Search/tanstack
Vendor

tanstack

Known CVEs
0
Highest CVSS
In KEV
0
Vendor
tanstack/react-start-rsc
Connections
92 relationships
In Australia arrestati due membri del gruppo hacker TeamPCP
La polizia federale australiana (AFP) ha annunciato l’arresto di due presunti membri del gruppo hacker TeamPCP , collegato a massicci attacchi alle catene di approvvigionamento. Secondo le indagini, gli attacchi del gruppo potrebbero aver coinvolto più di 1000 organizzazioni in tutto il mondo , e gli hacker criminali hanno rubato alle vittime oltre 500.000 credenziali e non meno di 300 GB di informazioni. Le forze dell’ordine hanno arrestato Ruben Ian Thomson , 21 anni, e Louis Michael Gaebler, 23 anni, della Western Australia. A loro sono stati mossi complessivamente 14 capi d’accusa accesso non autorizzato a sistemi informatici, otten:imento, conservazione e diffusione illegale di dati rubati, nonché altri reati informatici. Inoltre, Thomson è accusato separatamente di operazioni con proventi illeciti per un importo di almeno 100.000 dollari USA e di rifiuto di ottemperare alla richiesta della polizia di fornire accesso a dati elettronici. Per il più grave di questi episodi, gli viene comminata una pena fino a 20 anni di reclusione. Ricordiamo che il gruppo TeamPCP ha guadagnato notorietà grazie ad attacchi alle catene di approvvigionamento open source . Tra gli attacchi più noti del gruppo è stato l’attacco allo scanner di vulnerabilità  Aqua Security’s Trivy , avvenuto nella primavera del 2026. I dati ottenuti durante questo attacco sono stati successivamente utilizzati contro KICS, e lo stesso Trivy infetto è entrato nel pipeline di LiteLLM, permettendo il furto di un token di accesso. Di conseguenza, gli hacker sono riusciti a pubblicare versioni infette di LiteLLM su PyPI . Di recente, esperti di CloudSEK e Hudson Rock  hanno riferito che in soli 40 minuti, mentre le versioni dannose di LiteLLM si diffondevano attraverso PyPI, gli attaccanti sono riusciti a rubare segreti da 434.000 pipeline CI/CD . Secondo i ricercatori, tra le vittime si trovano alcune delle più grandi aziende tecnologiche e industriali del mondo, e gli hacker hanno rubato terabyte di dati. TeamPCP è anche collegata alla compromissione dei pacchetti Telnyx, SAP и TanStack, e tra le organizzazioni vittime delle azioni del gruppo figurano Mistral AI, GitHub, OpenAI e altre. Secondo le stime degli investigatori dell’AFP, i costi sostenuti dalle aziende per eliminare le conseguenze di questi attacchi ammontano già a centinaia di milioni di dollari. Inoltre, la polizia afferma che Thomson e Gaebler hanno ricevuto pagamenti in criptovaluta per la loro partecipazione alle operazioni di TeamPCP , anche se l’importo esatto è ancora in fase di accertamento. L’indagine è iniziata ad aprile 2026 dopo che l’AFP e l’FBI hanno ricevuto informazioni su TeamPCP da diverse aziende di sicurezza informatica . Durante le perquisizioni, le forze dell’ordine hanno sequestrato dispositivi elettronici e un grande volume di dati presumibilmente rubati, che ora dovranno essere esaminati dagli esperti forensi. I rappresentanti dell’AFP sottolineano che l’indagine sull’attività del gruppo hacker è ancora in corso, quindi in futuro potrebbero seguire nuove accuse e arresti. Si noti che il giornalista indipendente di sicurezza informatica Brian Krebs (Brian Krebs) ha condotto un’indagine propria e dopo l’arresto di Thomson e Gaebler ha pubblicato i risultati. Egli scrive che già a giugno 2026 aveva identificato la vera identità di Thomson, dopo di che ha comunicato direttamente con lui per diversi mesi. Secondo Krebs, Thomson ha utilizzato numerosi pseudonimi, tra cui EllisD25, LSD, BulkDMT, Express e Persy_PCP , e questi account sono stati collegati grazie a una serie di gravi errori OPSEC: ad esempio, hanno aiutato ID Tox e Session uguali che sono stati pubblicati su diversi forum hacker. Inoltre, uno degli indirizzi IP collegati all’account ChristmasSnow di Thomson è stato utilizzato per anni dai server domestici della sua famiglia a Perth. Un altro indizio è stato trovato grazie all’indirizzo [email protected], che era collegato al profilo di Thomson su Airbnb, dove egli stesso scriveva di sé: “gli amici mi chiamano Ellis”. Inoltre, nel 2025 Thomson si è registrato sulla piattaforma HackerOne con il suo vero nome e ha scelto lo pseudonimo Deadcatx3 , che le aziende di sicurezza informatica avevano già collegato a TeamPCP. Nelle conversazioni con Krebs, Ellis affermava di essersi ritirato dalle attività di TeamPCP a marzo 2026, poco prima dell’attacco a LiteLLM, e che la guida del gruppo era passata a un’altra persona. Inoltre, affermava di aver guadagnato solo circa 20.000 dollari USA in tutto il tempo di collaborazione con TeamPCP. Circa due settimane prima dell’arresto, Thomson diceva al giornalista di voler abbandonare definitivamente la criminalità informatica e di essere disposto a consegnarsi alle autorità. L'articolo In Australia arrestati due membri del gruppo hacker TeamPCP proviene da Red Hot Cyber .
redhotcyber.comSep 1, 2026extracted
Two alleged TeamPCP hackers arrested over global supply chain attacks
Two alleged TeamPCP hackers arrested over global supply chain attacks Two men from Western Australia have been charged after police allege they were part of TeamPCP, a cybercrime group that planted malicious code in open-source software, then used it to break into organizations around the world. The Australian Federal Police (AFP), working with the FBI and Western Australia Police Force (WAPF), arrested a 21-year-old from Cottesloe and a 23-year-old from Mandurah on August 26. The 21-year-old Cottesloe man was charged with eight offences, including possessing and supplying data for use in computer offences, unauthorized modification of data, failing to comply with a section 3LA order, and dealing with proceeds of crime worth $100,000 or more. The charges carry maximum penalties ranging from three to 20 years in prison. The 23-year-old Mandurah man was charged with six computer-related offences, including possessing and supplying data for use in computer offences and unauthorized modification of data. The offences carry maximum penalties of up to five years in prison. “These men are allegedly members of the cybercriminal group TeamPCP, whose malicious code potentially compromised more than a thousand organizations worldwide,” FBI Cyber Division Assistant Director, Brett E. Leatherman, said. According to the AFP, the investigation started in April 2026 after several cyber threat assessment companies flagged a syndicate that had inserted malicious code into software hosted on an open-source repository. Developers who pulled that code into their own projects unknowingly spread it into systems across government, academia and the private sector. Once inside those systems, the code let the group harvest sensitive data, including login credentials and authentication tokens. The AFP estimates the campaign hit more than 1,000 organizations worldwide, with over 500,000 credentials stolen and at least 300 gigabytes of data taken. Global remediation costs are estimated in the hundreds of millions of dollars. “Cybercrime syndicates are becoming increasingly organised and often operate like professional businesses,” noted AFP Commander Graeme Marshall. Investigators say a large amount of seized data is still being examined, and they have not ruled out further arrests. TeamPCP has allegedly been behind supply chain attacks on GitHub, Telnyx, LiteLLM, Aqua’s Trivy, Checkmarx’s KICS, TanStack, MistralAI and Red Hat, using their self-spreading Mini Shai-Hulud worm to steal credentials and infect further packages. TeamPCP made headlines after being attributed to a self-replicating worm dubbed Shai-Hulud, which compromised more than 180 npm packages in September 2025 by stealing credentials and using them to spread to new packages automatically. It exfiltrated secrets to public GitHub repositories and turned victims’ private repos public. “There are absolutely no indications that TeamPCP was behind the original S1ngularity and Shai-Hulud attacks we saw in the summer of 2025. However, they did clone the worm, and it became regularly reported that they were behind the Shai-Hulud attacks. I want to make it clear that they are distinct attacks. We still don’t know who was behind the original attacks, and we may never know,” Aikido researcher Charlie Eriksen wrote. Eriksen described TeamPCP as difficult to categorize: neither a state actor, an organized cybercrime group, nor a purely ideological one. “They were also not especially sophisticated. What made them dangerous was their ability to take public exploits, techniques, research, and malware ideas and operationalize them quickly,“ Eriksen added.
helpnetsecurity.comAug 27, 2026extracted
Australia arrests alleged TeamPCP hackers behind supply-chain attacks
Australian authorities have arrested and charged two young men accused of being part of the TeamPCP hacking group linked to a string of far-reaching developer supply chain attacks. TeamPCP is a hacking group known for widespread supply-chain attacks over the past year that targeted open-source software and developer platforms to steal credentials, authentication secrets, and source code. High-profile attacks attributed to TeamPCP have impacted Trivy, LiteLLM, Telnyx, SAP, and TanStack packages, while the group has also breached the European Commission, Mistral AI, OpenAI, and GitHub. To carry out their attacks, the threat actors injected malicious code into software hosted on open-source repositories, which developers then unknowingly incorporated into their own applications on systems used by government, academic, and private-sector organizations. Rather than a cohesive group, the malicious activity is believed to have been carried out by a loose-knit collective of threat actors who all frequent the same hacking forums, Discord servers, and Telegram channels. According to the Australian Federal Police (AFP), the FBI, and Western Australia Police, malicious code distributed by TeamPCP has potentially compromised over a thousand organizations worldwide, enabling the theft of half a million credentials and the exfiltration of at least 300GB of data. "The alleged compromise of a small number of trusted software components had a significant global impact," reads the AFP announcement. "To date, the financial impact includes global remediation costs estimated to be hundreds of millions of dollars." The investigation began in April 2026, after the AFP and FBI received key information from cybersecurity firms. The two men, aged 21 and 23, were arrested in the western Australian cities of Cottesloe and Mandurah on August 26, 2026. During the law enforcement action, investigators also seized electronic devices and other evidence for forensic analysis. Police allege the two men received an undisclosed amount in cryptocurrency payments for their involvement in TeamPCP operations. After the arrests were announced, both Flare and Brian Krebs published separate investigations detailing how Telegram activity, reused aliases, accounts, and other online traces linked alleged TeamPCP members to real-world identities. The two suspects now face a combined 14 charges related to possessing and supplying data for computer offenses and modifying data to facilitate serious crimes. The younger of the two also faces charges for allegedly dealing with at least $100,000 in criminal proceeds and failing to comply with an order requiring access to electronic data. The charges carry maximum penalties of 3 to 20 years' imprisonment per charge. The AFP said further arrests or charges have not been ruled out at this stage, as it examines seized evidence. Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply. The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments. Get the report
bleepingcomputer.comAug 27, 2026extracted
Australia charges two men for TeamPCP supply-chain hacking spree
Australia charges two men for TeamPCP supply-chain hacking spree Two men in Australia were charged Wednesday over their alleged membership in TeamPCP, the cybercrime group blamed for one of the most damaging hacking campaigns of the past year. The men, both based in Perth, Western Australia, were charged with a combined 14 offenses after police executed search warrants at properties in the city’s suburbs and seized electronic devices. Australian authorities did not formally name the men, but national broadcaster ABC identified them as Ruben Ian Thomson, 21, and Louis Michael Gaebler, 23. In a statement, the federal police said “the men were part of a highly organised syndicate involved in large-scale cybercrime offending, including data intrusion, identity crime, and cryptocurrency-based money laundering.” Thomson, of the Perth suburb of Cottesloe, faces eight charges, including unauthorized modification of data, supplying and possessing data to commit a computer offense, dealing with proceeds of crime worth $100,000 or more and failing to comply with an order to hand over device passwords. Gaebler, of Mandurah, faces six related charges. Australian authorities allege both men were “principal participants” in the TeamPCP syndicate and were paid in cryptocurrency for their roles. Commenting on the suspects’ ages, Australian Federal Police Commander Graeme Marshall said police see “a lot of young offenders involved in cybercrime” who have “grown up in a cyber-native environment, and for whatever reason have decided to go down that pathway.” The Australian Federal Police said it worked with the Western Australia Police Force and the FBI in the investigation. Brett Leatherman, assistant director of the FBI’s Cyber Division, alleged the men were members of TeamPCP “whose malicious code potentially compromised more than a thousand organizations worldwide.” The prolific cybercrime group has carried out a series of supply chain attacks since March, often targeting developer tools including TanStack, Trivy and LiteLLM. Downstream victims have included the European Commission and GitHub. The attack on LiteLLM, an open-source Python package widely used by artificial intelligence systems, was initially feared to have potentially affected tens of thousands of corporate environments. Australian investigators estimate TeamPCP’s hacking campaign compromised more than 1,000 organizations worldwide, exposed more than 500,000 credentials and led to the theft of at least 300 gigabytes of data. Police said global remediation costs have reached hundreds of millions of dollars. Marshall said the operation demonstrated the value of cross-border cooperation against cybercrime, describing the agency’s network of law enforcement and industry partners as a “force multiplier.” “Cybercrime syndicates are becoming increasingly organised and often operate like professional businesses, but our investigators are relentless in tracking down criminals who attempt to exploit digital anonymity to attack our community,” Marshall said. Authorities said a large volume of seized data is still being examined and did not rule out further arrests. If convicted and given the maximum sentence on every count, the men could face a combined 82 years in prison, with 56 years for Thomson and 26 for Gaebler. In practice, however, sentences for multiple offenses are often served concurrently. Alexander Martin is the UK Editor for Recorded Future News. He was previously a technology reporter for Sky News and a fellow at the European Cyber Conflict Research Initiative, now Virtual Routes. He can be reached securely using Signal on: AlexanderMartin.79
therecord.mediaAug 27, 2026extracted
Supply chain software: Amazon conferma una campagna d’attacco che l’Italia ha già intercettato
Amazon ha attribuito a un gruppo di hacker legato alla Corea del Nord una serie di attacchi alla catena di distribuzione di alcune librerie JavaScript open source molto diffuse, pubblicate nel registro Node Package Manager (NPM), la raccolta di pacchetti software scritti in JavaScript pubblicamente disponibile in rete, più grande e maggiormente implementata dalle aziende di tutto il mondo. Per chi segue la sicurezza informatica in Italia, i nomi di questi pacchetti non sono una novità. L’Agenzia per la Cybersicurezza Nazionale (ACN) aveva infatti già segnalato entrambe le compromissioni più rilevanti, quella di Axios e quella di debug e chalk, attraverso due bollettini pubblicati sul portale csirt.gov.it rispettivamente nel marzo 2026 e nel settembre 2025. Indice degli argomenti Secondo l’analisi di Amazon Threat Intelligence, le compromissioni di questi pacchetti sarebbero riconducibili allo stesso attore statale, noto alla comunità della sicurezza informatica con diversi nomi in codice: Sapphire Sleet, Stardust Chollima, BlueNoroff, CageyChameleon e Alluring Pisces. Il filo che collega questi pacchetti compromessi sarebbe stato individuato proprio a partire dal monitoraggio della campagna più recente, quella che ha colpito il pacchetto axios. Il 31 marzo 2026, il Google Threat Intelligence Group (GTIG) ha infatti rilevato l’inserimento di una dipendenza malevola in due versioni della libreria, veicolo per l’installazione di una backdoor denominata WAVESHAPER.V2, un trojan di accesso remoto capace di operare su più sistemi operativi, di cifrare le comunicazioni con il centro di comando e controllo dell’attaccante e di cancellare le proprie tracce una volta eseguito. Ingegneria sociale con il supporto dell’intelligenza artificiale GTIG aveva attribuito l’attacco a un attore già noto, classificato con la sigla UNC1069 e riconosciuto per l’impiego di tecniche di ingegneria sociale mirate a instaurare un contatto diretto con le vittime, già osservate in una campagna condotta tra marzo e giugno 2024 6 con il supporto di strumenti di intelligenza artificiale. Analizzando l’infrastruttura di comando e controllo legata a quell’episodio, Amazon avrebbe individuato un dominio registrato nel 2025 che ha permesso di risalire a un malware inserito nel pacchetto typo-crypto, ritenuto un banco di prova per le campagne più estese condotte nel settembre 2025 su debug e chalk e poi, di nuovo, su axios. Ad accomunare gli episodi, secondo Amazon, non sarebbero soltanto gli indicatori tecnici, ma anche l’approccio organizzativo: in ciascun caso gli attaccanti avrebbero fatto leva su tecniche di ingegneria sociale per conquistare la fiducia degli amministratori dei pacchetti e ottenere così i privilegi necessari a pubblicarne versioni compromesse. CSIRT Italia alle organizzazioni italiane: verificare le dipendenze Il bollettino di CSIRT Italia sul caso axios porta la stessa data di quella prima rilevazione, il 31 marzo 2026. Segno che l’allerta era arrivata alle organizzazioni italiane in tempi rapidi. Questo, identificato dalla sigla BL01/260331/CSIRT-ITA, ricostruisce l’attacco con un buon livello di dettaglio. Secondo l’Agenzia, l’attaccante è riuscito a impossessarsi dell’account di uno dei manutentori del progetto e a pubblicare sul registro NPM due versioni modificate della libreria, aggirando i controlli automatizzati normalmente previsti dalla pipeline di rilascio. Le versioni compromesse richiamavano una dipendenza aggiuntiva che, una volta installata, scaricava ed eseguiva silenziosamente il trojan di accesso remoto adattato al sistema operativo della vittima. Il malware era progettato per cancellare le proprie tracce al termine dell’installazione, rendendo più difficile accorgersi dell’infezione con i normali strumenti di controllo. Il registro NPM ha rimosso le versioni compromesse una volta individuato il problema, e CSIRT Italia ha raccomandato alle organizzazioni italiane di verificare le proprie dipendenze, aggiornare alla versione sicura e, nei casi più seri, considerare compromessi i sistemi coinvolti. Relativo alla compromissione di debug e chalk, il secondo bollettino racconta invece una vicenda che parte da un errore umano. Un manutentore molto noto nell’ambiente NPM, identificato con lo pseudonimo Qix, è stato ingannato da un’email di phishing che imitava una comunicazione ufficiale del registro NPM e lo avvertiva di un presunto blocco imminente del proprio account. Convinto dalla comunicazione fraudolenta, il manutentore ha fornito le proprie credenziali e il codice di autenticazione a due fattori, permettendo così all’attaccante di prendere il controllo del suo profilo e di pubblicare versioni modificate di numerosi pacchetti ampiamenteutilizzati nello sviluppo di applicazioni JavaScript e Node.js. Anche in questo caso CSIRT Italia ha diffuso l’allerta alle organizzazioni nazionali, suggerendo strumenti per verificare la presenza delle versioni compromesse tra le proprie dipendenze. In entrambi i casi, il punto debole sfruttato dall’attaccante non è stato un errore nel codice dei pacchetti, ma la fiducia riposta in chi li gestisce. È un dettaglio che ricorre spesso nella sicurezza del software open source, un ecosistema costruito sul lavoro di poche persone da cui dipendono, a cascata, migliaia di aziende. Colpendo un numero ristretto di pacchetti molto diffusi, un gruppo può ottenere un accesso potenziale a migliaia di ambienti informatici in un colpo solo, un approccio più efficiente rispetto a colpire le organizzazioni una alla volta. Inoltre, secondo Amazon Threat Intelligence, le evoluzioni più recenti della tecnica rivelano una minaccia che non deriva più dai singoli pacchetti compromessi, i quali presi singolarmente non eseguono più codice malevolo una volta installati, ma dall’azione concatenata innescata dall’installazione di più pacchetti che agiscono in modo complementare sui sistemi infettati. Questa strategia, che evita ai singoli pacchetti di essere rilevati individualmente dai sistemi di sicurezza, sarebbe stata ulteriormente affinata adattando il codice ai diversi ambienti e sistemi operativi in cui viene eseguito, e ricorrendo a strumenti di intelligenza artificiale generativa per correggere le porzioni di codice più facilmente riconoscibili come sospette dagli antivirus e dai sistemi di rilevamento. Amazon cita anche un’altra tecnica emergente legata all’intelligenza artificiale, lo slopsquatting, che consiste nel registrare nomi di pacchetti inesistenti ma suggeriti per errore da un assistente di intelligenza artificiale, nella speranza che qualche sviluppatore li scarichi per sbaglio. Sul fronte della risposta, Amazon segnala di aver condiviso gli indicatori individuati con il database internazionale Open Source Vulnerabilities e di aver diffuso le informazioni attraverso il proprio servizio di rilevamento delle minacce. L’azienda ha inoltre ricordato la propria partecipazione, insieme alla Linux Foundation, all’iniziativa Akrites, nata per difendere il software open source critico dalle minacce abilitate dall’intelligenza artificiale. Il bollettino sulla compromissione di debug e chalk già citato porta la data del 9 settembre 2025 e precisa una finestra di esposizione risalente all’8 settembre, raccomandando alle organizzazioni di bloccare le versioni delle dipendenze tramite i file package-lock.json o yarn.lock. Nei mesi successivi, CSIRT Italia ha continuato a pubblicare allerte sulla stessa filiera di dipendenze: un attacco multistadio alla supply chain CI/CD legato all’attore TeamPCP e al malware CanisterWorm, la compromissione dei componenti Cloud Application Programming Model di SAP, la campagna worm Mini Shai-Hulud, che ha colpito oltre 160 pacchetti tra cui TanStack e gli SDK di Mistral AI, e la violazione del namespace @redhat-cloud-services di Red Hat, con 32 pacchetti e 96 versioni malevole. Il quadro che ne emerge è quello di una minaccia strutturale sull’ecosistema di dipendenze su cui si appoggia buona parte dello sviluppo software italiano, non di un episodio isolato. Questa esposizione arriva mentre il quadro normativo rende la sicurezza della catena di fornitura un obbligo esplicito. L’articolo 21 della direttiva NIS2 (UE 2022/2555) include la sicurezza della supply chain tra gli obblighi chiave per i soggetti essenziali e importanti, richiedendo la mappatura dei fornitori con accesso a dati o sistemi critici. Sul piano nazionale, la Determinazione ACN 127437/2026 ha introdotto l’obbligo di dichiarare i cosiddetti fornitori rilevanti sulla piattaforma dell’Agenzia. Sul piano operativo, le linee guida pubblicate da ACN articolano la gestione degli incidenti in cinque fasi, preparazione, rilevamento, risposta, ripristino e miglioramento, un modello di riferimento anche per allerte come quella lanciata da Amazon. Il Rapporto Clusit 2026 aggrava il quadro: 507 attacchi gravi registrati in Italia nel 2025, in aumento del 42% sull’anno precedente, a fronte di un record globale di 5.265 incidenti, il 48,7% in più rispetto al 2024. Il rapporto dedica un approfondimento alla sicurezza della filiera ICT, in cui la compromissione NPM di settembre 2025 legata al worm Shai-Hulud, un episodio distinto da quello di debug e chalk descritto in precedenza, sebbene avvenuto nello stesso mese, oltre 500 pacchetti coinvolti e furto di credenziali cloud di Microsoft, Amazon e Google, viene citata come uno degli episodi più rilevanti dell’anno. Accanto a questo si citano i dati di ENISA, secondo cui oltre il 10% degli incidenti censiti in Europa coinvolge soggetti terzi, e del Verizon DBIR, che colloca al 30% a livello globale la quota di violazioni legate alla catena di fornitura, un valore raddoppiato rispetto all’anno precedente. Nel complesso, l’attribuzione di Amazon aggiunge continuità a una minaccia che le autorità italiane osservano da quasi un anno, collocandola nell’orbita di un attore statuale nordcoreano orientato al profitto più che di gruppi criminali indipendenti. Per le organizzazioni soggette alla normativa NIS2, l’implicazione pratica è duplice: consolidare fin da subito pratiche di blocco delle versioni delle dipendenze e monitoraggio delle pipeline di sviluppo, e formalizzare, entro i termini previsti, la gestione del rischio di filiera secondo il modello indicato da ACN.
