Microsoft Access VBA, (Mon, May 25th)
2026-05-25T19:23:47Z•c08190a252814a74cec5bae4762c65b22e4131b1fc20a6a581ffc57c37d90e1f
TeamPCPlinuxmicrosoft-accessnodejsnpmproxypythonsdkstealersupply-chaintrojanvbavulnerabilitywireshark
What happened
SANS ISC diary collection (late May 2026) highlights a high-risk supply-chain campaign (TeamPCP) operating across three package ecosystems, including compromise/trojanization of an officially Microsoft-published Python SDK and apparent public release of its framework. A cross-platform Node.js/NPM stealer was identified (SHA256: 049300aa5dd774d6c984779a0570f59610399c71864b5d5c2605906db46ddeb9) after static analysis. Wireshark 4.6.6 was released to address one vulnerability and multiple bugs. Other notes: Microsoft Access files can contain VBA code that may be abused, an article on stack string/
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- sans_isc_diary
- Record identifier
- c08190a252814a74cec5bae4762c65b22e4131b1fc20a6a581ffc57c37d90e1f
- Enrichment time
- 2026-05-25T19:23:47Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.