Wireshark 4.6.6 Released, (Sun, May 24th)
2026-05-24T19:23:49Z•accd78ecc2197dcac96f9246145b7aa678ef24092be81ddd2d734c88c33867c9
CheckmarxMini-Shai-HuludTeamPCPjenkins-pluginmalwarenodejsnpmpackage-repo-compromisepatchpypisha256:049300aa5dd774d6c984779a0570f59610399c71864b5d5c2605906dbsoftware-updatestealersupply-chainwiresharkwireshark-4.6.6worm
What happened
SANS ISC diary roundup (mid‑May 2026): Wireshark 4.6.6 was released to address one vulnerability and 11 bug fixes (no CVE referenced in the entry). Analysis identified a heavily obfuscated cross‑platform Node.js stealer (SHA256 049300aa5dd774d6c984779a0570f59610399c71864b5d5c2605906db46ddeb9) observed in static analysis. Significant supply‑chain activity from the TeamPCP campaign: an officially confirmed compromise of a Checkmarx Jenkins plugin and emergence of a self‑spreading “Mini Shai‑Hulud” worm propagating via npm and PyPI, increasing developer‑tooling and package registry risk. Other, 1
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- sans_isc_diary
- Record identifier
- accd78ecc2197dcac96f9246145b7aa678ef24092be81ddd2d734c88c33867c9
- Enrichment time
- 2026-05-24T19:23:49Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.