cybersecurity360.itAug 5, 2026extracted
OpenAI says its AI models hacked Hugging Face during testing
OpenAI says its AI models, including GPT‑5.6 Sol and a pre-release model, hacked into the Hugging Face artificial intelligence repository while being tested in a sandboxed testing environment. As the company explained, instead of focusing on finding a solution for the ExploitGym public AI cybersecurity benchmark on their own, the AI models went rogue and tried to cheat by stealing the test solutions by hacking Hugging Face after inferring that they could get the test solutions directly from its production database. In one of their attempts, the OpenAI agents chained zero-day vulnerabilities and used stolen credentials to find a remote code execution attack vector while trying to gain access to Hugging Face servers. "After investigating, we now know that this particular incident was driven by a combination of OpenAI models — including GPT‑5.6 Sol and an even more capable pre-release model, all with reduced cyber refusals for evaluation purposes — while being internally tested on a benchmark(opens in a new window) of cyber capabilities," OpenAI revealed on Tuesday. "To gain access, the models identified and exploited a zero-day vulnerability (which we've now responsibly disclosed to the vendor) in the package registry cache proxy. With this access, our models performed a series of privilege escalation and lateral movement actions in our research testing environment until the models reached a node with Internet access." While it didn't directly name OpenAI as the company behind the incident, Hugging Face confirmed its claims last week when it disclosed that its production infrastructure was breached by an autonomous AI agent system that gained access to credentials and internal datasets. According to Hugging Face's findings, the agent used a malicious dataset to exploit two code-execution vulnerabilities and run code on a processing worker to steal cloud and cluster credentials, making it possible to move laterally across several internal clusters. Once inside the company's systems, the AI models executed "many thousands of individual actions across a swarm of short-lived sandboxes, with self-migrating command-and-control staged on public services." Hugging Face also added that, while attempting to contain the breach and evict the AI agent, it found that its efforts were "blocked by the guardrails of the hosted models we first tried" while "the attacker was bound by no usage policy." "We've spent the past 24 hours working closely with the @OpenAI team (thanks!), and we strongly believe there was no malicious intent on their part," Clément Delangue, Hugging Face's founder and CEO, added yesterday. "It's quite mind-blowing that all of this happened autonomously!" After the incident, OpenAI says it disclosed a zero-day vulnerability in the internally hosted third-party software exploited by the AI agents and is working on adding stronger protections to prevent similar issues during future evaluations. Recently, the company also confirmed reports of GPT‑5.6 Sol deleting users' files, saying this may happen "extremely rarely" when the "model makes an honest mistake and mistakenly deletes $HOME instead" when run without sandboxing protections and full access mode is enabled. OpenAI also rotated code-signing certificates for its applications in May after two employees' devices were breached in the TanStack supply chain attack that impacted hundreds of npm and PyPI packages, while Hugging Face revoked some members' authentication secrets two years ago after hackers breached its Spaces platform. Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply. The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments. Get the report
bleepingcomputer.comJul 22, 2026extracted
GitHub Updates actions/checkout to Block Common Pwn Request Attack Patterns
GitHub is moving to strengthen software supply chain security by updating "actions/checkout" to block pwn request attacks that exploit the risky use of the "pull_request_target workflow" trigger to run malicious code with the workflow's full privileges. Effective June 18, 2026, the latest version of "actions/checkout," the official GitHub action for checking out a repository into the workflow's runner, refuses common pwn request patterns by default. The change is expected to be backported to all currently supported major versions on July 16, 2026. "Actions/checkout v7 refuses to fetch fork pull request code in pull_request_target and workflow_run workflows (the latter only when workflow_run.event is a pull_request* event)," it added. The refusal occurs when the pull request is from a fork, and any of the following criteria is met, unless workflow authors explicitly opt out of it by setting the "allow-unsafe-pr-checkout" flag to "true" in "actions/checkout" - repository: resolves to the fork pull request' repository ref: matches refs/pull/number/head or refs/pull/number/merge ref: resolves to a fork pull request's head or merge commit SHA The change is aimed at preventing the most common form of pwn requests in the Actions ecosystem. As a result, "actions/checkout" will fail for "pull_request_target events" from forks with insecure inputs. "Pull_request_target" is a workflow trigger that's automatically run without requiring manual approval when a pull request is opened or reopened, or when the head branch of the pull request is updated. It's important to note that the event runs in the context of the default branch of the base repository, potentially exposing secrets and a privileged GITHUB_TOKEN with both read and write permissions. "Running untrusted code on the pull_request_target trigger may lead to security vulnerabilities," GitHub notes in its documentation. "These vulnerabilities include cache poisoning and granting unintended access to write privileges or secrets." The danger arises when a "pull_request_target" is combined with "actions/checkout" to download and execute code submitted by an untrusted fork. Should a bad actor submit a pull request containing malicious scripts and the workflow checks out and runs the code, it can allow the attacker to steal the GITHUB_TOKEN and other secrets, leading to what's called a pwn request attack. "Workflows triggered by pull_request_target run with the base repository's GITHUB_TOKEN, secrets, and default-branch cache access," GitHub said. "Checking out the head of an unreviewed pull request from a fork inside one of these workflows typically lets attacker-controlled code execute with the workflow's full privileges." In recent months, a number of software chain attacks have weaponized this behavior. The most severe of them was the compromise of multiple packages associated with the Nx build system as part of a campaign codenamed s1ngularity, as well as the breach of PostHog, TanStack, and the popular Emacs package, "kubernetes-el/kubernetes-el." "Pull_request_target was designed for trusted automation around pull requests, such as labeling, commenting, or applying project metadata," Socket said. "But the checkout step controls which code actually lands in the runner workspace. If it pulls code from a forked pull request, the workflow can end up running attacker-controlled code with the base repository's privileges." That said, the Microsoft-owned subsidiary emphasized that pwn requests triggered via other event types besides pull_request_target (e.g., issue_comment) or through other means, such as git or the GitHub CLI, are out of scope of this change. "This change only blocks checkouts of the fork pull request head and merge commits," it added. "It does not block checkouts of other untrusted repositories. For example, setting repository: to an unrelated third-party repository is not blocked. Checking out and executing any untrusted code in a privileged event remains a pwn request risk that should be reviewed." To counter the risk posed by "pull_request_target," developers are advised to assess and use it only when necessary, switch to "pull_request" if the workflow does not require elevated permissions or access to secrets, restrict permissions granted to the workflows, and ensure user-controlled input does not result in execution of untrusted code. "The protection in this update only covers checkouts performed through actions/checkout," Socket said. "That makes this a guardrail, not a complete solution for Actions security. Workflows that run with secrets, write permissions, deployment permissions, or OIDC publishing access still need careful review."
thehackernews.comJun 23, 2026extracted
OpenAI Refocuses Cybersecurity Efforts on Patching Over Discovery
OpenAI on Monday expanded its Daybreak cybersecurity initiative with a new suite of tools and partnerships, framing the effort around a problem it says has become more pressing than vulnerability discovery itself: getting patches deployed. The company argues that AI models have fundamentally changed the security landscape by accelerating the rate at which vulnerabilities are found to the point where defenders are now overwhelmed by the volume of findings. To address the vulnerability remediation bottleneck, the company released an updated Codex Security plugin designed to further enhance security workflows. The tool integrates directly into Codex and can scan entire codebases, trace attack paths, construct threat models, validate findings, generate patches, and export results into existing vulnerability management pipelines via SARIF files and CodeQL queries. [ Read: AI and Cybersecurity – Everything You Wanted to Know, But Were Afraid to Ask ] Since a research preview launched in March, Codex Security has processed more than 30 million commits across over 30,000 repositories, with human reviewers confirming more than 70,000 fixes and an additional 500,000 findings resolved automatically. Alongside the plugin update, OpenAI launched the full version of GPT-5.5-Cyber, following an earlier release that focused on reducing unnecessary refusals. The updated model is described as OpenAI’s most capable offering for authorized security work, able to sustain analysis across large codebases, assess whether vulnerable code is actually reachable, and carry work through to patch development and testing. Access remains limited to verified defenders. On the CyberGym benchmark, which tests whether an agent can reproduce known vulnerabilities, the model scored 85.6%, compared to 81.8% for the standard GPT-5.5. OpenAI also unveiled Patch the Planet, an initiative founded with Trail of Bits and developed in collaboration with HackerOne and Calif. The program deploys expert security researchers equipped with Codex Security and OpenAI models to work alongside maintainers of widely used open source projects. Researchers handle validation, deduplication, and patch development before anything reaches maintainers, to reduce the burden on teams that are often small and under-resourced. More than 30 projects have signed on, with early participants including cURL, Go, Python, Sigstore, and pyca/cryptography. OpenAI also announced the Daybreak Cyber Partner Program, through which security vendors can integrate GPT-5.5 with Trusted Access for Cyber into their own products and services. Launch partners include many cybersecurity giants. The AI company plans to expand the program in the coming months and is also working directly with governments to help them boost their cyber defenses and protect critical infrastructure. Related: OpenAI Rolling Out ChatGPT Account Security Controls Related: 1Password Teams With OpenAI to Stop AI Coding Agents From Leaking Credentials Related: OpenAI Hit by TanStack Supply Chain Attack Related: OpenAI Rolls Out Advanced Security for ChatGPT Accounts
securityweek.comJun 23, 2026extracted
NPM 12 Will Change Script Execution Behavior to Prevent Supply Chain Attacks
In response to a recent wave of supply chain attacks targeting the NPM ecosystem, GitHub announced that scripts from dependencies will no longer be executed by default. Multiple major incidents that occurred over the past several months, mainly associated with TeamPCP and the Shai-Hulud self-replicating worm, have been abusing the default, automatic execution of scripts from dependencies during npm install to infect thousands of developers with malware. To better protect users, starting with NPM version 12, which is expected to arrive in July, script execution will be blocked by default, GitHub announced. “npm install will no longer execute preinstall, install, or postinstall scripts from dependencies unless they are explicitly allowed in your project,” the code-sharing platform explains. The change will also impact native node-gyp builds, such as packages that have a binding.gyp and no explicit install script, as well as prepare scripts from git, file, and link dependencies. The recent Shai-Hulud Miasma attacks relied on a weaponized binding.gyp file. To check how the upcoming change will impact their projects, developers can run npm approve-scripts –allow-scripts-pending, and allow the packages they trust and block the rest, to obtain an allowlist that is written to package.json. Once the JSON is committed, developers using NPM version 11.16.0 or above will receive warnings if their install routine executes scripts. Additionally, GitHub explains, Git dependencies (direct or transitive) will no longer be resolved at npm install, unless explicitly allowed. “This closes a code-execution path where a Git dependency’s .npmrc could override the Git executable, even with –ignore-scripts,” the platform notes. Similarly, dependencies from remote URLs will no longer be resolved in NPM version 12. This includes HTTPS tarballs (direct or transitive), but developers can allow them via the –allow-remote flag, which has been available since version 11.15.0. “Upgrade to NPM 11.16.0 or later, run your normal install, and review the warnings. Use npm approve-scripts –allow-scripts-pending to see which packages have scripts, approve the ones you trust, and commit the updated package.json. After that, only the scripts you approved keep running once you upgrade,” GitHub notes. Related: Over 5,500 GitHub Repositories Infected in ‘Megalodon’ Supply Chain Attack Related: Supply Chain Attack Hits 32 Red Hat NPM Packages Related: GitHub Confirms Hack Impacting 3,800 Internal Repositories Related: Grafana Says Codebase and Other Data Stolen via TanStack Supply Chain Attack
securityweek.comJun 13, 2026extracted
TeamPCP Supply Chain Campaign: Activity Through 2026-06-07, (Mon, Jun 8th)
This diary continues the Internet Storm Center's tracking of the TeamPCP supply chain campaign, first documented in the SANS white paper When the Security Scanner Became the Weapon and most recently in the handler diary Activity Through 2026-05-24. Since that update, the story moved into two new places: the United States government, which formally caught up to the campaign, and the wider population of attackers now wielding the Mini Shai-Hulud framework that TeamPCP open-sourced last month. Bottom line up front Two developments stand out since the last update. First, the federal response that prior coverage flagged as conspicuously absent arrived in a roughly 48-hour burst: on 2026-05-27 CISA added the campaign's primary tracking vulnerabilities to its Known Exploited Vulnerabilities catalog, and on 2026-05-28 it issued its first standalone advisory naming the Nx Console and GitHub repository compromises. Second, the leaked Mini Shai-Hulud framework produced its first significant in-the-wild npm wave: beginning 2026-06-01, a credential-stealing worm that Wiz named "Miasma" compromised dozens of @redhat-cloud-services packages, followed two days later by a "Phantom Gyp" variant that reached 57 more. Vendors trace the malware to the TeamPCP lineage but now explicitly caution that a copycat using the public toolkit cannot be ruled out. The affiliated extortion channels stayed frozen, so this period's activity was ecosystem-scale worming rather than named-victim extortion. How this developed The last update closed with two open questions: whether CISA would act on a campaign it had so far left out of the KEV catalog, and whether the framework TeamPCP published to GitHub would produce copycat attacks. Both resolved in the affirmative. CISA's KEV addition and standalone advisory closed the government-silence gap within roughly a day of each other. A week later, the Red Hat npm compromise demonstrated that the open-sourced code is now operational in other hands. The throughline is that the campaign has entered a phase where its tradecraft outlives any single operator: the same techniques, subverted build pipelines that emit validly signed artifacts and install-time credential theft, now arrive from attackers who may have no direct connection to TeamPCP at all. What changed, by theme CISA formally caught up On 2026-05-27, CISA added three vulnerabilities to the KEV catalog, including CVE-2026-45321 (the TanStack / Mini Shai-Hulud tracking identifier) and CVE-2026-48027 (the malicious code embedded in the Nx Console v18.95.0 build), both carrying a federal remediation due date of 2026-06-10, alongside CVE-2026-8398 (DAEMON Tools Lite). This resolved the multi-week KEV omission that earlier coverage tracked as an open question. The additions were corroborated by SC Media and Security Affairs. The next day, 2026-05-28, CISA published its first standalone advisory on the campaign, Supply Chain Compromises Impact Nx Console and GitHub Repositories. The advisory documents the poisoned Nx Console VS Code extension auto-distributed through the editor update mechanism, the exfiltration of approximately 3,800 GitHub-internal repositories, the assignment of CVE-2026-48027, and a separate "Megalodon" campaign that injected malicious GitHub Actions workflows to harvest CI/CD secrets and cloud credentials in public repositories. CISA urges forensic review of CI/CD logs and cloud audit trails and rotation of all CI/CD-accessible secrets. TechRadar Pro and Cybersecurity Dive carried the advisory to a wider audience. The leaked framework produced its first major wave: Red Hat npm On 2026-06-01, a supply chain attack that Wiz named "Miasma" compromised at least 32 packages (across roughly 90 or more versions) published under the @redhat-cloud-services npm scope, with the affected packages cumulatively averaging about 80,000 weekly downloads. The attacker used a compromised Red Hat employee GitHub account to inject malicious GitHub Actions workflows into RedHatInsights repositories, so the malicious releases carried valid SLSA provenance attestations: the pipeline genuinely ran Red Hat code that contained attacker-injected steps. The payload was a credential-stealing worm with a preinstall script and new cloud-identity collectors for GCP and Azure, and the obfuscated index.js grew from roughly 200 KB to about 4.29 MB. Corroborated by BleepingComputer and Cybersecurity Dive. Microsoft Threat Intelligence published its analysis on 2026-06-02, confirming the 32 packages across more than 90 versions and characterizing the payload as a lightly reskinned descendant of the Mini Shai-Hulud worm. Unit 42 folded the compromise into its running npm tracker the same day. Install-time tradecraft advanced within days: Phantom Gyp On 2026-06-03, a follow-on variant that StepSecurity named "Phantom Gyp" compromised 57 additional packages across 286 or more malicious versions in under two hours. Rather than modifying the package.json scripts field, the variant weaponized binding.gyp files to trigger node-gyp execution at install time, evading monitors that watch only package.json. The largest named victim was @vapi-ai/server-sdk, the official server SDK for the Vapi.ai voice platform, with over 408,000 monthly downloads. See TechTimes, corroborated by Wiz and Protos Labs. Attribution is now genuinely ambiguous Wiz, Microsoft, and Unit 42 all describe the Red Hat payload as Mini Shai-Hulud derived while explicitly warning that a copycat leveraging the public toolkit cannot be excluded. Wiz states the similarities should be treated as evidence of TTP overlap rather than definitive attribution to TeamPCP. This is the practical materialization of the copycat risk flagged when TeamPCP open-sourced its framework: the defender takeaway is unchanged, but single-incident attribution to the operators is now weaker than it was during the operator-run phase earlier in the campaign. Signed provenance still does not save you As with the earlier TanStack incident, the Red Hat packages shipped valid provenance attestations because the build pipeline itself was subverted from within. Trade reporting this period foregrounded the point that signed attestations cannot block a pipeline hijack. Build-provenance attestation confirms that an artifact came from a given pipeline; it does not confirm that the pipeline was free of attacker-injected steps. Monetization stayed frozen The affiliated extortion channels posted nothing in this period. Per direct checks of ransomware.live, the Vect leak site remained at 25 victims with its most recent listing dated 2026-04-15, and CipherForce remained at 6 victims with last activity dated 2026-02-23. The contrast from earlier in the campaign holds: the supply chain operation draws government and vendor attention while the affiliate-ransomware channel remains dormant. What defenders should do now Treat the 2026-06-10 CISA remediation deadline for CVE-2026-45321 and CVE-2026-48027 as binding. Confirm no exposed Nx Console v18.95.0 install remains and that TanStack-related exposure is remediated. Rotate all CI/CD-accessible secrets and cloud credentials, and review CI/CD logs and cloud audit trails, per the CISA advisory. Assume any token reachable from a build pipeline is potentially exposed. Inventory use of the affected scopes (@redhat-cloud-services, and the earlier @antv) and packages such as @vapi-ai/server-sdk. Pin to known-good versions and rebuild from a trusted state. Monitor install-time execution beyond the package.json scripts field. Include binding.gyp and node-gyp hooks in detection, since Phantom Gyp moved specifically to evade scripts-only monitors. Consider running install with scripts disabled in CI where feasible. Do not rely on SLSA provenance attestations alone. Valid provenance does not defend against a compromised build environment; pair it with build-environment integrity controls and behavioral monitoring of install steps. Enforce two-factor authentication on registry maintainer accounts, scope publish tokens narrowly, and alert on anomalous workflow changes in source repositories. Watch items A formal Red Hat post-incident statement and a definitive package and version inventory, including confirmation of the compromised employee-account vector and any downstream notification to consumers. Convergence or divergence on attribution. Watch for whether Mandiant or the Google Threat Intelligence Group issues a dedicated note either claiming the Miasma and Phantom Gyp waves as UNC6780 or designating a separate copycat cluster. Further binding.gyp and node-gyp install-time abuse beyond the @redhat-cloud-services scope, and whether registry-side or scanner-side detection adapts to install hooks outside package.json. The CISA KEV remediation deadline of 2026-06-10. Watch for deadline-driven follow-on guidance, KEV additions covering the Red Hat activity, or disclosure of federal-agency exposure as the date passes. Resumption of named-victim extortion. Watch the Vect and CipherForce leak sites for any end to their multi-month dormancy, which would signal a shift back from ecosystem worming to monetization.
