logo

Mini Shai-Hulud: Frequently asked questions about the TeamPCP npm and PyPI supply chain campaign

ID: 87c6b71b-073f-57d8-80b9-837f147695c5

STIX ID: report--87c6b71b-073f-57d8-80b9-837f147695c5

Feed Name: Tenable Blog

Threat Score
90/100

Date Published: 2026-05-21

Date Updated: 2026-06-04

Author: Research Special Operations

...
...

**Mini Shai-Hulud (TeamPCP)**: A high-impact, active supply-chain campaign using a self-propagating worm to poison npm and PyPI packages, harvest extensive developer and cloud credentials (including OIDC tokens), and publish trojanized packages via compromised CI/CD pipelines — notably defeating SLSA Build Level 3 provenance attestations and impacting high-profile organizations (OpenAI, Mistral AI, GitHub, EU entities); Tenable provides IOCs, CVE-2026-45321 context, and prioritized remediation guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.