CVE Tools

TeamPCP Supply Chain Campaign: Activity Through 2026-06-07

SANS Internet Storm CenterBy SANS Internet Storm Center7 min read

Reported exploitedTeamPCP-linked toolingTeamPCPNx Console VS Code extension
Read at SANS Internet Storm Center

Below is the opening; the full story is at SANS Internet Storm Center.

From SANS Internet Storm Center

This diary continues the Internet Storm Center's tracking of the TeamPCP supply chain campaign, first documented in the SANS white paper When the Security Scanner Became the Weapon and most recently in the handler diary Activity Through 2026-05-24. Since that update, the story moved into two new places: the United States government, which formally caught up to the campaign, and the wider population of attackers now wielding the Mini Shai-Hulud framework that TeamPCP open-sourced last month.…

Continue at SANS Internet Storm Center

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store