isc.sans.eduJun 8, 2026extracted
Red Hat removes tainted packages after software pipeline compromise
Red Hat removes tainted packages after software pipeline compromise Red Hat pulled dozens of packages from its software distribution pipeline on Monday after attackers used a compromised GitHub account to distribute credential-stealing malware to developers. According to the company’s own preliminary analysis, a compromised GitHub account was used to push the malicious code out to customers, hitting 32 packages downloaded roughly 117,000 times a week. Red Hat said it had since removed the affected packages and that “based on current findings, no actions from customers are required.” The attack used a variant of the Mini Shai-Hulud self-propagating worm whose complete source code was published online May 12 by a cybercriminal group tracked as TeamPCP. As cybersecurity company Tenable noted, the criminals “simultaneously announced a $1,000 contest on BreachForums for the largest supply chain attack using the code.” Whether Monday's attack was carried out by TeamPCP itself or a separate actor using its published code could not be immediately determined, researchers said. Palo Alto Networks' Unit 42 warned that the open-sourcing of the worm's code had already spawned copycat activity, making definitive attribution harder, and that Mini Shai-Hulud “is no longer scoped to TeamPCP.” The attack's malware, which its authors named Miasma, differed from the TeamPCP original only cosmetically, with references to the science-fiction series Dune replaced by Greek mythology while the underlying credential-stealing functionality remained intact. Monday's attack is the latest in a cascading series of supply chain intrusions stretching back to September 2025 — when the original Shai-Hulud worm prompted a CISA advisory — that have struck some of the world's most widely used developer tools. Recent incidents have included an attack in March on LiteLLM, which allowed the cybercriminals to breach several organizations including AI recruiting company Mercor. The attack on LiteLLM was followed by a separate wave of compromises attributed to North Korean hackers targeting the axios JavaScript library. That campaign prompted Mandiant chief technology officer Charles Carmakal to warn “the secrets stolen over the past two weeks will enable more software supply chain attacks, software-as-a-service environment compromises, ransomware and extortion events, and crypto heists over the next several days, weeks, and months.” In May, GitHub confirmed it had been breached by TeamPCP after an employee's device was compromised via a malicious Visual Studio Code extension, with the group demanding $50,000 for stolen source code and threatening to leak it for free if no buyer came forward. OpenAI had also warned that two of its employee devices had been compromised in the same wave, following a supply chain attack on the open-source library TanStack. Speaking at the time of the LiteLLM compromise, Adam Reynolds, senior security researcher at Sonatype, warned that because “the malware targets such a broad range of credentials … this creates the potential for second- and third-order effects that may ripple outward over time, leading to further breaches, service disruptions, or misuse of sensitive data well beyond the initial point of compromise.” Alexander Martin is the UK Editor for Recorded Future News. He was previously a technology reporter for Sky News and a fellow at the European Cyber Conflict Research Initiative, now Virtual Routes. He can be reached securely using Signal on: AlexanderMartin.79
therecord.mediaJun 2, 2026extracted
Supply Chain Attack Hits 32 Red Hat NPM Packages
On Monday, hackers hit Red Hat’s NPM repository in a new supply chain attack, publishing malicious versions of 32 packages to distribute a credential-stealing worm. Within a 72-second window, the threat actor published poisoned iterations across all 32 packages, likely using automation, ReversingLabs notes. The affected packages cover the entire Red Hat Hybrid Cloud Console JavaScript ecosystem and have nearly 10 million collective downloads. According to Aikido, the attackers likely compromised the CI/CD pipeline and used the GitHub Actions OIDC to publish the malicious package versions. ReversingLabs believes that the hackers had access to @redhat-cloud-services NPM scope credentials. The packages contained a preinstall hook that led to the execution of malware during NPM install, before the package is imported or used. The payload contains the string “Miasma: The Spreading Blight” and appears to be a variant of the Mini Shai-Hulud worm that TeamPCP used in several attacks against the open source software community over the past months. The hacking group released the malware’s source code last month, inviting miscreants to use it in supply chain attacks as part of a challenge. According to Ox Security, the threat actor behind the Red Hat compromise infected a repository on May 29, likely to test its capabilities. The malware was designed to harvest “GitHub Actions secrets, npm tokens, cloud credentials, Kubernetes and Vault material, SSH keys, Git credentials, and other sensitive files,” Socket reports. Like Mini Shai-Hulud, it exfiltrates the collected data to an attacker-controlled server and uses a GitHub-based fallback mechanism, publishing the stolen information to newly created public repositories. While the full scope of infection is yet unknown, Ox identified 210 repositories containing stolen credentials, suggesting that at least as many developers were infected after downloading and installing the malicious Red Hat package versions. The malware was also observed attempting to use stolen GitHub tokens to enumerate repositories. It contains a GitHub Actions workflow modification logic and can write malicious index.js payloads into repositories/actions. Red Hat maintainers have published clean versions of all 32 affected packages, and the malicious iterations have been removed from NPM. Users are advised to update to a clean release as soon as possible. Anyone who installed a malicious version should consider their system and build environment compromised and should immediately rotate credentials, tokens, API keys, and other sensitive information the malware might have accessed. Developers are also advised to check transitive dependencies, as the packages are widely used as indirect libraries, and to monitor their environments for anomalous outbound connections. Related: ‘SymJack’ Attack Turns AI Coding Agents Into Supply Chain Attack Delivery Systems Related: Over 5,500 GitHub Repositories Infected in ‘Megalodon’ Supply Chain Attack Related: Grafana Says Codebase and Other Data Stolen via TanStack Supply Chain Attack
securityweek.comJun 2, 2026extracted
Red Hat npm packages compromised to steal developer credentials
More than 30 npm packages under Red Hat's '@redhat-cloud-services' namespace were compromised in a supply-chain attack that distributed a new variant of the Shai-Hulud credential-stealing malware, dubbed "Miasma." The incident was discovered by security firms Aikido and OX Security, which found dozens of package versions backdoored with malware designed to steal developer credentials, cloud secrets, SSH keys, CI/CD tokens, and other sensitive information. According to Aikido, the compromised packages receive roughly 117,000 weekly downloads. In a statement shared with BleepingComputer, Red Hat said it removed the affected packages after becoming aware of the incident and that the compromise was limited to internal development tooling. "Red Hat is aware of security reports regarding certain npm packages within our development tooling ecosystem. We immediately initiated an investigation and removed the packages from the npm registry," Red Hat told BleepingComputer. "The packages are strictly limited to internal development, and the malicious code was never published for customer consumption via the console.redhat.com system. While our investigation is ongoing, we have not identified any impact to customer or partner environments or Red Hat production systems." The company says it is continuing to investigate the incident, but did not answer our questions about how the account was compromised. Red Hat packages backdoored through GitHub compromise According to Aikido, the attackers allegedly compromised a Red Hat employee's GitHub account and used it to push malicious commits directly to multiple repositories. Those commits added a GitHub Actions workflow and a script that abused npm's publishing mechanism to release backdoored packages. "When the workflow runs, it installs Bun and executes _index.js, passing it a list of target packages via the OIDC_PACKAGES environment variable," explains Aikido. "The script uses the id-token: write permission to request a short-lived OIDC token from GitHub, then uses that token to authenticate directly with npm's trusted publishing endpoint and publish backdoored versions of every package in the list." These compromised packages contained a malicious 'preinstall script that automatically executed a heavily obfuscated malicious index.js file when developers installed the packages. "scripts": { "preinstall": "node index.js" } According to Aikido, the 'index.js' payload was approximately 4.2 MB in size, and is used to steal GitHub Actions secrets, AWS credentials, Google Cloud credentials, Azure service principal credentials, HashiCorp Vault tokens, Kubernetes service account tokens, npm and PyPI publishing tokens, SSH keys, Docker credentials, GPG keys, and .env files. Aikido says 32 packages and 96 package versions were affected by the compromise, including numerous client libraries maintained under the @redhat-cloud-services namespace. Organizations that installed any affected versions are advised to rotate all credentials, secrets, and tokens utilized by code on the infected device immediately. Miasma appears to be a new Shai-Hulud variant Over the past couple of months, there have been numerous supply chain attacks utilizing a Shai-Hulud malware to steal credentials and spread to other projects. These attacks have impacted well-known projects, including Bitwarden, SAP, Mistral, TanStack, OpenAI, and GitHub. In May, the TeamPCP threat group publicly released the source code for its Mini Shai-Hulud malware framework, making the malware available to other threat actors. Researchers say the malware used in the Red Hat compromise shares many similarities with Mini Shai-Hulud, but now utilizes the "Miasma: The Spreading Blight" string as comments in compromised GitHub repositories. While the malware resembles TeamPCP's Mini Shai-Hulud, it is unclear whether the campaign was conducted by that threat actor or by another threat actor that modified the leaked malware source code. OX Security says the malware retains the same credential-stealing functionality as Mini Shai-Hulud but adds additional obfuscation layers, multi-stage payload delivery mechanisms, and enhanced data theft and credential-harvesting features. At the time of this writing, 309 GitHub repositories have been compromised by the Miasma malware campaign. Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply. The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments. Get the report
bleepingcomputer.comJun 1, 2026extracted
Miasma Supply Chain Attack Compromises Red Hat npm Packages with Credential-Stealing Worm
A new Mini Shai-Hulud supply chain attack campaign, codenamed Miasma, has compromised @redhat-cloud-services packages to steal credentials and secrets from developer machines and deliver a self-propagating worm. "This is effectively a Mini Shai-Hulud campaign: it uses the same core tactics of install-time execution, credential harvesting, CI/CD targeting, encrypted exfiltration, and potential downstream propagation," Socket said. Exactly who is behind the attack activity is presently unknown given that TeamPCP (aka Replicating Marauder, TGR-CRI-1135, and UNC6780), an infamous cybercrime group, has open-sourced the attack tools linked to the Shai-Hulud worm, opening the door for other threat actors to pull off similar attacks and making definitive attribution harder. The names of some of the affected packages are listed below - @redhat-cloud-services/vulnerabilities-client @redhat-cloud-services/tsc-transform-imports @redhat-cloud-services/topological-inventory-client @redhat-cloud-services/sources-client @redhat-cloud-services/rule-components @redhat-cloud-services/remediations-client @redhat-cloud-services/rbac-client Per analyses from Aikido Security, JFrog, Microsoft, OX Security, ReversingLabs, SafeDep, StepSecurity, and Wiz, the npm packages contain an obfuscated preinstall hook that's designed to collect GitHub Actions secrets, npm tokens, cloud credentials, Kubernetes and Vault material, SSH keys, Git credentials, and other sensitive files. Like observed in prior Mini Shai-Hulud waves, the malware also contains encrypted exfiltration logic that transmits the data to "api.anthropic[.]com:443/v1/api" and uses GitHub as a fallback mechanism. This indicates attempts made by the attacker to both steal credentials and weaponize them to further poison the software supply chain. "It commits the encrypted result envelope through the GitHub API," Socket said. "The commit message can include: IfYouInvalidateThisTokenItWillNukeTheComputerOfTheOwner: ." Another noteworthy step carried out by the malware is to avoid execution on Russian-language systems, a pattern also observed in the GlassWorm supply chain campaigns. "For npm, the payload calls the OIDC token exchange and whoami endpoints, repackages a tarball (updateTarball, package-updated.tgz), and signs the artifact through Sigstore," SafeDep said. "Stolen credentials exfiltrate to attacker-created public GitHub repositories, each carrying the description Miasma: The Spreading Blight." The first commit containing the "Miasma: The Spreading Blight" string appeared on May 29, 2026, OX Security noted, indicating that either this variant was active since then, or the threat actor started testing around that time. As for GitHub, the malware enumerates repositories the token can write to, reads action.yml/action.yaml via GraphQL, and commits a workflow through the createCommitOnBranch mutation so that the commit appears as a verified, signed change. Other actions carried out by the malware are listed below - Attempt privilege escalation by launching a container that bind-mounts the host /etc/sudoers.d and grants the CI runner passwordless sudo Check for endpoint protection from CrowdStrike, SentinelOne, Carbon Black, and StepSecurity Harden-Runner before commencing the malicious actions Establish persistence by injecting a SessionStart hook to Anthropic Claude Code and a tasks.json with "runOn": "folderOpen" for Microsoft Visual Studio Code projects so that the malware is automatically launched during every session "One of the main changes in this new variant is the addition of new data collectors focused on cloud identities," Wiz researchers said. "Specifically, collectors for GCP and Azure identities were added that collect all identities the infected machine has access to. While previous versions of the malware primarily focused on extracting secrets from these environments, this variant suggests an increased attacker focus on gaining and leveraging access to the cloud itself. Unlike previous versions, the malware has also been found to generate a uniquely encrypted payload for each infection, thereby making detection and version tracking significantly more challenging. Evidence suggests that the compromise of a Red Hat employee's GitHub account was the patient zero that was used to inject the payload into these packages. The compromised account is said to have pushed malicious orphan commits to two RedHatInsights repositories, bypassing code review. It's recommended to isolate hosts that have installed the affected versions, remove the malicious versions, rotate exposed credentials, review for any signs of suspicious GitHub or npm activity, audit the environment for persistence artifacts that involve changes to configuration files (~/.claude/settings.json, .vscode/tasks.json, .github/workflows/codeql.yml, .github/setup.js), and enforce strong access controls. "Because the malware includes background execution and potential developer-tool persistence mechanisms, uninstalling the npm package or deleting node_modules should not be considered sufficient cleanup," Socket explained. "For CI/CD systems, suspend affected workflow runs, invalidate build artifacts produced during the exposure window, and review whether any release, container image, npm package, or deployment artifact was created after the malicious package was installed." Update Dark web monitoring and threat intelligence firm Whiteintel said it "detected a Red Hat GitHub credential and session cookie in infostealer logs on April 13 and May 15, 2026," raising the possibility that this information may have been used to break into the employee's account. The development is the latest in a number of supply chain attacks that have targeted the open-source ecosystems over the past couple of months. These attacks have impacted well-known projects, including Aqua Trivy, Checkmarx KICS, Bitwarden, SAP, TanStack, and GitHub, and Nx Console. Last month, a separate campaign codenamed Megalodon was found to have injected malicious GitHub Action workflows to harvest CI/CD secrets, cloud credentials, and tokens, impacting both development and deployment pipelines in public GitHub repositories. "These recent incidents, including the GitHub compromise via a malicious Nx Console Visual Studio Code (VS Code) extension and the 'Megalodon' supply chain intrusion campaign, demonstrate how cyber threat actors are abusing tools and processes that support enterprise, cloud, and DevOps environments - specifically CI/CD pipelines, code extensions and workflows," the U.S. Cybersecurity and Infrastructure Security Agency (CISA) said.
thehackernews.comJun 1, 2026extracted
In Other News: Trump Mobile Data Breach, FIFA World Cup Phishing, CISA Responds to Supply Chain Attacks
SecurityWeek’s weekly cybersecurity news roundup offers a concise overview of important developments that may not receive full standalone coverage but remain relevant to the broader threat landscape. This curated summary highlights key stories across vulnerability disclosures, emerging attack methods, policy updates, industry reports, and other noteworthy events to help readers maintain a well-rounded awareness of the evolving cybersecurity environment. Here are this week’s highlights: Trump Mobile data breach Phone provider Trump Mobile has confirmed that customers’ names, addresses, email addresses, phone numbers, and other data was exposed to the internet. The company reportedly said a third-party platform provider was responsible for the exposure. Russian hackers’ deep reach in Treasury emails Documents presented in a Freedom of Information Act lawsuit filed by Bloomberg News against the US government show that the Russian state-sponsored APT responsible for the 2019-2020 SolarWinds supply chain attack had deep access to Treasury emails. The hackers reportedly focused on only eight email accounts linked to 300 other email addresses. The Treasury had roughly 94,000 people at the time. VS Code Remote SSH extension vulnerability A remote code execution (RCE) vulnerability in the Visual Studio Code (VS Code) Remote‑SSH extension could allow attackers to pivot to remote systems, security researcher Suman Kumar Chakraborty warns. The issue exists because, upon initiating a Remote SSH connection, the extension writes a bootstrap shell script to the Temp directory. An attacker with access to the system can modify the script before it is transmitted and executed on the remote server, to deploy a reverse shell. UK Visa Portal exposes over 100,000 documents Immigration portal UK Visa Portal publicly exposed over 100,000 documents of people who applied for a UK visa, TechCrunch reports. Not affiliated with the UK government, the website requires applicants to upload selfies and passports, and to pay a fee for obtaining visas. The exposed files were stored in an AWS S3 bucket and were secured earlier this week. LinkedIn phishing campaign abuses Adobe Target Phishers are posing as LinkedIn in a new phishing campaign posing as a business inquiry. The emails contain fake contract attachments masquerading as PDFs. In fact, they are HTML files directing victims to the Adobe Target A/B testing platform. The attackers are abusing Adobe Target to track users and serve them fake login pages to steal their credentials before redirecting them to LinkedIn. 2026 FIFA World Cup in attackers’ crosshairs Just as the 2026 FIFA World Cup is about to kick off, Group-IB has discovered over 4,300 fraudulent domains impersonating FIFA, including a sophisticated phishing campaign run by Chinses-speaking hacking group Ghost Stadium. The threat actor has set up over 300 domains, including a pixel-perfect clone of the legitimate FIFA site. The phishers could cause hundreds of millions of dollars in losses. Veeam, Notepad++, Roundcube patches Veeam this week resolved two high-severity vulnerabilities in its Backup & Replication product, warning they could lead to privilege escalation and arbitrary file writes. Notepad++ patched three security issues, including two leading to arbitrary code execution. The latest Roudcube security updates fix eight flaws, including unauthenticated SQL injection and arbitrary file delete bugs. CISA responds to recent supply chain attacks The US cybersecurity agency CISA has expanded its KEV catalog with three vulnerabilities describing recent software supply chain attacks. These include Daemon Tools Lite, TanStack, and Nx Console (which led to the 3.800 internal GitHub repositories hack). CISA also issued an alert on the Megalodon and Nx Console attacks, urging organizations to hunt for and remediate potential compromises. NPM invalidated granular access tokens in response to these attacks. Supply chain attack hits 176 NPM packages Sonatype warns of a supply chain attack involving 176 malicious NPM packages containing postinstall scripts designed to install information-stealing malware on the victims’ computers. The malware harvests and exfiltrates credentials, system and directory information, environment variables, CI/CD secrets, and other tokens and sensitive information. All malicious packages have the version number 99.99.99. Contractor jailed for hacking former employer Maxwell Schultz, 36, of Columbus, Ohio, was sentenced to 24 months in federal prison for hacking into his employer’s network after his contract was terminated in May 2021. Impersonating another contractor, he obtained login credentials, accessed the former employer’s systems, and executed a script that reset roughly 2,500 passwords, locking out employees and contractors and causing more than $862,000 in losses. Schultz pleaded guilty in November 2025.
securityweek.comMay 29, 2026extracted
Lithuania Suspects Foreign Involvement in Data Leak of Over 600,000 National Register Entries
Lithuanian authorities are on high alert after a massive data leak involving more than 600,000 entries from national data registers, which is believed to have been executed by another country. The Lithuanian general prosecutor’s office on Friday announced the leak was primarily from registers of real estate and legal entities accessed by using login credentials of institutions authorized to receive the data. The head of the State Enterprise Centre of Registers, Adrijus Jusas, resigned Monday following the leak. The authorities immediately implemented additional cybersecurity measures, including blocking the accounts of suspected data users and restricting access with a requirement to update credentials, the prosecutors said. The prosecutor’s office said a foreign country is suspected of involvement, although authorities did not specified which nation. Lithuanians are especially cautious given that the country, with a population of 2.9 million, is one of the main targets of Russia’s hybrid war against Europe, which includes sabotage, arson attacks and vandalism, as well as influence operations. Opposition politician Laurynas Kasčiūnas wrote on social media Sunday that the data theft is suspected to be a Russian intelligence operation, although he offered no evidence for the claim. The politician warned that addresses of intelligence officers, military personnel, diplomats or politicians may have been accessed, which could potentially allow the perpetrators to spy on or exercise pressure against the targets. Related: Oncology Institute Discloses Data Breach Related: DocketWise Data Breach Impacts 143,000 Related: Grafana Says Codebase and Other Data Stolen via TanStack Supply Chain Attack
securityweek.comMay 26, 2026extracted
⚡ Weekly Recap: Linux Flaws, Defender 0-Days, Router Botnets, and Supply Chain Chaos
Monday recap. Same mess, new week. A sketchy dev tool got people pwned, old bugs came back from the dead, and security products somehow needed protecting from themselves. A bunch of companies spent the week checking old boxes and forgotten servers they should've patched years ago. Good times. Phishing crews are getting smarter too - less obvious scam junk, more targeted stuff that actually looks real. Meanwhile, botnets are grabbing anything exposed to the internet like it's free candy. The Internet's still a dumpster fire. Let’s get into it. ⚡ Threat of the Week GitHub Breached via Nx Console VS Code Extension—GitHub officially confirmed that the breach of its internal repositories was the result of a compromise of an employee device involving a poisoned version of the Nx Console Microsoft Visual Studio Code (VS Code) extension. The attack is said to have allowed the threat actor, a cybercriminal group known as TeamPCP, to exfiltrate about 3,800 repositories. GitHub said it has taken steps to contain the incident and rotated critical secrets, adding it's continuing to monitor the situation for follow-on activity. The Nx team revealed that the extension, nrwl.angular-console, was breached after one of its developers' systems was hacked in the wake of the recent TanStack supply chain attack. Other companies that were impacted by the TanStack compromise include OpenAI, Mistral AI, and Grafana Labs. Grafana Labs was also the target of an extortion attempt, but the company said it refused to pay the hackers who had threatened to release the company's codebase. The incidents are just some examples of the long tail of downstream victims emerging from the Mini Shai-Hulud campaign. This, coupled with TeamPCP's public release of the Shai-Hulud code, marks a significant evolution in software supply chain threats, as it gives attackers a ready-made blueprint for fleshing out similar worms targeting open-source repositories and developer environments. 80% of Security Teams Know OAuth Security Is Urgent. Half Are Doing Nothing Manual OAuth reviews don’t scale, and the rapid adoption of AI agents is making it worse. Material’s OAuth Threat Remediation Agent continuously monitors every connection across your cloud workspace, classifies risk, and automatically kills malicious ones before they become incidents. Close the Gap Today ➝ 🔔 Top News Microsoft Took Down Fox Tempest—Microsoft has cracked down on Fox Tempest, a cyber threat actor that fueled Rhysida ransomware attacks and other infections involving Oyster, Lumma Stealer, and Vidar. The group operates upstream in the malware and ransomware supply chain, acting as an enabler and providing tools for other threat actors to carry out attacks. This included a fraudulent code-signing service that let cybercriminals deploy malware "through the front door" without being detected. While bad actors have been known to resell code-signing certificates for at least a decade, Fox Tempest's operation stood out because it provided a scalable service for extortion, phishing, SEO poisoning, or malware-laced advertising. 9-Year-Old Linux Kernel Flaw Enables Root Command Execution—A new vulnerability disclosed in the Linux kernel remained undetected for nine years. The vulnerability, tracked as CVE-2026-46333 (CVSS score: 5.5), is a case of improper privilege management that could permit an unprivileged local user to disclose sensitive files and execute arbitrary commands as root on default installations of several major distributions like Debian, Fedora, and Ubuntu. The issue was introduced in November 2016. Microsoft Warned of Two Actively Exploited Defender Vulnerabilities—Microsoft has disclosed that a privilege escalation and a denial-of-service flaw in Defender have come under active exploitation in the wild. While CVE-2026-41091 could allow an attacker to gain SYSTEM privileges, CVE-2026-45498 relates to a case of denial-of-service. Although Microsoft has not formally confirmed, the vulnerability descriptions for CVE-2026-41091 and CVE-2026-45498 overlap with those of RedSun and UnDefend, two Defender zero-days that were disclosed by Chaotic Eclipse (aka Nightmare-Eclipse) last month. Newly Disclosed Drupal Core Flaw Under Attack—A critical security flaw impacting Drupal Core has come under active exploitation within days of public disclosure. The vulnerability in question is CVE-2026-9082 (CVSS score: 6.5), an SQL injection vulnerability affecting all supported versions of Drupal Core. Drupal acknowledged that "exploit attempts are now being detected in the wild." Thales-owned Imperva said it has observed over 15,000 attack attempts targeting almost 6,000 individual sites across 65 countries. Claude Mythos AI Finds 10K High-Severity Flaws in Popular Software—Anthropic revealed that Project Glasswing has helped uncover more than 10,000 high- or critical-severity vulnerabilities across some of the most "systemically" important software across the world since the cybersecurity initiative went live last month. Of these vulnerabilities, 6,202 have been classified as high- or critical-severity flaws impacting more than 1,000 open-source projects. Subsequent analysis of these vulnerability candidates has identified that 1,726 are valid true positives. As many as 1,094 flaws are assessed to be either high- or critical-severity. In total, these efforts have led to 97 findings being patched upstream and 88 advisories being issued. Cisco Patched CVSS 10.0 Secure Workload Flaw—Cisco rolled out updates for a maximum-severity security flaw impacting Secure Workload that could allow an unauthenticated, remote attacker to access sensitive data. Tracked as CVE-2026-20223 (CVSS score: 10.0), the vulnerability arises from insufficient validation and authentication when accessing REST API endpoints. "An attacker could exploit this vulnerability if they are able to send a crafted API request to an affected endpoint," Cisco said. "A successful exploit could allow the attacker to read sensitive information and make configuration changes across tenant boundaries with the privileges of the Site Admin user." Microsoft Released Mitigations for YellowKey—Microsoft released a mitigation for a BitLocker bypass vulnerability named YellowKey following its public disclosure last week. The zero-day flaw, now tracked as CVE-2026-45585, carries a CVSS score of 6.8. It has been described as a BitLocker security feature bypass. The issue impacts Windows 11 version 26H1 for x64-based Systems, Windows 11 Version 24H2 for x64-based Systems, Windows 11 Version 25H2 for x64-based Systems, Windows Server 2025, and Windows Server 2025 (Server Core installation). Microsoft noted that successful exploitation could permit an attacker with physical access to sidestep the BitLocker Device Encryption feature on the system storage device and gain access to encrypted data. 