logo

TeamPCP Used Mini Shai-Hulud Worm to Poison Over 400 npm and PyPI Packages

ID: 4f8de37e-ad53-56b8-a3d6-4d5c52150e5b

STIX ID: report--4f8de37e-ad53-56b8-a3d6-4d5c52150e5b

Feed Name: HackRead

Threat Score
90/100

Date Published: 2026-05-13

Date Updated: 2026-05-13

Author: Deeba Ahmed

...
...

A threat actor identified as TeamPCP executed a high-speed, coordinated supply-chain attack (Mini Shai-Hulud) on 11–12 May 2026, poisoning hundreds of npm and PyPI packages (over 400 malicious versions across ~172 packages) by abusing CI/CD via stolen OIDC tokens and valid SLSA attestations. The malicious packages delivered a self-propagating worm and credential-stealer targeting AWS, Vault, and GitHub tokens, used stolen tokens to spread further in projects, and exfiltrated data via the Oxen network; registries and vendors have removed/quarantined affected releases and recommend immediate lockfile audits and full credential rotations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.