TeamPCP Supply Chain Campaign: Activity Through 2026-05-17, (Mon, May 18th)

2026-05-19T01:23:43Z5d842d65667eb09e9597ff232958a36334b8fb25fd7c473ada872550e7012718
CheckmarxJenkins-plugin-compromiseMicrosoft-Patch-TuesdayMini-Shai-HuludPyPITeamPCPmalwarenpmoutlook-link-preview-bypassphishingsupply-chainworm

What happened

SANS ISC reports a surge in activity from the TeamPCP supply-chain campaign: an officially confirmed compromise of a Checkmarx Jenkins plugin and the emergence of a self‑spreading “Mini Shai‑Hulud” worm propagating through npm and PyPI. Related coverage includes the May 2026 Microsoft Patch Tuesday (137 vulnerabilities addressed), new malware libraries driving signature updates, and various phishing/abuse techniques (Outlook junk folder link preview bypass, website fraud, EXE proxying).

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
sans_isc_diary
Record identifier
5d842d65667eb09e9597ff232958a36334b8fb25fd7c473ada872550e7012718
Enrichment time
2026-05-19T01:23:43Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · TeamPCP Supply Chain Campaign: Activity Through 2026-05-17, (Mon, May 18th) · Baitaphish