🔥 Trending CVEs Bugs drop weekly, and the gap between a patch and an exploit is shrinking fast. These are the heavy hitters for the week: high-severity, widely used, or already being poked at in the wild. Check the list, patch what you have, and hit the ones marked urgent first — CVE-2026-48172 (LiteSpeed User-End cPanel Plugin), CVE-2026-34926 (Trend Micro Apex One), CVE-2026-20223 (Cisco Secure Workload), CVE-2026-41091, CVE-2026-45498, CVE-2026-45584 (Microsoft Defender), CVE-2026-46333 (Linux Kernel), CVE-2026-9082 (Drupal Core), CVE-2026-45585 (Microsoft Windows BitLocker), CVE-2026-2743 (SEPPMail), CVE-2026-7301, CVE-2026-7302, CVE-2026-7304 (SGLang), CVE-2026-29205 (cPanel), CVE-2026-8178 (Amazon Redshift JDBC driver), CVE-2026-8053 (MongoDB), CVE-2026-45829 aka ChromaToast (ChromaDB), CVE-2026-8153 (Universal Robots PolyScope 5), CVE-2026-3102 (ExifTool), CVE-2026-9110, CVE-2026-9111, from CVE-2026-8511 through CVE-2026-8522 (Google Chrome), CVE-2026-45434 (Apache OFBiz), CVE-2026-33000, CVE-2026-34908, CVE-2026-34909, CVE-2026-34910, CVE-2026-34911 (UniFi OS), CVE-2026-45401 (Open WebUI), CVE-2026-9256, CVE‑2026‑8711 (F5 NGINX Plus and NGINX Open Source), CVE-2026-20239 (Splunk Enterprise and Splunk Cloud Platform), CVE-2026-46376 (FreePBX), CVE‑2026‑6637 (PostgreSQL), and CVE-2026-35194 (Apache Flink). 🎥 Cybersecurity Webinars Learn How Attackers Use AI to Supercharge DDoS Efficiency (and How to Stop It) → Adversaries are weaponizing AI to exploit network blind spots, auto-generate evasion scripts, and bypass traditional defenses with surgical precision. This webinar bridges the gap between AI-driven exploitation and cloud resilience, offering data-driven insights into how attackers maximize DDoS success rates. Join us to move beyond theory, leverage AI for non-disruptive security testing (CTEM), and transition your team from reactive mitigation to automated, continuous resilience. Beyond the Zero-Day: Hunting for Threats That Don't Need an Exploit → Zero-day exploits are no longer the ultimate metric of cyber risk. Today, sophisticated adversaries bypass traditional defenses entirely by leveraging identity flaws, living-off-the-land techniques, and AI automation that don't rely on unpatched software. This session moves beyond the zero-day obsession to expose how attackers operationalize modern post-compromise tactics—and how security teams can pivot from reactive patching to proactive, behavioral threat hunting. 📰 Around the Cyber World Vulnerability Exploitation Overtakes Compromised Credentials in a Long Time —Vulnerability exploitation has overtaken compromised credentials for the first time in nearly two decades as the most common initial access vector for data breaches, per Verizon. Nearly a third (31%) of data breaches over the past year started with vulnerability exploitation, up from 20% in 2024. Credential abuse declined from 22% to 13%. What's more, only 26% of critical vulnerabilities listed in the U.S. Cybersecurity Infrastructure and Security Agency Known Exploited Vulnerabilities (KEV) catalog were fully remediated by organizations in 2025, a drop from 38% the previous year. "The median time for full resolution went up to 43 days, almost two weeks more than the previous year’s 32 days," the report said. "In the median case, organizations had 50% more critical vulnerabilities to patch in this year’s reporting dataset compared to the previous year." Ransomware accounted for 48% of all breaches last year, up from 44% in 2024. But in a positive development, ransom payments have continued to decline, with the median payment sliding from $150,000 in 2024 to almost $140,000. Attackers Go After India's Education Ecosystem —Threat actors are abusing student data within India's education ecosystem, spanning educational institutions, third-party vendors, and online services, for phishing, impersonation, social engineering, and financially motivated fraud operations. "Attackers commonly leverage exposed or misused student information to create highly convincing scams related to admissions, scholarships, internships, fee payments, and academic services," CYFIRMA said. "In several instances, threat actors exploited trusted educational branding, fraudulent portals, and insider access to obtain credentials, financial information, or direct payments. Additionally, some cases indicated the misuse of student-linked bank accounts within broader fraud and mule account operations." RondoDox Adds ASUS Router Flaw to its Arsenal —The operators of the RondoDox botnet have incorporated CVE-2018-5999 (CVSS score: 9.8), a critical ASUS router flaw, to their arsenal, marking the first observation of in-the-wild exploitation of the vulnerability. The activity was first detected on May 17, 2026, against its honeypots. "The attack pattern: payloads that set the ateCommand_flag to 1, enabling the infosvr interface to accept arbitrary configuration changes," VulnCheck CTO Jacob Baines said in a post on LinkedIn. Fake Microsoft Teams Sites Deliver ValleyRAT —Fake Microsoft Teams distribution sites shared on X are being used to trick unsuspecting users into downloading a trojanized installer packaged as a ZIP archive, ultimately leading to the deployment of ValleyRAT, a malware associated with a Chinese cybercrime group called Silver Fox. "The delivered payload leverages a DLL sideloading chain via a legitimate executable (GameBox.exe) developed by Tencent, ultimately deploying a ValleyRAT variant," K7 Labs said. "This malware campaign stands out for its clean execution chain, combining social engineering with staged payload delivery, in-memory decryption, and stealthy persistence mechanisms." Malicious Activity Targeting Malaysian Entities —An attacker-controlled infrastructure hosted on Microsoft Azure infrastructure in the Malaysia West region has been used to conduct a targeted intrusion campaign against multiple Malaysian organizations, per Oasis Security. "The operation demonstrates a high degree of operational planning, with the attacker developing purpose-built Python tooling for each target — covering internal network enumeration, database access, and external data exfiltration," the company said. The infrastructure hosts target-specific Python scripts, webshell deployment tools, a Laravel remote code execution exploit chain, and source code for custom command-and-control (C2) components. Texas Attorney General Sues Meta Over WhatsApp Encryption Claims —The Texas Attorney General has sued Meta over allegations that the company's WhatsApp messenger doesn't provide the end-to-end encryption (E2EE) it has long claimed. "Reports suggest that employees of WhatsApp have been able to access user communications," the Office of the Texas Attorney General said. "Additional reporting and investigations indicate that message content can be pulled and viewed after the message has been sent. This is a complete and total misrepresentation of Meta’s privacy policies." The lawsuit hinges on a report from Bloomberg from last month about how the U.S. Commerce Department's Bureau of Industry and Security had abruptly closed an investigation into allegations that Meta could access encrypted WhatsApp messages. Preliminary findings from the department claimed that "there is no limit to the type of WhatsApp message that can be viewed by Meta." Meta has called the allegations "baseless." FIOD Arrests Two in Connection with Stark Industries —The Netherlands Fiscal Intelligence and Investigation Service (FIOD) arrested two men and seized 800 servers in connection with a web hosting company that enabled cyber attacks, interference operations, and disinformation campaigns. The arrested individuals included a 57-year-old man from Amsterdam and a 39-year-old man from The Hague. Although the name of the company was not explicitly mentioned, it is assessed to be Stark Industries, which was sanctioned by the E.U. in May 2025. Following the sanctions, a significant chunk of the technical infrastructure was transferred to a Dutch-based entity known as THE.Hosting aka WorkTitans. "This new company actually acts as a cover for the sanctioned entities," FIOD said. "The director and (indirect) sole shareholder of this company is the 57-year-old suspect." A second unnamed Dutch company is said to have played a facilitating role. "This company, of which the 39-year-old is a suspected director and sole shareholder, ensures that the servers of the former new company are connected to the internet," FIOD added. UNG0002 Targets Chinese Educational Sector —The Chinese educational sector has become the target of a new campaign conducted by UNG0002 as part of a spear-phishing campaign codenamed Operation Dragon Whistle. "What makes this campaign particularly effective is the precision of its social engineering," Seqrite Labs said. "The threat actor did not use a generic lure — they specifically identified that Changzhou University conducts mandatory annual fitness assessments where failure directly impacts graduation eligibility. This creates an environment of urgency and compliance that significantly increases the probability of victim engagement." The emails have been found to distribute ZIP archives that ultimately lead to the deployment of Cobalt Strike Beacon. Void Botnet Uses Ethereum Smart Contracts for C2 —A new botnet malware called Void Botnet uses Ethereum smart contracts for seizure-resistant command-and-control (C2). It's a Rust-based malware that's advertised on cybercrime forums by a developer operating under the handle TheVoidStl. "Based on the seller's documentation and panel screenshots, Void Botnet is a Rust-native loader with two command-and-control modes in the same binary," Qrator Labs said. "The first mode routes commands through Ethereum smart contracts: the operator writes instructions to a contract, and infected machines check it at regular intervals, picking up new tasks within three to five minutes. The second mode connects machines directly to the operator's web panel, with tasks completing in under thirty seconds. The operator switches between them at any time by updating the contract." The botnet works by writing commands to smart contracts, bots polling public RPC endpoints, and C2 infrastructure that is hard to take down. Proton Debuts AI Access Tokens in Proton Pass —Proton Pass, a secure, end-to-end encrypted (E2EE) password manager, has added credential sharing through AI access tokens, allowing users to give AI agents access to items it's permissioned to and monitor their activity. "AI access tokens are our newest secure sharing option to bring password management into the age of agentic AI," Proton said. "Every time an AI agent uses an access token, this is logged, and a reason for the access must be provided. For extra security, you can also set an expiration for each token, from one hour to one year, after which it can no longer be used." DevilNFC and NFCMultiPay Android NFC Relay Malware Spotted —Two new Android NFC relay malware families named DevilNFC and NFCMultiPay have been observed targeting European and LATAM banking customers. "These two NFC relay toolkits are being developed and operated outside the Chinese-speaking MaaS ecosystem: DevilNFC carries an exclusively Spanish-speaking attribution, while NFCMultiPay's developer fingerprint is Portuguese (Brazilian)," Cleafy said. "Local groups are no longer buying access to Chinese platforms; they are building their own." It's assessed that the malware families may have been developed with assistance using generative artificial intelligence (AI). Both malware families are designed to collect the victim's card PIN. "DevilNFC further locks the victim inside the malicious interface via Kiosk Mode, preventing any escape while the relay completes," the Italian company said. "DevilNFC employs an asymmetric architecture in which a single APK serves both roles in a relay attack: a passive reader on the victim's device and a system-level card emulator on the attacker's rooted device, achieved via a hooking framework that intercepts NFC traffic below the Android API layer." DevilNFC overlaps with an NGate variant documented by ESET last month. The malicious apps are distributed via SMS or WhatsApp messages, directing victims to fake landing pages impersonating Google Play Store listings. TAX#TRIDENT Uses Indian Income Tax Lures —A new campaign dubbed TAX#TRIDENT is using Indian Income Tax-themed lures to target Windows endpoints via three delivery paths. The campaign starts with fake tax assessment lures and then moves victims toward ZIP files, VBScript downloaders, or PHP-looking web endpoints that actually return script content," Securonix said. "The first branch uses a ZIP file and a signed ClientSetup installer. Once executed, the installer creates a hidden client tree, adds service and driver persistence, and starts network communication. The second branch uses 'Assessment_Order.vbs.' The script shows a tax assessment decoy image, downloads the same ClientSetup payload, writes a new 'YTSysConfig.ini,' and runs the payload hidden. The third branch uses a PHP-looking endpoint that returns VBScript. That script downloads more stages from S3, disguises a VBS file as a PNG image, changes UAC prompt behavior, and silently installs a signed ManageEngine UEMS / Endpoint Central agent." CISA Launches KEV Nomination Form to Report Exploited Bugs —The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has introduced an online Nomination Form that lets researchers, vendors, and industry partners submit known exploited vulnerabilities (KEVs) directly so as to "quickly identify, validate, and share KEVs, critical threat information." Exploitation of Four-Faith Router Flaw —Attackers are exploiting CVE-2024-9643 (CVSS score: 9.8), a critical authentication bypass flaw in Four-Faith F3x36 industrial cellular routers, as part of a large-scale campaign since mid-May 2026 to turn fold compromised devices into botnets for further campaigns. CrowdSec said it has observed 139 attacking IP addresses through May 18, 2026. "Exploitation was first observed on April 20 and escalated to the point of being reclassified as mass exploitation on May 12, a strong signal that attackers are operationalizing this flaw at scale," it added. Chinese-Language PhaaS Ecosystem Detailed —An analysis of a dozen current phishing-as-a-service (PhaaS) offerings in the Chinese underground has found that they have shifted away from static password harvesting towards real-time interception and tokenization via live administration panels, allowing attackers to capture one-time passcodes (OTPs) and bypass multifactor authentication (MFA) instantly. The services, such as YY Lai Yu, primarily target non-Chinese entities, with advertisements regularly posted to Telegram rather than channels such as WeChat (Weixin) or Tencent QQ. A crucial aspect of these operations is their exploitation of digital wallet provisioning to monetize stolen payment details. Attackers have been found to leverage captured credentials and OTPs to provision the victim's card into a digital wallet on an attacker-controlled device. Once tokenized, the card can be used for high-value transactions, contactless payments, and ATM withdrawals. "Instead of simply gaining account access, these operations focus on exploiting digital wallet provisioning to transform stolen payment data into tokenized assets within ecosystems," Google said. "This shift—combined with the use of encrypted delivery channels like RCS and iMessage to bypass traditional carrier security filters on SMS messages—represents an emerging development where the goal is no longer just a login, but securing direct, unauthorized control over a victim's financial accounts." 🔧 Cybersecurity Tools Bumblebee → It is an open-source security tool for macOS and Linux designed to find software supply-chain vulnerabilities on developer computers. It acts as a lightweight, read-only scanner that audits metadata files, manifests, and configurations rather than executing code. This allows it to safely check local language packages, web browser extensions, text editor add-ons, and AI tool configurations for known security exposures without running potentially malicious install scripts. Claude-BugHunter → It is an open-source add-on that configures Anthropic’s Claude Code command-line tool into a specialized security assistant. It equips the AI with pre-built vulnerability patterns, attack techniques, and reporting templates, automating the process of finding and documenting security flaws during authorized testing. Disclaimer: This is strictly for research and learning. It hasn't been through a formal security audit, so don't just blindly drop it into production. Read the code, break it in a sandbox first, and make sure whatever you’re doing stays on the right side of the law. Conclusion Patch the easy stuff before it becomes a bigger problem next week. The old bugs everyone ignored? Attackers didn’t ignore them. They never do. Right now, the internet feels held together with tape and luck. Every week, there’s a new mess, a new scam, or some old box getting dragged into a botnet. See you next Monday.
thehackernews.comMay 25, 2026extracted
TeamPCP Supply Chain Campaign: Activity Through 2026-05-24, (Mon, May 25th)
TeamPCP now operates across three package ecosystems in parallel, it reached GitHub's own internal codebase, it trojanized an officially Microsoft-published Python SDK, and it appears to have open-sourced its own framework on GitHub. Bottom line up front Three escalations stacked inside a single week. First, GitHub's CISO Alexis Wales publicly named a malicious Nx Console VS Code extension build (v18.95.0, publisher nrwl.angular-console, verified-publisher badge, roughly 2.2 million installs) as the root of an intrusion that exfiltrated approximately 3,800 GitHub-internal repositories; OpenAI, Grafana Labs, and Mistral AI were named as downstream victims. The poisoned extension was live on the Visual Studio Marketplace for roughly 18 minutes. Second, an officially Microsoft-published Python SDK on PyPI (durabletask, the Azure Durable Functions client, roughly 417,000 monthly downloads) was trojanized across three versions (1.4.1 through 1.4.3) inside an approximately 35-minute window, and independent reporting characterizes the second-stage payload as carrying a Linux disk wiper. Third, the same operator pushed a third Mini Shai-Hulud wave through the @antv npm ecosystem: 639 malicious package versions across 323 packages, including echarts-for-react (roughly 1.1 million weekly downloads) and size-sensor (roughly 4.2 million weekly downloads). Action: rotate any developer or CI/CD credentials exposed during the windows below, stop treating publisher-verified or attestation badges as install-time safety signals, and inspect AI coding agent configuration files for persistence. How this developed The week opened with a credentials-to-publish chain that nobody had previously walked end-to-end in public. Reporting from BleepingComputer and Help Net Security ties OIDC credentials harvested in the May 11 TanStack wave to the Nx Console publish on May 18, which means the same operator that built the worm two weeks earlier used its loot to push a trojanized VS Code extension through a verified-publisher account. In parallel, the same operator poisoned the @antv npm ecosystem through a compromised maintainer account ("atool") and dropped a trojanized build of Microsoft's own durabletask SDK on PyPI. Within 72 hours, GitHub itself, Microsoft, and several named AI-lab developer endpoints were affected. By Friday, multiple vendors reported the Shai-Hulud framework source had been published to GitHub, and copycat forks were already running. What changed, by theme The GitHub-internal breach: a multi-stage operation that worked Takeaway: TanStack-harvested credentials from May 11 were used to publish the trojanized Nx Console extension that breached GitHub itself. This is the first publicly confirmed multi-stage operation in the campaign. On 2026-05-18 a malicious build of the Nx Console VS Code extension (v18.95.0, publisher nrwl.angular-console) was published to the Visual Studio Marketplace and was live for approximately 18 minutes before it was pulled. Per Help Net Security and OX Security, an Nx maintainer credential was used to publish; per BleepingComputer, that credential traces back to the TanStack OIDC abuse chain tracked as CVE-2026-45321. On a GitHub employee endpoint, the extension auto-updated during the 18-minute window, exfiltrated developer secrets, and was then used to move laterally through GitHub's internal CI/CD. The intrusion exfiltrated approximately 3,800 GitHub-internal repositories before containment; reporting suggests no customer-tenant data was affected. On 2026-05-21, GitHub CISO Alexis Wales publicly named Nx Console as the root and confirmed OpenAI, Grafana Labs, and Mistral AI as named downstream victims whose developers had auto-update enabled. The practical lesson is uncomfortable: the malicious extension carried the Visual Studio Marketplace verified-publisher badge. Treating that badge as a safety signal at install time would not have prevented this intrusion. A publisher account being legitimate and a specific publish event being legitimate are different claims, and the campaign now operationalizes that gap. The official Microsoft SDK: durabletask 1.4.1 through 1.4.3 Takeaway: For the first time in this campaign, an officially Microsoft-published package surface was trojanized. The second-stage payload reportedly carries a Linux disk wiper. Three malicious versions of the durabletask Python client (Microsoft's official Azure Durable Functions SDK, roughly 417,000 monthly downloads) were published to PyPI on 2026-05-19 and yanked within hours. Per Wiz, Aikido, and Endor Labs, the dropper is injected into the package's Python source files, so importing the SDK is sufficient to execute it. The second stage is a credential stealer and worm that targets AWS, Azure, GCP, HashiCorp Vault, 1Password, and Bitwarden, and that propagates inside cloud environments via AWS SSM (inside EC2) and kubectl exec (inside Kubernetes). iTnews reporting characterizes the second stage as carrying a Linux disk wiper, materially extending the campaign's destructive capability beyond the W20 1-in-6 locale-conditional wipe. If any team installed durabletask versions 1.4.1, 1.4.2, or 1.4.3 on 2026-05-19, the import alone is the trigger. Treat any environment that pulled one of those builds as exposed, including ephemeral CI runners. The @antv npm wave: the largest single burst by package count Takeaway: 639 malicious versions across 323 packages, including echarts-for-react (roughly 1.1 million weekly downloads). Forty-two of the malicious packages were observed displaying fake Sigstore verification badges in the npm UI. On 2026-05-19, a compromised maintainer account ("atool") published a third Mini Shai-Hulud wave across the @antv ecosystem. Independent counts from StepSecurity, Snyk, and Socket agree on 639 malicious versions across 323 packages, which makes this the largest single-hour Shai-Hulud burst the campaign has produced. The roughly 499 KB obfuscated JavaScript payload runs during npm install and harvests more than 20 credential classes: GitHub and npm tokens, AWS keys, GCP and Azure tokens, SSH keys, Kubernetes service accounts, HashiCorp Vault secrets, Stripe API keys, and local password vaults from 1Password and Bitwarden. The persistence vector first seen in the TanStack wave (.vscode/tasks.json and ~/.claude/settings.json) continues here. Endor Labs flagged a previously unreported primitive in this wave: 42 of the malicious packages displayed forged Sigstore verification badges in the npm UI. This pairs poorly with the W20 finding that the prior wave shipped valid SLSA Build Level 3 provenance. Read together, provenance is now being attacked from two directions at once: real attestations produced by hijacked release pipelines, and fake attestations rendered by the registry UI. Pin exact versions and verify lockfile hashes; do not rely on either visual indicator. Per The Hacker News, the GitHub cleanup invalidated roughly 61,274 npm granular access tokens that had write permissions and 2FA bypass. The framework code drop Takeaway: Multiple vendors reported on 2026-05-22 that the Shai-Hulud framework source was published to GitHub. Copycat forks were running within hours. Datadog Security Labs published a static analysis of a public GitHub repository containing what appears to be the complete TeamPCP framework: a modular TypeScript/Bun toolkit for credential harvesting, supply chain poisoning, and encrypted exfiltration. The repository README explicitly carries the strings "Love - TeamPCP" and "Change keys and C2 as needed." OX Security and ReversingLabs corroborated, and OX subsequently documented the first observed deployments from forks. At least three forks had appeared by Datadog's analysis, including one adding FreeBSD support. For defenders, the practical effect is attribution noise. Detection patterns built on framework artifacts (PBKDF2 salt strings, dead-drop string lineage, GitHub repository naming conventions including the reversed-string "niagA oG eW ereH :duluH-iahS") will now also fire on copycat operators with no operational connection to TeamPCP. Behavioral indicators (writes to ~/.claude/settings.json and .vscode/tasks.json, large 2FA-bypassing token harvests, and Session messenger exfiltration to filev2[.]getsession[.]org and seed1[.]getsession[.]org) remain the more durable detection surface. Microsoft broke its silence; CISA did not Takeaway: Microsoft publicly and prominently entered the response coalition. CISA did not add CVE-2026-45321 to the Known Exploited Vulnerabilities catalog in either of the two W21 update tranches. On 2026-05-20 the Microsoft Security Blog published "Mini Shai-Hulud: Compromised @antv npm packages enable CI/CD credential theft," the first formal Microsoft Security Blog post tied to this campaign in 2026. The next day, GitHub's CISO posted publicly on the Nx Console root cause and named downstream victims. Together, these break the multi-week Microsoft silence that prior weekly updates had flagged as anomalous. Federal posture moved the other way. CISA added nine vulnerabilities to the Known Exploited Vulnerabilities catalog inside W21 across two tranches (seven on 2026-05-20 and two on 2026-05-21) and added none of the campaign's tracking identifiers. CVE-2026-45321 is now absent from the KEV catalog despite the GitHub-internal-codebase intrusion, the Microsoft Security Blog publication, the named impact to OpenAI, Grafana Labs, and Mistral AI, and the trojanization of an officially Microsoft-maintained Python SDK. The continued KEV silence is itself the watch item; it is now the longest such gap of the campaign. Monetization stays frozen Takeaway: Vect and CipherForce remained inactive through the window. Direct fetches on 2026-05-24 confirm Vect's victim count unchanged at 25 (most recent posting 2026-04-15, approximately 40 days inactive) and CipherForce inactive at 91 days with 6 victims unchanged. Combined with the earlier Check Point disclosure of cryptographic flaws in Vect 2.0, the affiliate-ransomware monetization channel remains impaired even as the supply chain operation reached new highs. What defenders should do now Inventory installs of the Nx Console VS Code extension v18.95.0 (publisher nrwl.angular-console) on developer endpoints with auto-update enabled. Treat any endpoint that pulled v18.95.0 during the 2026-05-18 Marketplace window as exposed. Inventory durabletask installs of versions 1.4.1, 1.4.2, or 1.4.3 (PyPI) from 2026-05-19. Treat any environment that imported one of those builds as exposed, including ephemeral CI runners. Inventory @antv/* installs and the named packages (echarts-for-react, size-sensor, timeago.js) from the 2026-05-19 window. Tokens, npm credentials, AWS, GCP, Azure, Vault, 1Password, and Bitwarden vaults from affected hosts should be rotated. Rotate any developer or CI/CD credentials that touched the affected extensions or packages, including GitHub PATs, npm granular access tokens, and cloud provider credentials. Do not treat the Visual Studio Marketplace verified-publisher badge or npm Sigstore verification badges as install-time safety signals. Pin exact versions and verify lockfile hashes against a known-good baseline. Inspect developer endpoints for persistence in ~/.claude/settings.json and.vscode/tasks.json . For Kubernetes-attached workloads, audit recent kubectl exec and AWS SSM session history for anomalous activity from compute that ran any of the affected packages. Watch items A CISA Known Exploited Vulnerabilities addition for CVE-2026-45321, a standalone TeamPCP advisory, or a joint advisory with NSA, FBI, or NCSC-UK. After two W21 KEV tranches that excluded the campaign's tracking CVE despite the GitHub-internal breach and the durabletask trojanization, the continued silence is the watch item. A Mandiant or Google Threat Intelligence Group named-actor product on UNC6780 covering the @antv wave, the durabletask compromise, or the Nx Console publish chain. Technical attribution still rests on StepSecurity, Wiz, Snyk, Socket, the Microsoft Security Blog, and the GitHub CISO statement. A formal GitHub incident report or Security Bulletin, including indicators of compromise and a detailed timeline of the May 18 Visual Studio Marketplace publish window. Any Microsoft response on Marketplace publisher-trust validation, given the verified-publisher badge on the malicious build, would be material. Named copycat-operator deployments from forks of the leaked framework, and any operational-confusion incident in which a fork's activity is misattributed to TeamPCP itself. Any verified disk-wipe incident tied to the durabletask Linux wiper or the @antv-wave payload, particularly a CERT-IL or CERT-IR advisory in response to vendor IR engagements disclosing data loss.
