ISC Stormcast For Wednesday, May 27th, 2026 https://isc.sans.edu/podcastdetail/9946, (Wed, May 27th)

2026-05-27T07:23:50Z4f347c6704d5a3a8d4c13a7adb572ca16719e574307316e849ec41c163a978aa
TeamPCPacr-stealergithubmalwaremicrosoft-accessnodejsnpmopen-sourcepatchpythonsha256:049300aa5dd774d6c984779a0570f59610399c71864b5d5c2605906dbstack-stringstealersupply-chaintrainingtrojanized-sdkvbavulnerabilityweb-impersonationwireshark

What happened

Feed of ISC SANS diary entries (May 22–27, 2026) highlighting a high-risk supply-chain campaign and multiple malware-related notes. TeamPCP supply chain activity (through 2026-05-24) is detailed: the actor now operates across three package ecosystems, has trojanized an officially Microsoft-published Python SDK, reached parts of GitHub’s internal codebase, and appears to have open-sourced its framework — indicating active, widespread supply‑chain compromise. Other items include a cross-platform Node.js/NPM stealer (SHA256 049300aa5dd774d6c984779a0570f59610399c71864b5d5c2605906db46ddeb9) that is

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
sans_isc_diary
Record identifier
4f347c6704d5a3a8d4c13a7adb572ca16719e574307316e849ec41c163a978aa
Enrichment time
2026-05-27T07:23:50Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · ISC Stormcast For Wednesday, May 27th, 2026 https://isc.sans.edu/podcastdetail/9946, (Wed, May 27th) · Baitaphish