wiz · Crawled Aug 6, 2026

Cloud Threat Highlights: H1 2026

7 IoCs 4 Actors 1 Malware
Read original article ↗

AI Summary

In H1 2026, a surge in cloud-based threats was driven by aggressive software supply-chain attacks, particularly by the group TeamPCP, which compromised developer toolchains across npm, PyPI, and VSCode extensions to steal credentials and propagate across cloud environments. TeamPCP's malware evolved to exploit CI misconfigurations, extract OIDC tokens, and deploy wipers with Dune-themed taunts. North Korea's UNC1069 conducted parallel campaigns, trojanizing the axios package and compromising over 140 @mastra-related packages. The open-sourced Shai-Hulud worm enabled follow-on attacks like IronWorm, which used Rust-based binaries and eBPF rootkits for stealth. A new extortion group, JINX-0163, emerged, targeting cloud identities across AWS, Azure, and GCP to steal secrets and enable ransom threats via the alias 'FulcrumSec'.

AI-extracted · verify before operational use

Extracted Entities 5 found

Indicators of Compromise 7 extracted

Type Value Detail
GitHub Repo TeamPCP/Shai-Hulud Details →
Filename .claude/unicorn Details →
Package keyv Details →
Package cacheable Details →
Package [email protected] Details →
Package @ctx/nightly-build Details →
Package @redhat-cloud-services/* Details →

MITRE ATT&CK TTPs 24 techniques