isc.sans.eduMay 25, 2026extracted
TeamPCP Supply Chain Campaign: Activity Through 2026-05-24, (Mon, May 25th)
TeamPCP now operates across three package ecosystems in parallel, it reached GitHub's own internal codebase, it trojanized an officially Microsoft-published Python SDK, and it appears to have open-sourced its own framework on GitHub. Bottom line up front Three escalations stacked inside a single week. First, GitHub's CISO Alexis Wales publicly named a malicious Nx Console VS Code extension build (v18.95.0, publisher nrwl.angular-console, verified-publisher badge, roughly 2.2 million installs) as the root of an intrusion that exfiltrated approximately 3,800 GitHub-internal repositories; OpenAI, Grafana Labs, and Mistral AI were named as downstream victims. The poisoned extension was live on the Visual Studio Marketplace for roughly 18 minutes. Second, an officially Microsoft-published Python SDK on PyPI (durabletask, the Azure Durable Functions client, roughly 417,000 monthly downloads) was trojanized across three versions (1.4.1 through 1.4.3) inside an approximately 35-minute window, and independent reporting characterizes the second-stage payload as carrying a Linux disk wiper. Third, the same operator pushed a third Mini Shai-Hulud wave through the @antv npm ecosystem: 639 malicious package versions across 323 packages, including echarts-for-react (roughly 1.1 million weekly downloads) and size-sensor (roughly 4.2 million weekly downloads). Action: rotate any developer or CI/CD credentials exposed during the windows below, stop treating publisher-verified or attestation badges as install-time safety signals, and inspect AI coding agent configuration files for persistence. How this developed The week opened with a credentials-to-publish chain that nobody had previously walked end-to-end in public. Reporting from BleepingComputer and Help Net Security ties OIDC credentials harvested in the May 11 TanStack wave to the Nx Console publish on May 18, which means the same operator that built the worm two weeks earlier used its loot to push a trojanized VS Code extension through a verified-publisher account. In parallel, the same operator poisoned the @antv npm ecosystem through a compromised maintainer account ("atool") and dropped a trojanized build of Microsoft's own durabletask SDK on PyPI. Within 72 hours, GitHub itself, Microsoft, and several named AI-lab developer endpoints were affected. By Friday, multiple vendors reported the Shai-Hulud framework source had been published to GitHub, and copycat forks were already running. What changed, by theme The GitHub-internal breach: a multi-stage operation that worked Takeaway: TanStack-harvested credentials from May 11 were used to publish the trojanized Nx Console extension that breached GitHub itself. This is the first publicly confirmed multi-stage operation in the campaign. On 2026-05-18 a malicious build of the Nx Console VS Code extension (v18.95.0, publisher nrwl.angular-console) was published to the Visual Studio Marketplace and was live for approximately 18 minutes before it was pulled. Per Help Net Security and OX Security, an Nx maintainer credential was used to publish; per BleepingComputer, that credential traces back to the TanStack OIDC abuse chain tracked as CVE-2026-45321. On a GitHub employee endpoint, the extension auto-updated during the 18-minute window, exfiltrated developer secrets, and was then used to move laterally through GitHub's internal CI/CD. The intrusion exfiltrated approximately 3,800 GitHub-internal repositories before containment; reporting suggests no customer-tenant data was affected. On 2026-05-21, GitHub CISO Alexis Wales publicly named Nx Console as the root and confirmed OpenAI, Grafana Labs, and Mistral AI as named downstream victims whose developers had auto-update enabled. The practical lesson is uncomfortable: the malicious extension carried the Visual Studio Marketplace verified-publisher badge. Treating that badge as a safety signal at install time would not have prevented this intrusion. A publisher account being legitimate and a specific publish event being legitimate are different claims, and the campaign now operationalizes that gap. The official Microsoft SDK: durabletask 1.4.1 through 1.4.3 Takeaway: For the first time in this campaign, an officially Microsoft-published package surface was trojanized. The second-stage payload reportedly carries a Linux disk wiper. Three malicious versions of the durabletask Python client (Microsoft's official Azure Durable Functions SDK, roughly 417,000 monthly downloads) were published to PyPI on 2026-05-19 and yanked within hours. Per Wiz, Aikido, and Endor Labs, the dropper is injected into the package's Python source files, so importing the SDK is sufficient to execute it. The second stage is a credential stealer and worm that targets AWS, Azure, GCP, HashiCorp Vault, 1Password, and Bitwarden, and that propagates inside cloud environments via AWS SSM (inside EC2) and kubectl exec (inside Kubernetes). iTnews reporting characterizes the second stage as carrying a Linux disk wiper, materially extending the campaign's destructive capability beyond the W20 1-in-6 locale-conditional wipe. If any team installed durabletask versions 1.4.1, 1.4.2, or 1.4.3 on 2026-05-19, the import alone is the trigger. Treat any environment that pulled one of those builds as exposed, including ephemeral CI runners. The @antv npm wave: the largest single burst by package count Takeaway: 639 malicious versions across 323 packages, including echarts-for-react (roughly 1.1 million weekly downloads). Forty-two of the malicious packages were observed displaying fake Sigstore verification badges in the npm UI. On 2026-05-19, a compromised maintainer account ("atool") published a third Mini Shai-Hulud wave across the @antv ecosystem. Independent counts from StepSecurity, Snyk, and Socket agree on 639 malicious versions across 323 packages, which makes this the largest single-hour Shai-Hulud burst the campaign has produced. The roughly 499 KB obfuscated JavaScript payload runs during npm install and harvests more than 20 credential classes: GitHub and npm tokens, AWS keys, GCP and Azure tokens, SSH keys, Kubernetes service accounts, HashiCorp Vault secrets, Stripe API keys, and local password vaults from 1Password and Bitwarden. The persistence vector first seen in the TanStack wave (.vscode/tasks.json and ~/.claude/settings.json) continues here. Endor Labs flagged a previously unreported primitive in this wave: 42 of the malicious packages displayed forged Sigstore verification badges in the npm UI. This pairs poorly with the W20 finding that the prior wave shipped valid SLSA Build Level 3 provenance. Read together, provenance is now being attacked from two directions at once: real attestations produced by hijacked release pipelines, and fake attestations rendered by the registry UI. Pin exact versions and verify lockfile hashes; do not rely on either visual indicator. Per The Hacker News, the GitHub cleanup invalidated roughly 61,274 npm granular access tokens that had write permissions and 2FA bypass. The framework code drop Takeaway: Multiple vendors reported on 2026-05-22 that the Shai-Hulud framework source was published to GitHub. Copycat forks were running within hours. Datadog Security Labs published a static analysis of a public GitHub repository containing what appears to be the complete TeamPCP framework: a modular TypeScript/Bun toolkit for credential harvesting, supply chain poisoning, and encrypted exfiltration. The repository README explicitly carries the strings "Love - TeamPCP" and "Change keys and C2 as needed." OX Security and ReversingLabs corroborated, and OX subsequently documented the first observed deployments from forks. At least three forks had appeared by Datadog's analysis, including one adding FreeBSD support. For defenders, the practical effect is attribution noise. Detection patterns built on framework artifacts (PBKDF2 salt strings, dead-drop string lineage, GitHub repository naming conventions including the reversed-string "niagA oG eW ereH :duluH-iahS") will now also fire on copycat operators with no operational connection to TeamPCP. Behavioral indicators (writes to ~/.claude/settings.json and .vscode/tasks.json, large 2FA-bypassing token harvests, and Session messenger exfiltration to filev2[.]getsession[.]org and seed1[.]getsession[.]org) remain the more durable detection surface. Microsoft broke its silence; CISA did not Takeaway: Microsoft publicly and prominently entered the response coalition. CISA did not add CVE-2026-45321 to the Known Exploited Vulnerabilities catalog in either of the two W21 update tranches. On 2026-05-20 the Microsoft Security Blog published "Mini Shai-Hulud: Compromised @antv npm packages enable CI/CD credential theft," the first formal Microsoft Security Blog post tied to this campaign in 2026. The next day, GitHub's CISO posted publicly on the Nx Console root cause and named downstream victims. Together, these break the multi-week Microsoft silence that prior weekly updates had flagged as anomalous. Federal posture moved the other way. CISA added nine vulnerabilities to the Known Exploited Vulnerabilities catalog inside W21 across two tranches (seven on 2026-05-20 and two on 2026-05-21) and added none of the campaign's tracking identifiers. CVE-2026-45321 is now absent from the KEV catalog despite the GitHub-internal-codebase intrusion, the Microsoft Security Blog publication, the named impact to OpenAI, Grafana Labs, and Mistral AI, and the trojanization of an officially Microsoft-maintained Python SDK. The continued KEV silence is itself the watch item; it is now the longest such gap of the campaign. Monetization stays frozen Takeaway: Vect and CipherForce remained inactive through the window. Direct fetches on 2026-05-24 confirm Vect's victim count unchanged at 25 (most recent posting 2026-04-15, approximately 40 days inactive) and CipherForce inactive at 91 days with 6 victims unchanged. Combined with the earlier Check Point disclosure of cryptographic flaws in Vect 2.0, the affiliate-ransomware monetization channel remains impaired even as the supply chain operation reached new highs. What defenders should do now Inventory installs of the Nx Console VS Code extension v18.95.0 (publisher nrwl.angular-console) on developer endpoints with auto-update enabled. Treat any endpoint that pulled v18.95.0 during the 2026-05-18 Marketplace window as exposed. Inventory durabletask installs of versions 1.4.1, 1.4.2, or 1.4.3 (PyPI) from 2026-05-19. Treat any environment that imported one of those builds as exposed, including ephemeral CI runners. Inventory @antv/* installs and the named packages (echarts-for-react, size-sensor, timeago.js) from the 2026-05-19 window. Tokens, npm credentials, AWS, GCP, Azure, Vault, 1Password, and Bitwarden vaults from affected hosts should be rotated. Rotate any developer or CI/CD credentials that touched the affected extensions or packages, including GitHub PATs, npm granular access tokens, and cloud provider credentials. Do not treat the Visual Studio Marketplace verified-publisher badge or npm Sigstore verification badges as install-time safety signals. Pin exact versions and verify lockfile hashes against a known-good baseline. Inspect developer endpoints for persistence in ~/.claude/settings.json and.vscode/tasks.json . For Kubernetes-attached workloads, audit recent kubectl exec and AWS SSM session history for anomalous activity from compute that ran any of the affected packages. Watch items A CISA Known Exploited Vulnerabilities addition for CVE-2026-45321, a standalone TeamPCP advisory, or a joint advisory with NSA, FBI, or NCSC-UK. After two W21 KEV tranches that excluded the campaign's tracking CVE despite the GitHub-internal breach and the durabletask trojanization, the continued silence is the watch item. A Mandiant or Google Threat Intelligence Group named-actor product on UNC6780 covering the @antv wave, the durabletask compromise, or the Nx Console publish chain. Technical attribution still rests on StepSecurity, Wiz, Snyk, Socket, the Microsoft Security Blog, and the GitHub CISO statement. A formal GitHub incident report or Security Bulletin, including indicators of compromise and a detailed timeline of the May 18 Visual Studio Marketplace publish window. Any Microsoft response on Marketplace publisher-trust validation, given the verified-publisher badge on the malicious build, would be material. Named copycat-operator deployments from forks of the leaked framework, and any operational-confusion incident in which a fork's activity is misattributed to TeamPCP itself. Any verified disk-wipe incident tied to the durabletask Linux wiper or the @antv-wave payload, particularly a CERT-IL or CERT-IR advisory in response to vendor IR engagements disclosing data loss.
isc.sans.eduMay 25, 2026extracted
Laravel-Lang Packages Poisoned for Malware Delivery
Four popular Composer packages maintained by the Laravel-Lang organization were poisoned with malware after hackers rewrote all their Git tags, security researchers warn. The affected packages, namely laravel-lang/lang, laravel-lang/http-statuses, laravel-lang/attributes, and laravel-lang/actions, are third-party localization libraries used by Laravel applications. The Laravel-Lang supply chain attack started on May 22. During a 15-minute window, the attackers published malicious version tags across three of the packages, StepSecurity says. By 00:00 UTC, May 23, all four packages had been poisoned. “The timing and pattern of the newly published tags point to a broader compromise of the Laravel Lang organization’s release process, rather than a single malicious package version,” Socket notes. According to the supply chain security firm, the malicious tags were published across over 700 historical versions of the four packages, potentially impacting all applications that fetched updates for them or installed them fresh. “What makes this particularly sneaky is that the malicious code was never committed to the official repos at all. GitHub allows version tags to point to commits from a fork of the same repository. The attacker exploited this to create tags pointed to commits in a malicious fork they controlled,” Aikido Security explains. The malicious version tags contained a file named src/helpers.php, posing as a Laravel localization helper. The code fingerprints the machine, then connects to the command-and-control (C&C) domain flipboxstudio[.]info to fetch a PHP credential stealer and execute it in the background. The malware was designed to harvest cloud keys and tokens (including AWS, GCP, and Azure), Docker and Kubernetes configurations, HashiCorp Vault tokens, Helm repository configurations, SSH private keys, developer credentials, authentication tokens, shell history files, and credential-storing files. Additionally, the malware would target credentials stored in browsers and password managers, cryptocurrency wallets and extensions, various communication platforms, VPN configuration files, and various high-value configuration and credential files across Windows, Linux, and macOS systems. Organizations and users alike are advised to block the affected packages and treat any systems that installed them as potentially compromised. They should also confirm the availability of clean versions and install them. “Because the payload targets cloud metadata, Kubernetes tokens, Vault, CI/CD systems, browser data, password managers, source control credentials, VPN configs, SSH keys, .env files, and local application configs, affected teams should rotate any secrets available to hosts, containers, CI runners, or developer machines that installed or ran the compromised packages,” Socket notes. Related: Over 5,500 GitHub Repositories Infected in ‘Megalodon’ Supply Chain Attack Related: Grafana Says Codebase and Other Data Stolen via TanStack Supply Chain Attack Related: Over 320 NPM Packages Hit by Fresh Mini Shai-Hulud Supply Chain Attack
securityweek.comMay 25, 2026extracted
Over 5,500 GitHub Repositories Infected in ‘Megalodon’ Supply Chain Attack
More than 5,500 GitHub repositories were infected with malware in a supply chain attack that relies on automated commits, security researchers warn. The campaign, dubbed Megalodon, relies on GitHub Actions workflows containing a payload designed to steal credentials, keys, tokens, and other secrets. The workflows, SafeDep says, were injected through over 5,700 malicious commits pushed to the impacted repositories within a six-hour window, on May 18. According to the cybersecurity firm, the attackers deployed two payloads as part of the attack. One was designed to add a new workflow that would be triggered on every push and pull request, and another that replaced existing workflows with specific triggers, creating dormant backdoors. On infected machines, the malware would exfiltrate all CI environment variables, AWS credentials, GCP access tokens, Azure credentials, SSH private keys, Docker and Kubernetes configurations, API keys, database connection strings, GitHub Actions tokens, GitLab CI/CD tokens, and dozens of other types of secrets. Megalodon, SafeDep explains, was discovered after malicious versions of the Tiledesk package, an open source live chat and chatbot platform, were identified. The infected packages were published between May 19 and May 21. “The same NPM account, eljohnny ([email protected]), published both the clean 2.18.5 and the compromised versions. The attacker never touched the NPM account. They compromised the GitHub repository, and the maintainer published from the poisoned source without realizing it,” SafeDep says. The malicious commit that led to the infection was pushed on May 18, authored by ‘build-bot’. SafeDep’s investigation into the associated email address uncovered a total of 2,878 commits made on the same day, along with an additional 2,841 commits made via a second email address. “All 5,718 commits landed on the same day: May 18, 2026, across a six-hour window from approximately 11:36 to 17:48 UTC, targeting 5,561 distinct repositories,” SafeDep explains. The cybersecurity firm also notes that the attackers’ choice of malicious GitHub Actions workflow, namely ‘workflow_dispatch’, ensured that the dormant backdoor could be triggered at a later date via the GitHub API, using stolen GitHub tokens. The workflow is exempted from GitHub’s anti-recursion rules, which prevent new workflow runs from being spawned via GitHub token-triggered events. Last week, NPM announced that all NPM granular access tokens with write access that bypass two-factor authentication have been invalidated to prevent supply chain attacks similar to Mini Shai-Hulud. According to Ox Security, this should prevent account hijacking, but does not resolve the underlying problem, and malicious code will continue to spread through compromised repositories. “If platforms continue allowing any type of code to be uploaded without serious vetting, the number of attacks will only increase,” Ox notes. “We’ve entered a new supply chain attack era, and TeamPCP compromising GitHub was only the beginning. What’s coming next is an endless wave, a tsunami of cyber attacks on developers worldwide,” the cybersecurity firm says. Related: Grafana Says Codebase and Other Data Stolen via TanStack Supply Chain Attack Related: Supply Chain Security Crisis: Too Many Vulnerabilities, Too Little Visibility Related: Over 320 NPM Packages Hit by Fresh Mini Shai-Hulud Supply Chain Attack
securityweek.comMay 25, 2026extracted
Week in review: GitHub breached via poisoned VS Code extension, critical NGINX flaw exploited
Week in review: GitHub breached via poisoned VS Code extension, critical NGINX flaw exploited Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: GitHub, Grafana Labs breaches traced back to TanStack supply chain compromise GitHub CISO Alexis Wales has named the malicious VS Code extension behind the breach they suffered at the hands of the threat group TeamPCP: Nx Console, a popular developer tool with 2.2 million installs. Earbud sensors can authenticate users by their heartbeat, study finds Researchers built a continuous authentication system called AccLock that identifies a wearer by the tiny vibrations a heartbeat makes inside the ear canal. Attackers are exploiting critical NGINX vulnerability (CVE-2026-42945) A critical NGINX vulnerability (CVE-2026-42945) disclosed last week is being exploited by attackers, VulnCheck security researcher Patrick Garrity revealed on Saturday. Communicating cyber risk in dollars boards understand In this Help Net Security interview, Nick Nieuwenhuis, Cybersecurity Architect at Nedscaper, explains why cybersecurity has not delivered the resilience that decades of investment have promised. Microsoft provides mitigation for “YellowKey” BitLocker bypass flaw (CVE-2026-45585) Microsoft is working on a fix for CVE-2026-45585 (aka “Yellowkey”), a vulnerability that can be used by attackers to bypass protections offered by BitLocker, the full-disk encryption feature built into Windows, and access users’ data. Why AI changed the threat model for travel technology In this Help Net Security interview, Devon Bryan, SVP, Global CSO at Booking Holdings, reflects on his path from Air Force network security engineer to global CSO across financial services, hospitality, and travel technology. Deleted Google API keys keep working for up to 23 minutes, researchers warn Google API keys are credentials that let applications access Google services, from Maps to the Gemini AI. If a key is leaked, an attacker can use it to make API calls, rack up charges, and, if Gemini is enabled, access uploaded files and cached conversations. The assumed fix is simple: delete the key. But Aikido Security has found that deletion doesn’t actually work right away. Microsoft open-sources tools for designing and testing AI agents Microsoft has open-sourced two tools aimed at bringing security discipline to AI agent development: Clarity, a structured design review tool, and RAMPART, a continuous testing framework. AI red teaming agents change how LLMs get tested Adversarial probing of LLMs has piled up a sprawling toolkit over the past three years. Attack techniques with names like Tree of Attacks with Pruning, Crescendo, and Skeleton Key sit alongside hundreds of prompt transforms and scoring methods across open-source frameworks including Microsoft’s PyRIT, NVIDIA’s Garak, and Promptfoo. Microsoft Defender vulnerabilities exploited in the wild (CVE-2026-41091, CVE-2026-45498) Attackers are exploiting two Microsoft Defender vulnerabilities (CVE-2026-41091 and CVE-2026-45498), Microsoft acknowledged and CISA confirmed by adding them to its Known Exploited Vulnerabilities catalog. Verizon DBIR: Vulnerability exploitation is the dominant initial access vector Vulnerability exploitation has overtaken stolen credentials as the most common way attackers gain initial access to target networks, according to the 2026 Verizon Data Breach Investigations Report. PureLogs infostealer is stealing credentials worldwide A phishing campaign is smuggling the powerful PureLogs information stealer onto targets’ Windows machines by hiding encrypted malicious payloads inside cat photos, Fortinet researchers discovered. New macOS infostealer impersonates Apple, Microsoft, and Google in a single attack chain A SHub macOS infostealer variant called Reaper impersonates Apple, Microsoft, and Google to trick users into executing malicious code, then targets browser data, password managers, and cryptocurrency wallets while establishing persistence for continued access, SentinelOne found. AI is drowning software maintainers in junk security reports AI-assisted vulnerability research has exploded, unleashing a firehose of low-quality reports on overworked software maintainers who are wasting hours sifting through noise instead of fixing real problems. The end of unencrypted Discord calls is here Discord has protected voice and video calls in DMs, group DMs, voice channels, and Go Live streams with end-to-end encryption (E2EE) by default. The AI backdoor your security stack is not built to see Enterprises deploying LLMs have spent the past two years building defenses around a reasonable assumption: malicious behavior leaves a trace in the input. Scan for suspicious tokens, filter unusual characters, watch for prompt injection patterns. New research from Microsoft and the Institute of Science Tokyo demonstrates that this defensive posture has a blind spot, and the cost of that blind spot could be measured in leaked proprietary data and regulatory exposure. When ransomware hits, confidence doesn’t restore endpoints Ransomware, supply chain vulnerabilities, insider threats, compliance failures, and software disruptions remain major concerns for security leaders, according to The Ransomware Reality: Zero Days to Recover report by Absolute Security. AI shrinks vulnerability exploitation window to hours Time has become organizations’ biggest vulnerability because the gap between vulnerability discovery and exploitation has narrowed to hours, according to Synack’s 2026 State of Vulnerabilities Report. Most dark web activity revolves around a handful of topics A six-year dataset covering more than 25,000 dark web sites tracked what people discussed in underground forums and marketplaces and how those discussions changed over time. Public Instagram posts provide raw material for AI phishing campaigns A handful of public Instagram posts can give attackers enough material to generate convincing phishing emails with GenAI. Research from the University of Texas at Arlington and Louisiana State University showed how public social media activity can be turned into phishing messages that appear personal and credible to human recipients. CVE Lite CLI: Open-source dependency vulnerability scanner Dependency vulnerability scanning in JavaScript and TypeScript projects has long sat at the end of the development pipeline. Pull requests get opened, continuous integration runs, and a security scanner returns a list of CVE identifiers that developers then have to triage hours or days after writing the code. CVE Lite CLI, now an officially recognized OWASP Incubator Project, moves that check to the developer’s terminal. What happens when your identity provider becomes the kill chain In this Help Net Security video, Colin Constable, CTO at Atsign, explains why your identity provider (IdP) has become the kill chain in cyberattacks. Attackers steal session cookies, tokens, or consent grants you’ve already issued and walk in behind you. 7 hard truths security pros should know: 2026 DevOps Threats Report In 2025, trusted Git hosting platforms became a playground for cyber criminals. This is the main conclusion from the latest “DevOps Threat Unwrapped Report 2026” by GitProtect. Product showcase: Bitdefender Mobile Security for iOS protects privacy where scams begin Bitdefender Mobile Security for iOS is a security and privacy application for iPhone and iPad that helps protect against phishing attempts, online scams, unsafe websites, and account exposure. Cybersecurity jobs available right now: May 19, 2026 We’ve scoured the market to bring you a selection of roles that span various skill levels within the cybersecurity field. Check out this weekly selection of cybersecurity jobs available right now. New infosec products of the week: May 22, 2026 Here’s a look at the most interesting products from the past week, featuring releases from ASAPP, Babel Street, CTERA, Forward, Riverbed, and Trust3 AI.
