logo

TeamPCP Open-Sources “Shai-Hulud” AI Supply Chain Malware, Hitting NPM Fleet

ID: a35ecab1-658c-52d7-9ec7-40d51e198783

STIX ID: report--a35ecab1-658c-52d7-9ec7-40d51e198783

Feed Name: securityonline.info

Threat Score
78/100

Date Published: 2026-05-19

Date Updated: 2026-05-19

Author: Ddos

...
...

The Shai-Hulud AI-synthesized worm—attributed to the TeamPCP collective—was open-sourced and quickly replicated across the internet; OX telemetry identified four malicious NPM packages (e.g., @chalk-tempalte, @axois-util) with hundreds of downloads that include either a direct clone of the worm or other malicious payloads designed to steal developer authentication tokens and use those credentials for lateral propagation. Microsoft removed the original repository, but copies proliferated and adversaries have begun modifying only the C2 endpoints (examples: 87e0bbc636999b.lhr.life, 80.200.28.28:2222, edcf8b03c84634.lhr.life) to weaponize the framework in active campaigns.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.