TeamPCP Open-Sources “Shai-Hulud” AI Supply Chain Malware, Hitting NPM Fleet
ID: a35ecab1-658c-52d7-9ec7-40d51e198783
STIX ID: report--a35ecab1-658c-52d7-9ec7-40d51e198783
Feed Name: securityonline.info
The Shai-Hulud AI-synthesized worm—attributed to the TeamPCP collective—was open-sourced and quickly replicated across the internet; OX telemetry identified four malicious NPM packages (e.g., @chalk-tempalte, @axois-util) with hundreds of downloads that include either a direct clone of the worm or other malicious payloads designed to steal developer authentication tokens and use those credentials for lateral propagation. Microsoft removed the original repository, but copies proliferated and adversaries have begun modifying only the C2 endpoints (examples: 87e0bbc636999b.lhr.life, 80.200.28.28:2222, edcf8b03c84634.lhr.life) to weaponize the framework in active campaigns.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