helpnetsecurity.comMay 24, 2026extracted
Grafana Says Codebase and Other Data Stolen via TanStack Supply Chain Attack
Grafana this week revealed that the unauthorized access to the Grafana Labs GitHub repositories disclosed earlier this month was the result of the TanStack supply chain attack. On May 11, TanStack and other high-profile NPM and PyPI projects were hit by a Mini Shai-Hulud supply chain attack that resulted in self-propagating information-stealing malware being deployed on victims’ computers. Grafana says it detected malicious activity associated with the attack on May 11 and immediately rotated GitHub workflow tokens. Because one token was not revoked, however, the threat actor behind the TanStack attack accessed Grafana’s GitHub repositories. “A subsequent review confirmed that a specific GitHub workflow we originally deemed not impacted had, in fact, been compromised,” Grafana says. On May 16, Grafana received a ransom demand from the attackers, but refused to pay. Simultaneously, it launched additional mitigation efforts, hardened its GitHub posture, and notified law enforcement. “Current findings indicate the scope of this incident is limited to the Grafana Labs GitHub repositories, which include public and private source code along with internal GitHub repos,” Grafana says. While no customer production systems or operations were affected, the hackers did steal Grafana’s codebase, as well as repositories storing internal operational information and other business details. “This includes business contact names and email addresses that would be exchanged in a professional relationship context, not information pulled from or processed through the use of production systems or the Grafana Cloud platform,” Grafana says. The incident, it explains, did not affect its production systems, nor the Grafana Cloud platform. Furthermore, Grafana says, while its codebase was downloaded, it was not modified, and no action is needed from customers or open source users. Related: Supply Chain Security Crisis: Too Many Vulnerabilities, Too Little Visibility Related: AI-Powered App Attacks Are Faster, More Frequent and Harder to Stop Related: Over 320 NPM Packages Hit by Fresh Mini Shai-Hulud Supply Chain Attack Related: OpenAI Hit by TanStack Supply Chain Attack
securityweek.comMay 22, 2026extracted
GitHub Breach Traced to Malicious 'Nx Console' VS Code Extension
GitHub has confirmed that a recent breach into its internal repositories was caused by a vulnerability in a Microsoft Visual Studio Code (VS Code) extension called ‘Nx Console.’ The security team at the Microsoft-owed software developer platform warned on May 19 that an attacker gained unauthorized access to 3800 internal repositories via a “poisoned” VS Code extension found on an employee device. It was later confirmed by Jeff Cross, CEO of Nx that Nx Console, a popular VS Code extension, was the extensions that was poisoned extension and resulted in the GitHub breach. Nx Console provides a graphical interface for managing and running Nx workspace tasks, generators and builds. Nx is a development toolkit for managing large codebases, also known as monorepos. Nx Console is a popular extension, with 2.2 million installs on the Visual Studio Marketplace and a verified publisher badge. In a report published on GitHub, Cross explained that a malicious version of Vx Console (version 18.95.0) was uploaded to Visual Studio Marketplace and Open VSX, an open-source extension registry for Visual Studio Code–compatible editors, on May 18. The upload was completed at 12.30 UTC by an individual who posed as a legitimate Nx maintainer. The compromised extension fetched an obfuscated payload that harvested credentials from multiple sources on disk and in memory: Vault: ~/.vault-token, /etc/vault/token; Kubernetes and AWS IAM auth Npm: .npmrc tokens and OIDC token exchange AWS: IMDS/ECS metadata, Secrets Manager, SSM, Web Identity tokens GitHub: ghp_/gho_/ghs_ tokens, Actions secrets, process memory 1Password: op CLI vault contents, if an op session was active Filesystem: private keys, connection strings, GCP/Docker credentials The issue has been allocated a vulnerability identifier, CVE-2026-48027. Cross explained that the person managed to gain the GitHub credentials of a legitimate Nx developer through a recent supply-chain compromise of TanStackn pm packages. This was part of a broader supply chain attack affecting developer ecosystems, commonly known as the Mini Shai-Hulud campaign. TanStack is a collection of open-source developer tools for building modern web apps, especially focused on state management, data fetching, tables, routing and virtualization. Additionally, Cross admitted that the upload of the malicious Nx Console version was performed “without manual approval” from other Nx administrators. “To prevent this from happening in the future, we have hardened our Nx Console publishing pipeline such that two admins need to manually approve the release.” A maintainer unpublished the malicious version a few minutes later and Microsoft fully registered the takedown at 12:48 UTC, meaning the malicious extension was available on the Visual Studio Marketplace for about 18 minutes. Cross, the Nx CEO, said his company “takes responsibility” for the role its software played in this incident. He thanked all involved, including at GitHub and Microsoft, to help investigate and contain the threat. “This incident highlights that there need to be deeper, more fundamental changes to how we and other maintainers need to think about securing developer tooling and open-source distribution,” he added. He also said Nx has already started implementing changes “to our publishing, automation, and extension security posture.” “We’re also beginning conversations with other high-profile open-source maintainers about how we can work together on some of the deeper structural problems around software supply chain security. A lot of the assumptions the ecosystem has operated under for years no longer hold.” 3800 GitHub Internal Repositories Stolen While the time window may appear short, it was long enough to infect many open-source project contributors running VS Code with the Nx Console extension installed and auto-update enabled. Anyone in this situation should assume they were compromised and should rotate any authentication keys stored on disk, including tokens, secrets, SSH keys and any type of credentials. The attacker also managed to steal approximately 3800 of GitHub’s internal repositories. GitHub contained the threat and explained in its 19 May update that it had removed the malicious extension version, isolated the endpoint and began incident response immediately. “Critical secrets were rotated yesterday and overnight with the highest-impact credentials prioritized first,” GitHub added. “We continue to analyze logs, validate secret rotation, and monitor for any follow-on activity. We will take additional action as the investigation warrants.” The company also promised to publish a more detailed report once the investigation is complete. Team PCP Allegedly Selling GitHub Repos for $95,000 The breach was claimed by the TeamPCP hacking group. The group first demanded “at least $50,000” for the stolen data before reportedly posting an ad in which TeamPCP appears to partner with the Lapsus$ threat group to sell the stolen data for $95,000. The group stated that this was “not a ransom” and that they were not interested in extorting GitHub. Instead, they claimed that they would only sell the data to one buyer, were "not interested in under 50k" and that "the best offer will get it." They certified they would delete the stolen data once a buyer has been found, adding that it appeared their retirement was imminent. They also warned that if no buyer was found, they would leak the data for free. Image credits: GitHub
infosecurity-magazine.comMay 21, 2026extracted
GitHub, Grafana Labs breaches traced back to TanStack supply chain compromise
GitHub, Grafana Labs breaches traced back to TanStack supply chain compromise GitHub CISO Alexis Wales has named the malicious VS Code extension behind the breach they suffered at the hands of the threat group TeamPCP: Nx Console, a popular developer tool with 2.2 million installs. A malicious version of the otherwise benign extension was used to steal secrets and developer credentials, which were then used to move through CI/CD pipelines and exfiltrate around 3,800 of GitHub’s private code repositories. One missed token, many victims The company confirmed the compromise on Wednesday, and promised to publish a fuller report once their investigation is complete. Soon after, Wales publicly identified the poisoned VS Code extension that a GitHub employee installed and thus enabled the attackers to gain access to the repositories. Nx Console maintainers have been sharing information surfaced by their own investigation into how a malicious version of the extension was published on both the Microsoft-owned Visual Studio Marketplace and the vendor-neutral registry Open VSX. “One of our developers was compromised by a recent supply-chain compromise on TanStack, which leaked their GitHub credentials through the GitHub CLI (gh). This allowed the attacker to run workflows on our GitHub repository as a contributor,” they explained. “According to Microsoft and OpenVSX, download numbers for the impacted 18.95.0 version were a low 28 and 41 respectively. However, according to our own internal analytics, we believe the impact to be two orders of magnitude higher, with thousands of affected users.” One of the affected users turned out to be the GitHub employee. The compromised extension fetched an obfuscated payload, which was able to harvest victims’ credentials. Among those were login tokens for the HashiCorp Vault secrets manager; credentials used authenticate via Kubernetes or AWS identity systems; authentication tokens used to publish packages to npm registries; GitHub personal access tokens, OAuth tokens, and app tokens; credentials stored in the victim’s 1Password vault; and Google Cloud Platform and Docker credentials. “Harvested data was exfiltrated via HTTPS, the GitHub API, and DNS. On Linux it also attempted sudoers injection for persistence,” the Nx Console maintainers noted, and provided remediation advice, which includes rotating “every credential reachable from the machine.” Grafana Labs, which similarly got its GitHub environment compromised and codebase stolen, also traced the compromise back to the TanStack npm supply chain attack. “The incident originated from a TanStack npm supply chain attack via the Mini Shai-Hulud campaign. We detected the malicious activity on May 11 and immediately initiated our incident response plan,” shared Joe McManus, the Grafana Labs chief information security officer. “We performed analysis and quickly rotated a significant number of GitHub workflow tokens, but a missed token led to the attackers gaining access to our GitHub repositories. A subsequent review confirmed that a specific GitHub workflow we originally deemed not impacted had, in fact, been compromised.” The company has been contacted by the attackers, who demanded payment not to release or sell the stolen codebase, but Grafana Labs decided not to pay the ransom. TeamPCP automated its way through the open source ecosystem The TanStack supply chain compromise affected 42 of its npm packages. Malicious versions were made to include a credential-stealing JavaScript payload. That compromise, like many others in the last weeks, was carried out via Mini Shai-Hulud, a self-replicating supply chain “worm” created and operated by TeamPCP. The “worm” allows them to automate supply chain attacks by stealing CI/CD credentials and leveraging them to publish infected versions of more and more packages. TeamPCP, a cybercrime group that specializes in supply chain attacks targeting open-source utilities and AI middleware, has claimed the GitHub hack and is likely behind Grafana’s, as well. Subscribe to our breaking news e-mail alert to never miss out on the latest breaches, vulnerabilities and cybersecurity threats. Subscribe here!
helpnetsecurity.comMay 21, 2026extracted
Supply Chain Security Crisis: Too Many Vulnerabilities, Too Little Visibility
New vulnerabilities are being discovered too fast, the time-to-exploitation is too short, and our visibility into them is largely lacking. The global interconnectivity of business, and the systems and software it uses, has elevated the supply chain and supply chain threats to a preeminent cybersecurity concern. A particular issue is that many organizations are unaware of their position within a supply chain and can be victimized through no active fault of their own. The 2026 supply chain vulnerability report from Black Kite leads with the statement, ‘velocity without visibility is the new supply chain crisis’. Its analysis offers three primary takeaways: more than 48,000 CVEs were published in 2025 the time to exploitation is now a negative number only 58 of the CVEs are identified as posing a genuine, discoverable, and exploitable threat to enterprise supply chains. The first takeaway is a matter of record. The second is a conclusion reached by both Black Kite and, separately, Mandiant (M-Trends 2026: “The mean time to exploit vulnerabilities dropped to an estimated -7 days, meaning exploitation is routinely occurring before a patch is even released.”). Together, these two facts illustrate that firms cannot possibly maintain security through patching CVEs. This explains Black Kite’s concern over ‘velocity’. The third takeaway indicates the need for ‘visibility’ into the vulnerabilities in order to reduce their number to a manageable figure. The approach taken by Black Kite was to select a subset of high priority CVEs (amounting to 1,024) based on their EPSS scores, KEV inclusion, and third-party relevance. From these, however, only 58 CVEs were easily discoverable to attackers through OSINT and were therefore the most critical. Finding those most critical CVEs is a primary visibility issue in supply chain security – but if they can be found, the velocity can be better managed. While this velocity and visibility was a problem in 2025, it is likely to get worse in the future – and AI is both a direct and indirect causal factor. Firstly, we can be certain that during 2026, frontier model AI will find more vulnerabilities than were discovered in previous years. Secondly, the rapid growth of easily vibe coded new applications is introducing more apps with more weaknesses. Thirdly, the increased AI-influenced frequency of software updates are more likely to include malicious npm-created software weaknesses that can be exploited later. To these, Jeffrey Wheatman, SVP and cyber risk strategist at Black Kite, adds a fourth. “I think much of the agentic growth we’re seeing is leading to additional exposures, because these tools are granted authorization, authentication, and access.” This increases the visibility problem because the IT and security departments are unaware of the agentic systems being used in their infrastructure: they can be hidden and undisclosed in downloaded web apps, or quietly introduced through shadow AI. The number of vulnerabilities will continue to rise, and the time to exploitation will continue to shrink. “I think the numbers just keep rising,” continues Wheatman. But he adds one hopeful point. “The good news is much of this is effectively background noise. For example, in all the hubbub over the vulnerabilities found by Mythos, there was some focus on finding a 27-years old bug in OpenBSD. Okay, that’s true. But can it be compromised? Not really, in any practical way.” So, we come back to Black Kite’s initial premise. The number of vulnerabilities will continue to rise, and the time to compromise will continue to shrink. The velocity of vulnerabilities will worsen, and organizations will be more unable to cope – unless they are able, through visibility, to determine the relatively few really critical vulnerabilities to focus on. Wheatman is also optimistic that defensive AI can assist. The biggest issue here is whether the increasing velocity of threats will cause an increased reliance on completely autonomous defensive AI, too soon. The answer, as so often happens in cybersecurity questions, is it depends. “Remember the CrowdStrike incident,” he suggests. A faulty configuration update to the Falcon Sensor on Windows systems was automatically deployed through CrowdStrike’s Rapid Response Content system – causing around 8.5 million Windows systems to crash. “The big question I heard,” he continues, “was ‘should we turn off automated updates?’, because that is what caused that problem. The decision I heard is that those automatic updates, while they do lead to some risk, not updating signatures, those definitions, that discovery, that identification capability, is a significantly higher risk.” But it still depends. “A bank will be less inclined to allow automatic shutdown of their trading system than their payroll system because it could cost millions of dollars for every hour of the shutdown.” Such situations may demand a human in the loop to make the final decision. Smaller firms with fewer manpower resources and lower security budgets may be more likely to move toward fully autonomous defense, simply to cope with the velocity of vulnerabilities and lack of visibility into their criticality. Again, a major problem is a lack of visibility into the software being used. This should be provided via SBOMs delivered by the software supplier, but their completeness, accuracy and value is currently debatable. SBOMs should provide details of any vulnerabilities in the software – but do they? “We’re starting to hear more about AI SBOMs, which are a bit of a holy grail – but they’re still a year or more in the future,” adds Wheatman. In the end, it all comes down to Black Kite’s original premise. Velocity without visibility is the new supply chain crisis and gaining that visibility will help provide the solution. Related: OpenAI Hit by TanStack Supply Chain Attack Related: TanStack, Mistral AI, UiPath Hit in Fresh Supply Chain Attack Related: Checkmarx Jenkins AST Plugin Compromised in Supply Chain Attack Related: Vendor Says Daemon Tools Supply Chain Attack Contained
securityweek.comMay 21, 2026extracted
Grafana Labs Says Code Breach Stemmed from TanStack Attack
A popular developer of open source analytics software has revealed that a recent data breach and extortion incident was caused by the Mini Shai-Hulud campaign which compromised TanStack packages. Grafana Labs, which makes the AI-powered visualization app Grafana, said on May 17 that it had discovered an unauthorized attacker had downloaded its codebase after accessing the firm’s GitHub environment. In an update this week, the developer shared more about the incident, revealing that it first spotted the malicious activity on May 11 and tied it to the TanStack supply chain attacks. TeamPCP threat actors compromised dozens of TanStack npm packages with credential-stealing malware targeting CI/CD environments including GitHub Actions. This meant that when a malicious package was released, Grafana’s CI/CD environment automatically consumed it and the infostealer executed to exfiltrate GitHub workflow tokens. “We performed analysis and quickly rotated a significant number of GitHub workflow tokens, but a missed token led to the attackers gaining access to our GitHub repositories,” Grafana admitted. “A subsequent review confirmed that a specific GitHub workflow we originally deemed not impacted had, in fact, been compromised.” “As soon as we were contacted by the ransom gang, we launched mitigation efforts, which have included rotating automation tokens, implementing enhanced monitoring, auditing all commits since the May 11 incident, and significantly hardening our GitHub security posture,” Grafana continued. Grafana Labs also shared that additional “internal operational information and other details” were taken by TeamPCP from its GitHub repositories, alongside the firm’s codebase. “This includes business contact names and email addresses that would be exchanged in a professional relationship context, not information pulled from or processed through the use of production systems or the Grafana Cloud platform,” it said. It reiterated that, at this stage, there’s no indication that customer production systems or operations have been compromised. The Ongoing Threat from Mini Shai-Hulud The incident is just one example of the long tail of downstream victims emerging from this particular Mini Shai-Hulud campaign. TanStack said the threat actors published 84 malicious versions across 42 @tanstack/* packages on May 11. The infostealer targeted not only GitHub Actions tokens but also GitLab, CircleCI, AWS, Google Cloud Platform, Azure, Kubernetes, HashiCorp Vault and package registry tokens. The campaign didn’t just impact TanStack users. TeamPCP also broadened its reach to compromise OpenSearch npm versions, PyPI mistralai 2.4.6, PyPI guardrails-ai 0.10.1 and further @squawk packages. This Mini Shai-Hulud campaign was particularly dangerous because TeamPCP compromised TanStack’s own CI/CD pipeline, meaning the malicious packages presented as valid and cryptographically signed. This ensured they bypassed any security filters that downstream developers may have been running in their environments.
