- Shai-HuludWorm deployed by TeamPCP to infect developer devices in TanStack supply chain attack
ThreatNoir Afternoon Brief — May 15
Afternoon Review in IT Security — May 15, 2026
The threat landscape continues to evolve with increased sophistication in supply chain attacks, phishing campaigns targeting enterprise cloud environments, and coordinated efforts by state-linked threat actors. Today's security briefing highlights critical incidents affecting major technology companies and critical infrastructure sectors, alongside emerging malware distribution tactics that pose significant risks to organizational security postures.
OpenAI Hit by TanStack Supply Chain Attack
OpenAI has fallen victim to a supply chain attack that resulted in the compromise of two employee devices and the theft of credential material from OpenAI code repositories. The incident underscores the persistent vulnerability of high-profile technology companies to sophisticated supply chain threats. Source: OpenAI Hit by TanStack Supply Chain Attack
The attack involved the Shai-Hulud malware, demonstrating how threat actors continue to leverage supply chain vulnerabilities to gain access to sensitive systems and intellectual property. This incident highlights the critical need for enhanced monitoring of dependency management and code repository access controls across the technology sector.
CalPhishing Scam Uses EvilTokens Kit, Outlook Invites to Steal M365 Sessions
A sophisticated phishing campaign is actively exploiting Outlook calendar invites and device code phishing techniques to steal Microsoft 365 session tokens and bypass multi-factor authentication protections. The attack leverages the EvilTokens kit and ConsentFix malware to compromise enterprise accounts and gain unauthorized access to organizational cloud environments. Source: CalPhishing Scam Uses EvilTokens Kit, Outlook Invites to Steal M365 Sessions
This campaign represents a significant evolution in cloud-focused attacks, as threat actors exploit legitimate communication channels and device authentication flows to circumvent traditional security controls. Organizations utilizing Microsoft 365 should implement additional verification procedures for calendar invitations and monitor for suspicious device code authentication attempts.
TeamPCP Ups the Game, Releases Shai-Hulud Worm's Source Code
The hacking group TeamPCP has released the source code for the Shai-Hulud worm and is actively encouraging other threat actors to utilize the code in supply chain attacks. The group is reportedly offering monetary rewards to incentivize the weaponization and deployment of the malware across target organizations. Source: TeamPCP Ups the Game, Releases Shai-Hulud Worm's Source Code
The open-source distribution of Shai-Hulud represents a troubling trend in the threat landscape, as it democratizes access to sophisticated supply chain attack capabilities. The financial incentives offered by TeamPCP suggest a coordinated effort to expand the scope and frequency of supply chain compromises against critical technology infrastructure.
FamousSparrow Targeted Oil and Gas Industry via MS Exchange Server Exploit
Bitdefender Labs has identified a targeted campaign by the China-linked hacking group FamousSparrow against an Azerbaijani energy company, leveraging the ProxyNotShell Microsoft Exchange Server exploit. The attack chain involved multiple malware components including Deed RAT, Mofu loader, Terndoor, and vmflt.sys, demonstrating a sophisticated multi-stage infection process. Source: FamousSparrow Targeted Oil and Gas Industry via MS Exchange Server Exploit
This campaign highlights the continued targeting of critical infrastructure sectors by state-linked threat actors, with a focus on energy companies that play vital roles in regional economic stability. The use of advanced malware toolsets and exploitation techniques underscores the elevated threat level facing the oil and gas industry and the necessity for comprehensive patch management and network segmentation strategies.
The convergence of supply chain attacks, cloud-focused phishing campaigns, and critical infrastructure targeting reflects an increasingly aggressive threat environment. Organizations across all sectors must prioritize enhanced monitoring, rapid patch deployment, and advanced authentication mechanisms to mitigate the evolving risks presented by these coordinated threat campaigns.
Sources & IOCs
Source articles and extracted indicators (defanged where appropriate).
- EvilTokensPhishing kit sold on Telegram used to automate session token theft and device code phishing attacks
- ConsentFixDevice code phishing technique used to steal M365 session tokens instead of passwords
- Shai-HuludWorm used in supply chain attacks; source code released by TeamPCP on GitHub
- Deed RATBackdoor deployed via DLL sideloading (lmiguardiandll.dll) and updated in third wave
- vmflt.sysRootkit driver deployed via Terndoor to establish god-mode control
- Mofu loaderObfuscated stager used to evade antivirus and hide malware instructions in memory
- TerndoorMalware deployed in second wave; installed rootkit driver vmflt.sys for system-level access