud worm. This campaign targeted npm… SANS Internet Storm Center · May 18, 2026 Critical CVE-2026-45321CVE-2025-29927CVE-2025-55182GBILIRsupply-chainnpmpypi
threat-intel Shai-Hulud Worm Clones Spread After Code Release The release of Shai-Hulud source code by TeamPCP, a financially motivated threat actor, has triggered the spread of clones targeting software developers and the open-source ecosystem. This incident highlights a new attac… Dark Reading · May 18, 2026 High supply-chainopen-sourcedeveloper
threat-intel ⚡ Weekly Recap: Exchange 0-Day, npm Worm, Fake AI Repo, Cisco Exploit and More This week’s security news highlights several active exploits and attacks, including a widespread vulnerability in on-prem Exchange Servers, a Cisco SD-WAN controller compromise attributed to UAT-8616, and a significant s… The Hacker News · May 18, 2026 High CVE-2026-42897CVE-2026-20182CVE-2026-20127USexchangesupply chainnpm
threat-intel Four Malicious npm Packages Deliver Infostealers and Phantom Bot DDoS Malware Four npm packages have been identified as containing malicious code, including a clone of the Shai-Hulud worm. One package delivers a DDoS botnet (Phantom Bot), while the others function as infostealers, stealing sensiti… The Hacker News · May 18, 2026 High NOsupply chainnpminfostealer
threat-intel ‘CanisterWorm’ Springs Wiper Attack Targeting Iran A financially motivated cybercrime group, TeamPCP, is deploying a wiper attack targeting Iran, leveraging a self-propagating worm that exploits vulnerabilities in cloud services like Azure and AWS. The group gained initi… Krebs on Security · Mar 23, 2026 High IRcloud securitysupply chain attackwiper