supply-chain TeamPCP Supply Chain Campaign: Activity Through 2026-06-07, (Mon, Jun 8th) This report details the ongoing TeamPCP supply chain campaign, which has recently seen increased activity and expanded impact. CISA has formally acknowledged and addressed the campaign, adding vulnerabilities to its Known Exploited Vulnerabilities catalog and issuing an advisory. Simultaneously, the open-source Mini Sh… SANS Internet Storm Center · Jun 8, 2026 High CVE-2026-45321CVE-2026-48027CVE-2026-8398USsupply chainnpmgithub
vulnerability CISA Adds Three Known Exploited Vulnerabilities to Catalog CISA has added three new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2026-8398 Daemon Tools Lite Embedded Malicious Code Vulnerability CVE-2026-453… CISA Advisories · May 27, 2026 Medium CVE-2026-8398CVE-2026-45321CVE-2026-48027
supply-chain TeamPCP Supply Chain Campaign: Activity Through 2026-05-24, (Mon, May 25th) TeamPCP, a threat actor, launched a sophisticated supply chain campaign involving the malicious publication of compromised code extensions and SDKs across multiple platforms, including GitHub, npm, and PyPI. This campaig… SANS Internet Storm Center · May 25, 2026 High CVE-2026-45321supply chaincredential theftdeveloper tools
supply-chain TeamPCP Supply Chain Campaign: Activity Through 2026-05-24, (Mon, May 25th) TeamPCP, a threat actor, launched a sophisticated supply chain campaign involving the trojanization of multiple software packages, impacting GitHub, Microsoft, OpenAI, Grafana Labs, and Mistral AI. The campaign utilized… SANS Internet Storm Center · May 25, 2026 High CVE-2026-45321supply chain attackcredential theftpublisher badge
threat-intel GitHub Internal Repositories Breached via Malicious Nx Console VS Code Extension GitHub experienced a breach of its internal repositories due to a compromised employee device utilizing a malicious VS Code extension, the Nx Console. The attack, orchestrated by TeamPCP, leveraged a supply chain vulnera… The Hacker News · May 21, 2026 High CVE-2026-45321CVE-2026-48027supply chainvscodeopen source
supply-chain TeamPCP Supply Chain Campaign: Activity Through 2026-05-17, (Mon, May 18th) The TeamPCP supply chain campaign intensified significantly on May 17th, 2026, marked by the confirmed compromise of a Checkmarx Jenkins plugin and the emergence of a new Mini Shai-Hulud worm. This campaign targeted npm… SANS Internet Storm Center · May 18, 2026 Critical CVE-2026-45321CVE-2025-29927CVE-2025-55182GBILIRsupply-chainnpmpypi