Cross-Platform NPM Stealer, (Fri, May 22nd)
2026-05-22T13:23:46Z•8dcd74bcacdd4e1a831eee3f3980763b834193be23483728e9cd8026e901e6d7
checkmarxjenkinslinuxmini-shai-huludnodejsnpmobfuscationoutlookproxifierpypisha256:049300aa5dd774d6c984779a0570f59610399c71864b5d5c2605906dbstatic-analysisstealersupply-chainworm
What happened
SANS ISC diary entries describe a well‑obfuscated cross‑platform Node.js stealer (SHA256 049300aa5dd774d6c984779a0570f59610399c71864b5d5c2605906db46ddeb9) that was only statically analyzed because it would not run in sandbox. Separately, the TeamPCP supply‑chain campaign continues through May 2026 with an officially confirmed Checkmarx Jenkins plugin compromise and a new self‑spreading "Mini Shai‑Hulud" worm observed propagating via npm and PyPI. Other notes discuss selective HTTP proxying on Linux (lack of a generic tool) and a simple bypass of Outlook link preview in the Junk folder.
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- sans_isc_diary
- Record identifier
- 8dcd74bcacdd4e1a831eee3f3980763b834193be23483728e9cd8026e901e6d7
- Enrichment time
- 2026-05-22T13:23:46Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.