Selective HTTP Proxying in Linux, (Thu, May 21st)

2026-05-22T01:23:47Z59999edad7443202f5d0793c76c8460adc54e8d2c29fe437f0b918357a4fa42d
CheckmarxJenkinsLinuxMini Shai-HuludOutlookProxifierPyPITeamPCPlink-previewmalwarenpmpackage-repositoryphishingproxyingsupply-chainsupply-chain-compromisethreat-actorworm

What happened

The ISC SANS diary collection (mid–May 2026) highlights a high-impact supply-chain campaign (TeamPCP) with an officially confirmed compromise of a Checkmarx Jenkins plugin and a new self‑spreading “Mini Shai‑Hulud” worm propagating across npm and PyPI — significant developer-tooling/package-repository risk that raises supply‑chain, persistence, and detection concerns. Other notes: discussion of per-process HTTP proxying (Proxifier equivalents) and the lack of a generic Linux tool for selective proxying useful in debugging/reverse engineering; a reported simple bypass reducing the effectiveness

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
sans_isc_diary
Record identifier
59999edad7443202f5d0793c76c8460adc54e8d2c29fe437f0b918357a4fa42d
Enrichment time
2026-05-22T01:23:47Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Selective HTTP Proxying in Linux, (Thu, May 21st) · Baitaphish