TeamPCP Supply Chain Campaign: Activity Through 2026-06-07, (Mon, Jun 8th)

2026-06-09T01:23:47Z479e7878d454045b0c3327dfb7ed719f4b2e895ea20ffccdccde9e7da3d1d7ab
API discoveryJPEG steganographyMSI backgroundMini Shai-HuludSANS ISCSVG phishingTeamPCPmalwareopen-source malwarephishingscanningsupply chainsupply-chain compromiseswagger.jsonthreat intelligence

What happened

SANS ISC diaries from early June 2026 describe ongoing activity around the TeamPCP supply-chain campaign — including the US government formally acknowledging the campaign and broader attacker adoption after TeamPCP open-sourced the Mini Shai‑Hulud framework. Related telemetry shows multiple malicious delivery techniques in use: payloads embedded in JPEGs (MSI‑branded background), phishing using SVG attachments, and continued scanning for swagger.json endpoints (exposed API metadata). Overall this indicates active, evolving supply‑chain and phishing activity with tooling being reused and repack

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
sans_isc_diary
Record identifier
479e7878d454045b0c3327dfb7ed719f4b2e895ea20ffccdccde9e7da3d1d7ab
Enrichment time
2026-06-09T01:23:47Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · TeamPCP Supply Chain Campaign: Activity Through 2026-06-07, (Mon, Jun 8th) · Baitaphish