infosecurity-magazine.comMay 21, 2026extracted
GitHub links repo breach to TanStack npm supply-chain attack
GitHub says the hackers who breached 3,800 internal repositories gained access via a malicious version of the Nx Console VS Code extension, compromised in last week's TanStack npm supply-chain attack. This attack is attributed to the TeamPCP threat group and began with the compromise of dozens of TanStack and Mistral AI npm packages, then quickly extended to other projects (including UiPath, Guardrails AI, and OpenSearch) using stolen CI/CD credentials. TeamPCP was linked to other (which also affected two OpenAI employees). GitHub revealed the breach on Tuesday, BleepingComputer that the incident resulted from an employee installing a malicious Visual Studio Code (VS Code) extension, without disclosing the extension's name. In a blog published Wednesday evening, GitHub CISO Alexis Wales said the breach involved a malicious version of Nx Console, the official Visual Studio Code marketplace extension for Nx, that allows developers to manage large repos and multi-project codebases without relying entirely on complex Terminal CLI commands. Wakes added that GitHub has since secured the compromised device and has yet to find evidence that customer data stored outside the affected repos has been stolen. "We rotated critical secrets Monday and into Tuesday with the highest-impact credentials prioritized first," Wales said. "We continue to analyze logs, validate secret rotation, and monitor our infrastructure for any follow-on activity. We will take additional action as the investigation warrants." While GitHub has yet to attribute the attack to a specific hacking group or threat actor, the TeamPCP cybercrime gang claimed access to GitHub source code and "~4,000 repos of private code" on the Breached forum on Tuesday, and is now asking for at least $50,000 for the stolen data. This comes after the Nx devs revealed on Monday that they were jointly investigating the impact of the attack with GitHub and Microsoft, after a malicious version of Nx Console 18.95.0 was available on the Visual Studio Marketplace for approximately 18 minutes and on OpenVSX for another 36 minutes. The poisoned extension deployed a malicious payload designed to steal credentials and secrets for a wide range of platforms, including npm, AWS, Kubernetes, GitHub, and GCP/Docker. "One of our developers was compromised by a recent supply-chain compromise on Tanstack, which leaked their GitHub credentials through the GitHub CLI (gh). This allowed the attacker to run workflows on our GitHub repository as a contributor," the NX team said. "According to Microsoft and OpenVSX, download numbers for the impacted 18.95.0 version were a low 28 and 41 respectively. [..] Two days after the attack, our analytics have registered approximately 6000 extension activations from VSCode and 0 from other editors (including VSCode forks like Cursor)." In recent years, multiple other malicious VS Code extensions with millions of installs have snuck on the official VS Code marketplace and have been used to steal developer credentials and other sensitive data. Last year, several VS Code extensions with 9 million installs were removed due to security risks, including 10 that infected users with the XMRig cryptominer, while a malicious extension with basic ransomware capabilities was later spotted on the VS Code marketplace after the threat actor WhiteCobra flooded it with 24 crypto-stealing extensions. In January, two more extensions posing as AI-based coding assistants, with 1.5 million installs, were used to exfiltrate data from compromised developer systems to servers in China. GitHub's cloud-based platform is used by more than 4 million organizations (including 90% of Fortune 100 companies) and over 180 million developers who contribute to more than 420 million code repositories. Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply. The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments. Get the report
bleepingcomputer.comMay 21, 2026extracted
GitHub Internal Repositories Breached via Malicious Nx Console VS Code Extension
GitHub on Wednesday officially confirmed that the breach of its internal repositories was the result of a compromise of an employee device involving a poisoned version of the Nx Console Microsoft Visual Studio Code (VS Code) extension. The development comes as the Nx team revealed that the extension, nrwl.angular-console, was breached after one of its developers' systems was hacked in the wake of the recent TanStack supply chain attack. Other companies that were impacted by the TanStack compromise include OpenAI, Mistral AI, and Grafana Labs. "We have no evidence of impact to customer information stored outside of GitHub's internal repositories, such as our customer's own enterprises, organizations, and repositories," Alexis Wales, Chief Information Security Officer of GitHub, said in a statement. "Some of GitHub's internal repositories contain information from customers, for example, excerpts of support interactions. If any impact is discovered, we will notify customers via established incident response and notification channels." The attack is said to have allowed the threat actor, a cybercriminal group known as TeamPCP, to exfiltrate about 3,800 repositories. GitHub said it has taken steps to contain the incident and rotated critical secrets, adding it's continuing to monitor the situation for follow-on activity. In a post on X, Jeff Cross, co-founder of Narwhal Technologies, the company behind nx.dev, said, "this incident highlights that there need to be deeper, more fundamental changes to how we and other maintainers need to think about securing developer tooling and open source distribution." "We're also beginning conversations with other high-profile open source maintainers about how we can work together on some of the deeper structural problems around software supply chain security. A lot of the assumptions the ecosystem has operated under for years no longer hold." In recent months, TeamPCP has rapidly gained notoriety for large-scale software supply chain attacks, specifically going after widely-used open-source projects and security-adjacent tools that developers rely on. What's notable here is that the trojanized version of the VS Code extension was live on Visual Studio Marketplace only for 18 minutes (between 12:30 p.m. and 12:48 p.m. UTC on May 18, 2026). But this short window was enough for the attackers to distribute a credential stealer capable of harvesting sensitive data from 1Password vaults, Anthropic Claude Code configurations, npm, GitHub, and Amazon Web Services (AWS). "The extension looked and behaved like normal Nx Console, but on startup it silently ran a single shell command that downloaded and executed a hidden package from a planted commit on the official nrwl/nx GitHub repository," OX Security researcher Nir Zadok said. "The command was disguised as a routine MCP setup task so it would not raise suspicion." The interlinked nature of modern software has allowed TeamPCP to unleash a self-sustaining cycle of new compromises. The pattern that drives home this aspect is deceptively simple as it's nefarious: break into one trusted tool, steal credentials from developer systems that may install it, and use those credentials to break into the next legitimate tool. "Every popular extension marketplace ships with auto-update on by default. VS Code, Cursor, the whole lineup," Aikido security researcher Raphael Silva said. "The reasoning makes sense in isolation, because most developers never update anything manually, so leaving it off means a long tail of editors running stale, vulnerable code." "The trade-off stops making sense once you account for hostile/compromised publishers. Auto-update gives an attacker who controls a release a direct push channel into every machine running that extension. Marketplaces don't impose any review gate or waiting period between when an update is published and when installed clients pull it in." Update The supply chain attacks targeting TanStack and Nx Console are being tracked as CVE-2026-45321 (CVSS score: 9.6) and CVE-2026-48027 (CVSS score: 9.3), respectively. On May 27, 2026, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added both the flaws to its Known Exploited Vulnerabilities (KEV) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply necessary fixes by June 10, 2026.
thehackernews.comMay 21, 2026extracted
Grafana breach caused by missed token rotation after TanStack attack
The Grafana data breach was caused by a single GitHub workflow token that slipped through the rotation process following the TanStack npm supply-chain attack last week. In the ongoing Shai-Hulud malware campaign attributed to TeamPCP hackers, dozens of TanStack packages infected with credential-stealing code were published on the npm index, compromising developer environments, including Grafana's. When the malicious npm package was released, Grafana’s CI/CD workflow consumed it, and the info-stealer module executed in its GitHub environment, exfiltrating GitHub workflow tokens to the attackers. The company explains that it detected malicious activity resulting from compromised TanStack packages on May 1, and immediately deployed the incident response plan, which included rotating GitHub workflow tokens. However, one token was missed in the process, and the attacker used it to gain access to the company's private repositories. “We performed analysis and quickly rotated a significant number of GitHub workflow tokens, but a missed token led to the attackers gaining access to our GitHub repositories,” reads Grafana’s update. “A subsequent review confirmed that a specific GitHub workflow we originally deemed not impacted had, in fact, been compromised.” Previously, the company confirmed that the intruders stole source code, assuring there was no customer impact, and stating that the hackers would not receive a ransom payment. The continued investigation revealed that the intruder also downloaded operational information and details Grafana uses for its business. "This includes business contact names and email addresses that would be exchanged in a professional relationship context, not information pulled from or processed through the use of production systems or the Grafana Cloud platform" - Grafana The company stresses that this was not customer production data, and according to the latest evidence and investigation, no customer production systems or operations have been compromised. Grafana Labs also noted that its codebase was not modified during the incident, so the code users downloaded throughout the events is considered safe, and users are not required to take any action. If that evaluation changes based on new evidence from the ongoing investigation, Grafana Labs promised to notify impacted customers directly. Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply. The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments. Get the report
bleepingcomputer.comMay 20, 2026extracted
Anthropic Silently Patches Claude Code Sandbox Bypass
A cybersecurity researcher says Anthropic has silently patched a vulnerability that would have allowed an attacker to bypass the Claude Code network sandbox, potentially enabling data exfiltration. Claude Code’s network sandbox funnels all outbound traffic through a local allowlist proxy, silently blocking any connection to unapproved hosts. According to vulnerability researcher Aonan Guan, two Claude Code network sandbox bypasses were discovered recently. One of them, tracked as CVE-2025-66479 and discovered by a different researcher, was related to the sandbox interpreting a setting to block all outbound traffic as ‘allow everything’. This issue was fixed with an update released on November 26, 2025. The second sandbox bypass vulnerability, discovered by Guan, has been described as a SOCKS5 hostname null-byte injection issue. “The userʼs policy says allow only *.google.com. The attacker sends a hostname like attacker-host.com\x00.google.com. The filter sees the trailing .google.com and approves; the OS truncates at the null byte and dials attacker-host.com,” Guan explained. According to Guan, the vulnerability was present in the Claude Code network sandbox from October 20, 2025, when the sandbox became generally available, until the release of version 2.1.90 in April, around the time he reported it through Anthropic’s bug bounty program on HackerOne. The AI giant marked the vulnerability report as a duplicate. The researcher is displeased that Anthropic has not assigned a CVE identifier to this vulnerability and has not mentioned the issue in its release notes. Moreover, Guan noted that CVE-2025-66479 was assigned to the ‘sandbox-runtime’ library rather than Claude Code itself, and there was no warning to Claude Code users. “A team running [the vulnerable configuration] in production from October 20 through November 26 had no way to know the sandbox was effectively off, and no notice afterwards that it had ever been off. The CVE shipped against a library most Claude Code users do not know exists by name,” the researcher said. Guan recently disclosed details of a prompt injection attack method called Comment and Control. The attack worked against popular AI code security and automation tools, including Claude Code Security Review, Gemini CLI Action, and GitHub Copilot Agent. He and other researchers discovered that AI agents associated with these tools on GitHub Actions could be hijacked using specially crafted GitHub comments, including PR titles, comments, and issue bodies. In his disclosure of the Claude Code sandbox vulnerability, Guan noted that the bypass would have been particularly useful in combination with a prompt injection attack such as Comment and Control, enabling attackers to exfiltrate data, including environment variables, credentials, tokens, and infrastructure data. Contacted by SecurityWeek, Anthropic said it appreciates Guan’s work, but its security team had identified and fixed this issue before receiving the researcher’s report. The AI giant clarified that the fix was included in a public commit to the ‘sandbox-runtime’ repository on March 27 and was shipped in Claude Code 2.1.88 on March 31, before Guan submitted his report via HackerOne on April 3. Related: ‘Claw Chain’ OpenClaw Flaws Allow Sandbox Escape, Backdoor Delivery Related: OpenAI Hit by TanStack Supply Chain Attack Related: Mythos Proves Potent in Vulnerability Discovery, Less Convincing Elsewhere
securityweek.comMay 20, 2026extracted
TeamPCP breached GitHub’s internal codebase via poisoned VS Code extension
TeamPCP breached GitHub’s internal codebase via poisoned VS Code extension Following TeamPCP’s claim that they’ve breached GitHub’s own private code repositories, the Microsoft-owned company launched an investigation and confirmed the compromise. “Our current assessment is that the activity involved exfiltration of GitHub-internal repositories only. The attacker’s current claims of ~3,800 repositories are directionally consistent with our investigation so far,” GitHub stated. The source of the breach The company previously said that they have no evidence that customer information stored outside of GitHub’s internal repositories was impacted, but as the investigation is still ongoing, this might change. GitHub’s investigation revealed that the attackers accessed the internal repos after a GitHub employee installed a poisoned Visual Studio (VS) Code extension. “We removed the malicious extension version, isolated the endpoint, and began incident response immediately,” the company shared. “Critical secrets were rotated yesterday and overnight with the highest-impact credentials prioritized first. We continue to analyze logs, validate secret rotation, and monitor for any follow-on activity. We will take additional action as the investigation warrants.” Charlie Eriksen, a security researcher with Aikido Security, noted that VS Code extensions have full access to everything on the developer’s machine, including credentials, cloud keys, and SSH keys. “The day before the GitHub breach was disclosed, a completely separate extension called Nx Console, 2.2 million installs, was also briefly backdoored. The community caught that one in 11 minutes, which sounds fast until you realise how many machines auto-update in that window,” he told Help Net Security. “GitHub still hasn’t named the extension used in their breach, and blocking something malicious always depends on it being identified first.” TeamPCP continues its rampage TeamPCP (aka UNC6780) is a cybercrime group that specializes in supply chain attacks targeting open-source security utilities and AI middleware. They have previously compromised Aqua’s Trivy security scanner, CheckMarx’s KICS, the LiteLLM library, the Telnyx SDK, TanStack, MistralAI, and other packages that depended on those. They achieved some of these compromises by deploying Mini Shai-Hulud, their adapted version of a self-replicating worm first documented in 2025, which largely automates supply chain attacks by stealing CI/CD credentials and using them to publish infected versions of further packages. The hacking group is ostensibly selling the contents of the stolen GitHub repositories, and said they plan to leak them if a buyer doesn’t materialize. UPDATE (May 21, 2026, 11:10 a.m. ET): The malicious VS Code extension behind the GitHub breach is Nx Console. Subscribe to our breaking news e-mail alert to never miss out on the latest breaches, vulnerabilities and cybersecurity threats. Subscribe here!
helpnetsecurity.comMay 20, 2026extracted
GitHub Confirms Hack Impacting 3,800 Internal Repositories
Microsoft-owned code-hosting platform GitHub on Wednesday morning confirmed that approximately 3,800 internal repositories were impacted in a supply chain attack. On Tuesday, the infamous hacking group TeamPCP, known for a series of recent supply chain attacks targeting the open source software community, claimed the hack of 4,000 GitHub internal repositories. Boasting about the incident on an underground hacking forum, the threat actor claimed the theft of source code and internal orgs, offering the allegedly stolen information to any buyer willing to pay at least $50,000 for it. GitHub launched an investigation into the matter shortly after and roughly five hours later confirmed the attackers’ claims. “Our current assessment is that the activity involved exfiltration of GitHub-internal repositories only. The attacker’s current claims of ~3,800 repositories are directionally consistent with our investigation so far,” GitHub said. The code-sharing platform immediately rotated critical secrets, prioritizing highest-impact credentials first. “We continue to analyze logs, validate secret rotation, and monitor for any follow-on activity. We will take additional action as the investigation warrants,” GitHub said, promising a full incident report at a later date. The intrusion, the platform said, was the result of an employee installing a poisoned VS Code extension. GitHub did not name the extension and did not share details on the type of data the compromised employee device contained. According to Aikido Security researcher Charlie Eriksen, VS Code extensions have full access to all data on a developer’s machine, including credentials, SSH keys, cloud keys, and all other secrets. “Developer workstations are the number one target in supply chain attacks right now, and this is exactly why. TeamPCP has compromised Trivy, Checkmarx, Bitwarden CLI, TanStack, and now GitHub, all in 2026, all through developer tooling,” Aikido Security’s Mackenzie Jackson said. “A single VS Code extension on one employee’s machine was enough to get access to 3,800 internal GitHub repositories. Most security teams still have zero visibility into what extensions or packages are on their developers’ machines, or how recently they were published. That’s the blind spot these attacks keep walking through,” Jackson added. Related: TeamPCP Ups the Game, Releases Shai-Hulud Worm’s Source Code Related: OpenAI Hit by TanStack Supply Chain Attack Related: TanStack, Mistral AI, UiPath Hit in Fresh Supply Chain Attack
securityweek.comMay 20, 2026extracted
GitHub confirms breach of 3,800 repos via malicious VSCode extension
Update May 21: GitHub has now linked this breach to the TanStack npm supply-chain attack and says the employee installed a malicious version of the Nx Console extension. GitHub has confirmed that roughly 3,800 internal repositories were breached after one of its employees installed a malicious VS Code extension. The company has since removed the unnamed trojanized extension from the VS Code marketplace and has secured the compromised device. "Yesterday we detected and contained a compromise of an employee device involving a poisoned VS Code extension. We removed the malicious extension version, isolated the endpoint, and began incident response immediately," the company said. "Our current assessment is that the activity involved exfiltration of GitHub-internal repositories only. The attacker's current claims of ~3,800 repositories are directionally consistent with our investigation so far." This comes after GitHub told BleepingComputer on Tuesday evening that it was investigating claims of unauthorized access to its internal repositories and added that it has no evidence that customer data stored outside the affected repos has been affected. While GitHub has yet to attribute the breach, the TeamPCP hacker group claimed access to GitHub source code and "~4,000 repos of private code" on the Breached cybercrime forum on Tuesday, asking for at least $50,000 for the stolen data. "As always this is not a ransom, We do not care about extorting Github, 1 buyer and we shred the data on our end, it looks like our retirement is soon so if no buyer is found we will leak it free," the cybercriminals said. "If you are interested. Send your offers to the communications below, we are not interested in under 50k, the best offer will get it." TeamPCP was previously linked to massive supply chain attacks targeting developer code platforms, including GitHub, PyPI, NPM, and Docker, and, more recently, to the "Mini Shai-Hulud" supply chain campaign(which also impacted two OpenAI employees). VS Code extensions are plugins that can be installed from the VS Code Marketplace (the official store for add-ons for Microsoft's code editor) to add features or integrate tools into the editor. This isn't the first time a trojanized VS Code extension has been spotted on the marketplace, as multiple other malicious extensions with millions of installs have been used to steal developer credentials and other sensitive data over the last several years. For instance, last year, VSCode extensions with 9 million installs were pulled over security risks, and 10 more, posing as legitimate development tools, infected users with the XMRig cryptominer. Later in the year, a malicious extension with basic ransomware capabilities snuck onto the VS Code marketplace after a threat actor named WhiteCobra flooded it with 24 crypto-stealing extensions. More recently, in January, two malicious extensions advertised as AI-based coding assistants with 1.5 million installs exfiltrated data from compromised developer systems to servers in China. GitHub's cloud-based platform is now used by over 4 million organizations (including 90% of the Fortune 100) and more than 180 million developers who contribute to over 420 million code repositories. Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply. The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments. Get the report
bleepingcomputer.comMay 20, 2026extracted
Grafana GitHub Breach Exposes Source Code via TanStack npm Attack
Grafana Labs, on May 19, 2026, said an investigation into its recent breach found no evidence of customer production systems or operations being compromised. It said the scope of the incident is limited to the Grafana Labs GitHub environment, which includes public and private source code along with internal GitHub repositories. "After the initial assessment, we found that in addition to source code, the downloaded content included GitHub repositories that some Grafana Labs teams use to collaborate on and store internal operational information and other details about our business," it said. "This includes business contact names and email addresses that would be exchanged in a professional relationship context, not information pulled from or processed through the use of production systems or the Grafana Cloud platform." The open-source visualization software maker also noted that the breach originated from the TanStack npm supply chain attack orchestrated by TeamPCP, which also hit OpenAI and Mistral AI, and that it detected the activity on May 11, 2026. "We performed analysis and quickly rotated a significant number of GitHub workflow tokens, but a missed token led to the attackers gaining access to our GitHub repositories," it said. "A subsequent review confirmed that a specific GitHub workflow we originally deemed not impacted had, in fact, been compromised." The company said it subsequently received an extortion demand from an unnamed threat actor on May 16, but opted against paying the ransom as there is no guarantee that the stolen data would actually be deleted, and could act as a catalyst for future campaigns. Since then, Grafana has taken steps to rotate automation tokens, implement enhanced monitoring, audit all commits for signs of malicious activity, and bolster its overall GitHub security posture. It's worth mentioning here that a data extortion crew named CoinbaseCartel listed Grafana Labs on its dark web site on May 15, 2026. The Hacker News has contacted Grafana for comment, and we will update the story if we hear back. The development comes as GitHub said it's investigating unauthorized access to its internal repositories after the notorious threat actor known as TeamPCP listed the platform's source code and internal organizations for sale on a cybercrime forum.
thehackernews.comMay 20, 2026extracted
New Shai-Hulud malware wave compromises 600 npm packages
Threat actors earlier today published more than 600 malicious packages to the Node Package Manager (npm) index as part of a new Shai-Hulud supply-chain campaign. Most of the affected packages are in the @antv ecosystem, which includes libraries for charting, graph visualization, building flowcharts, and mapping. However, popular packages outside this namespace have also been compromised. One-hour attack As in the previous Shai-Hulud campaign impacting TanStack and Mistral packages, the payload collects secrets from developer and CI/CD environments and exfiltrates them over the Session P2P network to complicate detection and takedown efforts. The threat actor also used GitHub as a fallback exfiltration mechanism and published stolen data in repositories under victims' accounts, when tokens used for publishing were found. According to application security company Socket, the hackers published 639 malicious versions across 323 unique packages in about one hour on May 19, between 01:56 UTC and 02:56 UTC. The attack started with compromising the npm account atool, which publishes the packages in the @antv namespace. Some of the impacted libraries include: echarts-for-react @antv/g2 @antv/g6 @antv/x6 @antv/l7 @antv/g2plot @antv/graphin timeago.js size-sensor canvas-nest.js Endor Labs researchers highlight that some of the packages (e.g., timeago.js, size-sensor, and jest-canvas-mock) had not received a legitimate update for a long time and were less likely to have their OIDC trusted publishing security feature configured. For instance, although the jest-canvas-mock still has 10 million monthly downloads, it has been dormant for about 3 years. Socket researchers maintain a list of package artifacts affected by all Shai-Hulud attacks, which has grown to more than 1,000 entries. The Shai-Hulud campaigns started last September and continue to affect multiple software ecosystems, such as npm, PyPI, and Composer, to a lesser degree. Publishing to GitHub The malware compromises maintainer accounts or publishing tokens to push legitimate packages with malicious code that steals developer and CI/CD secrets, and can spread to other projects using the stolen credentials. The latest wave involves the injection of a heavily obfuscated ‘index.js’ payload that attempts to steal GitHub, npm, cloud, Kubernetes, Vault, Docker, database, and SSH credentials. It primarily targets developer workstations and CI/CD environments, including GitHub Actions, GitLab CI, Jenkins, Azure DevOps, CircleCI, Vercel, Netlify, and other build platforms. The stolen data is serialized, Gzip-compressed, AES-256-GCM-encrypted, and RSA-OAEP-wrapped to make network inspection harder. When GitHub credentials are available, the malware uses the GitHub API to automatically create new repositories under the victim’s account and upload the stolen data to them. Repos published as a result of this attack have a Readme file with the string niaga og ew ereh :duluh-iahs, which is the reverse of Shai-Hulud: Here We Go Again, a phrase used in the Shai-Hulud malware leak last week. A report from software security platform Aikido notes that there are more than 2,700 rogue repositories on GitHub matching the campaign’s markers. A search before publishing this article shows that there are currently at least 2,900 GitHub repositories generated by the latest Shai-Hulud supply-chain campaign. The main exfiltration channel, though, is to filev2.getsession[.]org/file/ via the Session P2P network. Microsoft also shared the t.m-kosche.com endpoint for shipping the stolen credentials. "On the wire this is end-to-end-encrypted traffic on TCP/443, indistinguishable from legitimate Session app traffic at the network layer. There is no traditional C2 [command-and-control] endpoint to block by hostname or IP," Endor Labs researchers say. Legit-looking package One key new addition that Endor Labs spotted in this Shai Hulud variant is its ability to generate valid Sigstore provenance attestations by abusing OpenID Connect (OIDC) tokens from compromised CI environments and submitting them to Fulcio and Reko. A similar capability was observed in the payload delivered in the TanStack attack attributed to TeamPCP, when the threat actor published malicious package versions with verifiable Supply-chain Levels for Software Artifacts (SLSA) provenance attestation. As a result, malicious npm packages may appear legitimately signed and pass standard provenance verification checks despite containing credential-stealing malware. The self-propagation capability is present in this attack too. The malware validates stolen npm tokens, enumerates packages owned by the victim, downloads the tarballs, injects the malicious payload, and republishes infected packages with bumped version numbers. Given that Shai Hulud's code was recently leaked on GitHub by the TeamPCP threat group and has already been used in attacks, attribution of the new Shai-Hulud campaign is more difficult. Persistence via VS Code and Claude Code Socket says this variant differs technically from earlier Mini Shai-Hulud payloads but shares the same operational characteristics. “The AntV payloads differ from earlier Mini Shai-Hulud artifacts such as TanStack’s router_init.js and Intercom-related router_runtime.js payloads,” explains Socket. “The AntV sample uses a root-level index.js, a different primary C2 endpoint, and a smaller payload body. However, the core operational model is consistent.” Aikido Security confirms that while the core model is the same, there are some differences. The payload is now smaller, and there is persistence through backdoors planted in VS Code and Claude Code configurations. The researchers warn that this may indicate that "the attacker is thinking about what happens after the initial compromise gets cleaned up." The general recommendation for developers who downloaded any of the infected npm packages is to immediately remove or downgrade to a known good version published before May 18, and then revoke and rotate all exposed credentials (e.g., GitHub, cloud tokens, SSH keys). Reports on the attack from application security companies Socket, Endor Labs, Aikido Security, and Step Security include indicators of compromise along with detection, remediation, and mitigation advice that defenders can use to protect development environments. [UPDATE: 10:31 EST]: Article updated with information from Aikido Security and Microsoft. Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply. The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments. Get the report
bleepingcomputer.comMay 19, 2026extracted
Attacchi cyber contro la supply chain del software, colpita anche OpenAI
Tra i progetti sotto attacco dei cyber criminali, coinvolta anche OpenAI. Una nuova ondata di attacchi informatici contro la supply chain del software ha colpito diversi progetti open source utilizzati da decine di aziende tecnologiche. Gli hacker criminali hanno preso il controllo di alcuni aggiornamenti e diffuso versioni malevoli progettate per installare malware sui sistemi degli sviluppatori. Tra le aziende coinvolte figura anche OpenAI. Dopo un’indagine interna, tuttavia, la società ha dichiarato di non aver trovato “alcuna prova che ci sia stata la consultazione dei dati degli utenti di OpenAI“. Né, “che i sistemi di produzione o la proprietà intellettuale siano stati compromessi o che sia avvenuta l’alterazione del software”. Secondo OpenAI, “i dispositivi dei dipendenti sono stati compromessi attraverso un precedente attacco contro TanStack“, una popolare libreria open source. Il suo impiego serve per lo sviluppo di applicazioni web. Pubblicate 84 versioni malevole in pochi minuti Due lunedì fa, secondo TechCrunch, TanStack ha reso pubblici i dettagli dell’incidente. E ha spiegato che gli hacker sono riusciti a pubblicare 84 versioni infette del software nell’arco di appena sei minuti. Le versioni compromesse contenevano malware progettati per rubare credenziali dai computer sui quali il s’installava il software e per propagarsi automaticamente verso altri sistemi. OpenAI ha spiegato di aver rilevato accessi non autorizzati e furto di credenziali all’interno di “un numero limitato di repository di codice sorgente interni”. L’azienda ha precisato che c’è stata la sottrazione solo di “materiale limitato relativo alle credenziali”. Tuttavia, poiché i repository interessati contenevano certificati digitali utilizzati per firmare i prodotti software di OpenAI, la stessa azienda ha deciso di sostituire preventivamente tali certificati. Questa operazione richiederà agli utenti MacOS di aggiornare l’applicazione. “Non abbiamo trovato prove di compromissione o rischi per le installazioni software esistenti”, ha sottolineato OpenAI. Gli attacchi alla supply chain diventano sempre più frequenti Non è ancora chiaro chi sia il responsabile dell’attacco contro TanStack. In passato, alcuni attacchi simili sono stati attribuiti a un gruppo di hacker criminali noto come TeamPCP. Quest’ultimo, a sua volta, era finito nel mirino di altre campagne informatiche. Negli ultimi mesi, però, diversi gruppi criminali hanno utilizzato delle modalità simili contro progetti open source molto diffusi. A marzo, gruppi affiliati alla Corea del Nord avevano compromesso Axios, un noto strumento di sviluppo software, distribuendo malware che avrebbe potuto colpire milioni di sviluppatori. A maggio, invece, diversi hacker cinesi sarebbero stati responsabili di un attacco analogo contro migliaia di computer Windows che utilizzavano Daemon Tools. Si tratta di un software per la gestione di immagini disco. Perché questi attacchi preoccupano? Gli esperti cyber, in relazione agli attacchi alla supply chain del software, li hanno definiti come “particolarmente insidiosi perché non prendono di mira direttamente una singola azienda“. Al contempo, gli hacker criminali compromettono progetti open source largamente utilizzati dagli sviluppatori e distribuiscono aggiornamenti infetti mascherati da normali update. In questo modo, con una sola intrusione, i criminali possono potenzialmente colpire decine o centinaia di organizzazioni contemporaneamente. Diffondono malware e accessi malevoli su larga scala, sfruttando Internet. Questo tipo strategia sta diventando sempre più comune, soprattutto perché molte aziende moderne dipendono da librerie open source integrate nei propri sistemi e applicazioni.
