ISC Stormcast For Wednesday, May 27th, 2026 https://isc.sans.edu/podcastdetail/9946, (Wed, May 27th)
2026-05-27T19:23:54Z•d686007a7dfe2cd9cc236581bf602aeefb80a7f46682f55eba2cfcd791ff5d6d
TeamPCPclaude-impersonationgithub-compromisemalwaremicrosoft-access-vbanodejsnpm-stealeropen-source-frameworkpackage-ecosystemspossible-acr-stealerred-teamsha256:049300aa5dd774d6c984779a0570f59610399c71864b5d5c2605906dbsoftware-updatestack-stringsupply-chaintrojanized-python-sdkwireshark-4.6.6
What happened
SANS ISC diary roundup (May 22–27, 2026) highlights an active supply‑chain campaign by 'TeamPCP' that now operates across three package ecosystems, trojanized an officially Microsoft‑published Python SDK, reached parts of GitHub's internal codebase, and published its framework on GitHub. Other notable items include a cross‑platform Node.js/NPM stealer (sample SHA256 049300aa5dd774d6c984779a0570f59610399c71864b5d5c2605906db46ddeb9) and a reported page impersonating 'Claude' that may be used to deploy an ACR stealer. Wireshark 4.6.6 was released (fixes one vulnerability and multiple bugs). Misc:
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- sans_isc_diary
- Record identifier
- d686007a7dfe2cd9cc236581bf602aeefb80a7f46682f55eba2cfcd791ff5d6d
- Enrichment time
- 2026-05-27T19:23:54Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.