TeamPCP Supply Chain Campaign: Activity Through 2026-06-07
Reported exploitedTeamPCP-linked toolingTeamPCPNx Console VS Code extensionBelow is the opening; the full story is at SANS Internet Storm Center.
From SANS Internet Storm Center
This diary continues the Internet Storm Center's tracking of the TeamPCP supply chain campaign, first documented in the SANS white paper When the Security Scanner Became the Weapon and most recently in the handler diary Activity Through 2026-05-24. Since that update, the story moved into two new places: the United States government, which formally caught up to the campaign, and the wider population of attackers now wielding the Mini Shai-Hulud framework that TeamPCP open-sourced last month.…
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.