Possible ACR Stealer From Page Impersonating Claude, (Tue, May 26th)
2026-05-26T01:23:46Z•bc7718239d3288a725c4d84c3b8698209ceada53989cd8c12c06e6e7ada58733
credential-theftgithub-compromisenodejsnpmsha256:049300aa5dd774d6c984779a0570f59610399c71864b5d5c2605906dbstealersupply-chainteampcptrojanized-python-sdk
What happened
SANS ISC diary roundup (May 21–26, 2026): Key findings include a notable supply‑chain campaign by “TeamPCP” that now operates across three package ecosystems, trojanized an officially Microsoft‑published Python SDK, reached parts of GitHub’s internal codebase, and appears to have published its framework on GitHub — indicating a broad, persistent supply‑chain compromise. A cross‑platform Node.js/NPM stealer was identified (SHA256 049300aa5dd774d6c984779a0570f59610399c71864b5d5c2605906db46ddeb9); it was heavily obfuscated and only statically analyzed. A web page impersonating the Claude AI page/
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- sans_isc_diary
- Record identifier
- bc7718239d3288a725c4d84c3b8698209ceada53989cd8c12c06e6e7ada58733
- Enrichment time
- 2026-05-26T01:23:46Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.