ISC Stormcast For Wednesday, May 20th, 2026 https://isc.sans.edu/podcastdetail/9938, (Wed, May 20th)

2026-05-20T19:23:47Z3a67a577c183bbec3d27e3faba1f9c3411e71b0e447a4a93f265e9d67d10f49a
CI/CDCheckmarxJenkinsPyPITeamPCPlink-preview-bypassmalware-librariesmini-shai-huludnpmoutlookphishingplugin-compromisesignaturessoftware-supply-chainsupply-chainwebsite-fraudworm

What happened

Recent ISC SANS diary entries (May 2026) highlight an active TeamPCP supply-chain campaign: an officially confirmed compromise of a Checkmarx Jenkins plugin and a newly observed self‑spreading "Mini Shai-Hulud" worm propagating via npm and PyPI packages. Coverage stresses elevated risk to CI/CD pipelines and downstream consumers of compromised packages, and the need to audit plugins, revoke/replace compromised artifacts, and harden package management and build infrastructure. Additional entries note new malware libraries requiring updated signatures, techniques for bypassing Outlook Junk‑folde

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
sans_isc_diary
Record identifier
3a67a577c183bbec3d27e3faba1f9c3411e71b0e447a4a93f265e9d67d10f49a
Enrichment time
2026-05-20T19:23:47Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.