cybersecitalia.itMay 19, 2026extracted
Compromised Nx Console 18.95.0 Targeted VS Code Developers with Credential Stealer
Cybersecurity researchers have flagged a compromised version of the Nx Console extension that was published to the Microsoft Visual Studio Code (VS Code) Marketplace. The extension in question is rwl.angular-console (version 18.95.0), a popular user interface and plugin for code editors like VS Code, Cursor, and JetBrains. The VS Code extension has more than 2.2 million installations. "Within seconds of a developer opening any workspace, the compromised extension silently fetched and executed a 498 KB obfuscated payload from a dangling orphan commit hidden inside the official nrwl/nx GitHub repository," StepSecurity researcher Ashish Kurmi said. The payload is a "multi-stage credential stealer and supply chain poisoning tool" that harvests developer secrets and exfiltrates them via HTTPS, the GitHub API, and DNS tunneling. It also installs a Python backdoor on macOS systems that abuses the GitHub Search API as a dead drop resolver for receiving further commands. In an advisory issued Monday, the maintainers of the extension said the root cause has been traced to one of its developers, whose machine was compromised in a recent security incident that leaked their GitHub credentials. Although the nature of the prior "incident" was not disclosed, the developer's credentials have since been temporarily revoked. The access afforded by the credentials is said to have been abused to push an orphaned, unsigned commit to nrwl/nx, which introduces the stealer malware. The malicious action is triggered as soon as a developer opens any workspace in VS Code, leading to the installation of the Bun JavaScript runtime to run an obfuscated "index.js" payload. The malware runs checks to avoid infecting machines likely located in the Russian/CIS time zones and launches itself as a detached background process to kick off the credential harvesting workflow, allowing it to retrieve sensitive data from 1Password vaults and Anthropic Claude Code configurations, and secrets associated with npm, GitHub, and Amazon Web Services (AWS). "One capability that stands out: the payload contains full Sigstore integration, including Fulcio certificate issuance and SLSA provenance generation," StepSecurity said. "Combined with stolen npm OIDC tokens, this means the attacker could publish downstream npm packages with valid, cryptographically signed provenance attestations, making the malicious packages appear as legitimate, verified builds." The Nx team also acknowledged a "few users were compromised" as a result of this breach. Besides urging users to update to 18.100.0 or later, the maintainers have published the following indicators of compromise - Nx Console version 18.95.0 was installed during the exposure window between May 18, 2026, at 2:36 p.m. CEST and 2:47 p.m. CEST. Presence of files like ~/.local/share/kitty/cat.py, ~/Library/LaunchAgents/com.user.kitty-monitor.plist, /var/tmp/.gh_update_state, or /tmp/kitty-*. Presence of any of the following running processes: a python process running cat.py and a process with __DAEMONIZED=1 in its environment. Affected users are recommended to terminate the aforementioned processes, delete artifacts on disk, and rotate all credentials reachable from the affected machine, including tokens, secrets, and SSH keys. The development marks the second time the Nx ecosystem has been targeted within a year. In August 2025, several npm packages were infected by a credential stealer as part of a supply chain attack campaign named s1ngularity. Unlike the previous iteration, the latest attack targets the VS Code extension. Malicious npm Packages Galore The findings coincide with the discovery of various malicious packages in the open-source repositories - iceberg-javascript, supabase-javascript, auth-javascript, microsoft-applicationinsights-common, and ms-graph-types: Five npm packages containing a hidden ELF binary that backdoors Claude Code sessions to steal developer credentials. noon-contracts: an npm package that impersonates a Noon Protocol smart contract SDK to exfiltrate SSH keys, crypto wallet private keys, AWS credentials, Kubernetes secrets, all .env files, shell history, Docker/Git/npm tokens, and browser wallet storage paths. martinez-polygon-clipping-tony: a trojanized fork of martinez-polygon-clipping that uses a postinstall hook to download a 17MB PyInstaller-packed Windows remote access trojan (RAT) that uses Telegram for command-and-control (C2) for remote shell execution, screenshot capture, file upload/download, and arbitrary Python execution. common-tg-service: an npm package that contains functionality to take over a victim's Telegram account while masquerading as "Common Telegram service for NestJS applications." exiouss: an npm package that bundles a ChatGPT and OpenAI session cookie stealer targeting web browsers like Google Chrome, Microsoft Edge, and Brave. k8s-pod-checker, dev-env-setup, and node-perf-utils: three npm packages part of the kube-health-tools cluster that install a large language model (LLM) proxy service on the victim's machine, allowing the attacker to route LLM traffic through the compromised server A coordinated credential harvesting campaign orchestrated by an Indonesian-speaking threat actor using a set of 38 npm packages that leverages dependency confusion as a way to trick CI/CD pipelines to resolve malicious public packages ahead of legitimate private ones associated with Apple, Google, and Alibaba, among others. An unusual campaign wherein seven npm packages under the @hd-team organization have been found to act as a stager for configurations used by a Chinese sports gambling and pirated streaming platform named Douqiu to determine the backend servers to connect to. Update On May 20, 2026, the Nx team disclosed that it's working with Microsoft and GitHub to understand the impact following the publication of the malicious Nx Console version 18.95.0 by unknown threat actors. "Initially, Microsoft indicated to us that there were 28 installs of the malicious version 18.95.0," Jeff Cross, co-founder of Narwhal Technologies, the company behind nx.dev, said. "Based on our own analytics for the compromised version, we currently believe the number of users who received the malicious package may be significantly higher; potentially over 6,000 installs." All the installs originated from VS Code, according to an updated advisory. As many as 41 installs came from the Open VSX registry. Nx Console Hack Stemmed from TanStack Supply Chain Attack In a fresh update shared on May 21, 2026, the Nx team officially acknowledged that one of its developers was compromised by a recent supply chain compromise targeting TanStack, causing their GitHub credentials to be leaked. "This allowed the attacker to run workflows on our GitHub repository as a contributor," the maintainers said. In a post-mortem published on May 21, 2026, the Nx team warned that anyone who had Nx Console with auto-update enabled during the exposure window should assume compromise. The malicious version was published on May 18, 2026, between 12:30 and 1:09 p.m. UTC. The extension was live in the Visual Studio Marketplace package for about 11 minutes and nearly 36 minutes in Open VSX. "The attacker published the malicious version as a legitimate Nx core contributor," the maintainers said. "A credential-stealing payload that arrived through the TanStack supply-chain compromise had silently exfiltrated that contributor's GitHub CLI OAuth token seven days earlier. Between credential theft on May 11 and the marketplace publish on May 18, the attacker was active in our GitHub repos for seven days without detection." Following the incident, the Nx team has rolled out a number of changes, including requiring approval to publish Nx Console, enhanced monitoring GitHub audit log for suspicious events, for example workflow-run deletions, and pinning GitHub Action SHAs instead of floating refs (e.g., @v6, @main) across all repositories.
thehackernews.comMay 19, 2026extracted
TeamPCP Supply Chain Campaign: Activity Through 2026-05-17, (Mon, May 18th)
Since the last update, the TeamPCP supply chain campaign produced its loudest stretch since the March Trivy disclosure: an officially confirmed Checkmarx Jenkins plugin compromise and a new self-spreading Mini Shai-Hulud worm across npm and PyPI. Bottom line up front Two TeamPCP events broke within 48 hours of each other and doubled attention on the campaign. Checkmarx confirmed its Jenkins AST plugin was trojanized, its third compromise in three months, validating an earlier single-researcher claim. In parallel, a new Mini Shai-Hulud worm poisoned roughly 170 npm and PyPI packages (42 @tanstack packages in about six minutes, downloads above 500 million) and was the first documented npm malware shipping with valid SLSA Build Level 3 provenance, plus a 1-in-6 disk-wipe payload on Israeli and Iranian locale hosts. NHS England issued the campaign's first government alert; CISA stayed silent. Action: audit CI for the indicators below, stop trusting provenance alone, pin and lockfile-verify dependencies. How this developed The period opened quiet and derivative: the lead story was PCPJack, a rival worm that evicts TeamPCP before stealing credentials, alongside a single-researcher claim that a Checkmarx Jenkins plugin had been backdoored. Days later it turned loud: Checkmarx officially confirmed that exact Jenkins compromise, and a new Mini Shai-Hulud worm hit the npm and PyPI ecosystems hard. The through-line is escalation: an unconfirmed rumor became a confirmed incident, and the campaign moved from a quiet competitor-eviction story to a high-impact, signed-malware supply chain wave. What changed, by theme Checkmarx Jenkins plugin: an unconfirmed claim, then official confirmation Takeaway: a single-researcher claim, explicitly logged as unconfirmed at the time, was confirmed by Checkmarx four days later. On 2026-05-09, researcher Berk Albayrak reported on X that the Checkmarx Jenkins AST scanner plugin had been backdoored. No Tier 1 outlet, no vendor, and no Checkmarx statement corroborated it at the time, so it was carried as information-only pending confirmation. On 2026-05-11 Checkmarx published an official update acknowledging that a tampered plugin (version 2026.5.09) had been published to the Jenkins Marketplace, with an exposure window of 2026-05-09 01:25 UTC to 2026-05-10 08:47 UTC. The Register, BleepingComputer, SecurityWeek, and The Hacker News carried it the same day. This is the third TeamPCP compromise of Checkmarx in three months, and the malicious plugin was installed by several hundred Jenkins controllers. Last known-good build: 2.0.13-829.vc72453fa_1c16 (2025-12-17). Remediated builds (both 2026-05-09): 2.0.13-848.v76e89de8a_053 and 2.0.13-847.v08c0072b_2fd5. The Mini Shai-Hulud TanStack wave Takeaway: a self-spreading worm poisoned roughly 170 npm and PyPI packages, and the publishes came from TanStack's own trusted release pipeline. Starting 2026-05-11 at 19:20 UTC, the worm published 84 malicious artifacts across 42 @tanstack npm packages in about six minutes, including @tanstack/react-router (roughly 12 million weekly downloads). It then propagated to Mistral AI, UiPath, OpenSearch, Guardrails AI, and roughly 170 packages across npm and PyPI, with combined cumulative downloads above 500 million. Primary technical disclosures came from Wiz and StepSecurity, with Snyk and BleepingComputer adding scope and counts. The tracking identifier is CVE-2026-45321 (CVSS 9.6 per The Hacker News; advisory GHSA-g7cv-rxg3-hmpx per Snyk; Wiz and StepSecurity did not assign a CVE). A reported operator error matters for defenders: per Wiz's 2026-05-13 update, the credential stealer is non-functional in the @uipath and @mistralai variants because the payload is reassembled incorrectly there, which limits the harvest from the largest non-TanStack targets. Signed malware: the SLSA Build Level 3 first Takeaway: this is the first documented npm supply chain attack shipping malware with valid SLSA Build Level 3 provenance, so "has provenance" no longer means "not malicious." Per Wiz, StepSecurity, and Snyk, the malicious versions carried valid SLSA Build Level 3 provenance attestations. Analysts assess this is novel and material: the attacker never stole maintainer npm credentials. Instead the malicious versions were published by TanStack's legitimate release pipeline using its own trusted OIDC identity, so the provenance is genuine and proves only that TanStack's pipeline built the artifact, not that the artifact is safe. The practical consequence: provenance and attestation checks alone do not detect this class of attack. Pinning exact versions and verifying lockfile hashes against a known-good baseline are still required. Destructive and persistent: a 1-in-6 wipe and AI-agent persistence Takeaway: this wave added a sabotage payload and a developer-tool persistence mechanism not seen in earlier Mini Shai-Hulud waves. BleepingComputer (Bill Toulas) reported a probabilistic sabotage mechanism with a 1-in-6 chance of running a recursive wipe on systems matching Israeli or Iranian locales, a new behavior class for this malware family. Expel reported that the worm injects persistence hooks into developer tooling, specifically .vscode/tasks.json and ~/.claude/settings.json, so it survives reboots on developer endpoints. Defenders in the affected regions should treat the wipe behavior as a credible data-loss risk, and all teams should inspect those two file locations on engineer machines. This destructive, geopolitically-targeted behavior is not new to the campaign. The original TeamPCP campaign report documented a conditional wiper in the earlier CanisterWorm payload that checked whether the infected system's timezone was set to Iran or its default language was Farsi, and on a match attempted to destroy data, wiping Kubernetes clusters node by node, or the local machine if no cluster was found. The current mechanism is a different payload and uses a probabilistic 1-in-6 trigger rather than a deterministic locale check, but it continues the same documented pattern of region-targeted data destruction layered onto a credential-theft operation. PCPJack: a rival worm evicting TeamPCP Takeaway: the first publicly documented actor to hunt and remove TeamPCP before stealing credentials, assessed with moderate confidence as a former affiliate. On 2026-05-07 SentinelLABS disclosed PCPJack, a cloud worm that scans for exposed Docker, Kubernetes, Redis, MongoDB, and RayML services, exploits five vulnerabilities for initial access (CVE-2025-29927 Next.js middleware authentication bypass, CVE-2025-55182 Next.js Server Actions deserialization, CVE-2026-1357 WPVivid arbitrary file upload, CVE-2025-9501 W3 Total Cache RCE, CVE-2025-48703 CentOS Web Panel command injection), then kills TeamPCP processes and removes TeamPCP artifacts before harvesting npm, GitHub, and cloud credentials. SentinelLABS assesses with moderate confidence that PCPJack may be operated by a former TeamPCP affiliate, based on tradecraft overlap with the December 2025 PCPCat phase. BleepingComputer, SecurityWeek, and The Register covered it within 36 hours. A follow-up on 2026-05-13 continued the PCPJack story. Monetization stays frozen: Vect and CipherForce Takeaway: the affiliated extortion channels stayed inactive through the period, supporting the view that TeamPCP's ransomware monetization is impaired. Direct fetches of the ransomware.live Vect tracker show the victim count unchanged at 25, with the most recent posting dated 2026-04-15, leaving Vect operationally quiet for roughly 32 days by 2026-05-15. CipherForce remained inactive at roughly 84 days, with 6 victims unchanged. Combined with the earlier Check Point disclosure of a cryptographic flaw in Vect 2.0, this reinforces the prior assessment that TeamPCP is currently monetizing through supply chain credential theft rather than affiliate ransomware. Institutional response: NHS moved, CISA did not Takeaway: a meaningful first government alert, against continued and now increasingly anomalous US federal silence. NHS England Digital issued cyber alert cc-4781 on 2026-05-12, the first government advisory of the campaign to name the affected packages. Against that, the meaningful negatives still hold: CISA did not issue a standalone TeamPCP advisory, did not add CVE-2026-45321 to the Known Exploited Vulnerabilities catalog within the window, and has not named the operator. No Mandiant or Google Threat Intelligence Group named-actor product on the TanStack wave was published; technical attribution to TeamPCP rests on StepSecurity, Wiz, and Snyk. OpenAI published a corporate response titled "Our response to the TanStack npm supply chain attack". How the TanStack compromise worked (short version) The attacker did not steal npm credentials. They abused CI: a pull_request_target workflow ran fork-controlled code on a privileged GitHub Actions runner, GitHub Actions cache poisoning was staged through a renamed attacker fork, and the pipeline's OIDC token was extracted from runner process memory. The malicious package versions were then published by TanStack's own trusted release identity, which is why the provenance attestations are valid. Two staged attacker forks were used and should not be conflated: github[.]com/voicproducoes/router (created 2026-05-10, per StepSecurity) and github[.]com/zblgg/configuration (account zblgg, commits 2026-05-11 19:20 to 19:26 UTC, per Wiz and Snyk). What defenders should do now Inventory installs of @tanstack/* and the named packages (mistralai, guardrails-ai, @opensearch-project/opensearch, @uipath/, @squawk/mcp, @tallyui/) created during the compromise windows below; treat matching installs as suspect. Rotate npm, GitHub, cloud provider, and CI/CD tokens that were exposed to affected CI runners. Stop treating SLSA provenance or attestation as sufficient; pin exact versions and verify lockfile hashes against a known-good baseline. Block and alert on the indicators below at egress, including the C2 IP and domain and the Session messenger exfiltration nodes. Inspect developer endpoints for persistence in .vscode/tasks.json and~/.claude/settings.json . Audit GitHub Actions for pull_request_target running on forks and for cache-poisoning exposure. For the Checkmarx Jenkins AST plugin, confirm you are on a remediated build (2.0.13-848.v76e89de8a_053 or 2.0.13-847.v08c0072b_2fd5) and not the tampered 2026.5.09. Compromise time windows (for CI self-check) Checkmarx Jenkins AST plugin tampered version exposure: 2026-05-09 01:25 UTC to 2026-05-10 08:47 UTC. TanStack malicious npm publishes: 2026-05-11 19:20 UTC to 19:26 UTC; broader worm propagation across npm and PyPI continued through 2026-05-13. Indicators of compromise Watch items CISA action: a Known Exploited Vulnerabilities addition for CVE-2026-45321, a standalone TeamPCP advisory, or an emergency directive. The continued federal silence on a campaign of this profile is itself the watch item. Attribution: a Mandiant or Google Threat Intelligence Group named-actor product on the TanStack wave (the operator is tracked as UNC6780); current technical attribution rests only on StepSecurity, Wiz, and Snyk. Maintainer disclosures: postmortems or breach notifications from TanStack, Mistral AI, or Guardrails AI, including any SEC or privacy-law filings. A formal Checkmarx postmortem naming TeamPCP, given this is the third Checkmarx compromise in three months. Any verified wipe event, or a CERT-IL or CERT-IR advisory, tied to the locale-targeted destructive payload. Any patched Vect 2.1 release fixing the disclosed Vect 2.0 cryptographic flaw, or a CipherForce return after the prolonged freeze.
isc.sans.eduMay 18, 2026extracted
TanStack weighs invitation-only pull requests after supply chain attack
ai and ML AI slop is good for business if you know what you're doingYour irresponsibility is someone else's opportunity SAAS Salesforce partners not seeing meaningful revenue from Agentforce AI platform, report saysShow us the money ai and ml AI companies are burning books, advocates complain to FTCFahrenheit 203, the temperature GPUs stop gorging on literature DEVOPS Go updates may delight diehard gophers but displease AI overlordsv 1.27 expands generics to support methods EDGE AND IOT Waymo has designed a robocar chip to stay ahead of Tesla5 nm ML accelerators promise 1,000+ TOPS, ultra-low latency Security Russians are posing as Signal support to launch phishing attacksPLUS: US takes down Iranian propaganda sites; Marketing company asks 'Why Do We Have Your Information?' And more! Security Microsoft patches failed to fix on-prem SharePoint, which is now under zero-day attackPLUS: China upgrades smartphone surveillance tools; Ring eases anti-snooping stance; and more Black Hat and DEF CON DEF CON Franklin project enlists hackers to harden critical infrastructureVoting village reports have been so successful, says Jeff Moss, that the whole of DEF CON will now be included Security EQT buys majority share in Swiss cybersecurity biz AcronisWent at equivalent of $3.5B+ valuation for entire firm, though portion sold not specified Malware Month Ten years since the first corp ransomware, Mikko Hyppönen sees no end in sightOn the plus side, infosec's a good bet for a long, stable career FOSS smashed one Microsoft monopoly. After 20 years of failure, it's time to smash anotherWord up GNOME can look like Windows – and Flashback can do it without extensionsNew 'Simple-taskbar' is an option, but there's a simpler, stabler way A moment of silence, please, for the final release of Debian on x86-32New Debian versions hit FOSSland in the form of 13.6 and 12.15 Baddies caught exploiting extensions bugs with perfect 10 scores on vulnerable Joomla websitesFlaws in iCagenda, Balbooa Forms extensions can impact open source CMS that powers a million sites worldwide Frame: A new X11 server – implemented directly in assemblyJoins yserver, Phoenix, and of course XLibre – and outlier Arcan Cinnamon 6.8 will support Wayland – if you want itNext version of Linux Mint’s desktop has both kinds of display server
theregister.comMay 18, 2026extracted
Loading 23 more…