TeamPCP Supply Chain Campaign: Activity Through 2026-05-17, (Mon, May 18th)

Source: SANS Internet Storm Center  ·  Category: Supply Chain


TeamPCP supply chain campaign confirmed Checkmarx Jenkins plugin compromise and Mini Shai-Hulud worm on npm/PyPI. Law firms using Jenkins, npm, or PyPI must verify plugin versions, scan build pipelines, and rotate credentials immediately.

→ Read the full article

Read more