logo

Malware crew TeamPCP open-sources its Shai-Hulud worm on GitHub

ID: e9e8621f-bf9e-532d-a80c-f342180f65e9

STIX ID: report--e9e8621f-bf9e-532d-a80c-f342180f65e9

Feed Name: The Register (Security)

Threat Score
75/100

Date Published: 2026-05-13

Date Updated: 2026-05-13

...
...

TeamPCP has publicly released the Shai-Hulud worm on GitHub under an MIT license, and repositories have already been forked and modified; the worm targets npm packages, seeks AWS/GCP/Azure/GitHub credentials, and propagates by publishing poisoned code (with some variants wiping infected environments). Researchers observed the malware previously (September 2025, with a stronger variant in November) and note that open-sourcing has enabled rapid copycat development while GitHub had not yet intervened.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.