Wireshark 4.6.6 Released, (Sun, May 24th)
2026-05-25T07:23:44Z•5236928ec2763d884e690b7ed300bf724bc1211ace71c60ae74f3d236bb64b5d
CheckmarxJenkinsTeamPCPmalwarenodejsnpmobfuscationpypisha256:049300aa5dd774d6c984779a0570f59610399c71864b5d5c2605906dbstealersupply chainvulnerabilitywiresharkworm
What happened
SANS ISC Diary (mid-May 2026) roundup: Wireshark 4.6.6 released (fixes 1 vulnerability and 11 bugs). A heavily obfuscated cross-platform Node.js stealer was found (SHA256: 049300aa5dd774d6c984779a0570f59610399c71864b5d5c2605906db46ddeb9) — only static analysis performed. TeamPCP supply-chain activity continues, including an officially confirmed Checkmarx Jenkins plugin compromise and a self-spreading “Mini Shai-Hulud” worm propagating via npm and PyPI. Other posts cover malware development techniques (stack strings), selective HTTP proxying on Linux, and regular ISC Stormcast podcast notes.
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- sans_isc_diary
- Record identifier
- 5236928ec2763d884e690b7ed300bf724bc1211ace71c60ae74f3d236bb64b5d
- Enrichment time
- 2026-05-25T07:23:44Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.