logo

New Mini-Shai-Hulud Wave Targets NPM, PyPi Packages and VSCode Extension (Campaign)

ID: daaa99e0-20f3-5c05-ba8b-f5da5c18d003

STIX ID: report--daaa99e0-20f3-5c05-ba8b-f5da5c18d003

Feed Name: Wiz Cloud Threat Landscape

Threat Score
88/100

Date Published: 2026-05-18

Date Updated: 2026-05-20

Author: [email protected] (Wiz Threat Research)

...
...

Researchers identified a broad TeamPCP-linked supply-chain campaign that delivered malicious NPM and PyPI packages, compromised GitHub Actions, and trojanized a VSCode extension to target developer, cloud, and CI/CD environments. The activity included credential harvesting and exfiltration (via public GitHub repositories with RSA-encrypted data), installation of backdoors (e.g., ~/.local/share/kitty/cat.py and pgmonitor.py), propagation using AWS SSM and kubectl exec, and a conditional destructive routine with a potential rm -rf/* trigger under specific geolocation checks.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.