logo

Shai-Hulud Worm Clones Spread After Code Release

ID: 43ee0c63-8e74-54d7-9f2a-2f2454d1177d

STIX ID: report--43ee0c63-8e74-54d7-9f2a-2f2454d1177d

Feed Name: Dark Reading

Threat Score
75/100

Date Published: 2026-05-18

Date Updated: 2026-05-18

Author: Alexander Culafi

...
...

A financially motivated group (TeamPCP) published the Shai-Hulud worm source, and multiple near-verbatim clones have since appeared in the NPM ecosystem as typosquats and malicious packages that include infostealers and DDoS payloads; attackers can easily swap C2 endpoints and signing keys to run many variants simultaneously, posing a growing automated supply-chain threat to developer accounts, CI/CD pipelines, and open source trust.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.