TeamPCP Used Mini Shai-Hulud Worm to Poison Over 400 npm and PyPI Packages
ID: 4f8de37e-ad53-56b8-a3d6-4d5c52150e5b
STIX ID: report--4f8de37e-ad53-56b8-a3d6-4d5c52150e5b
Feed Name: HackRead
A threat actor identified as TeamPCP executed a high-speed, coordinated supply-chain attack (Mini Shai-Hulud) on 11–12 May 2026, poisoning hundreds of npm and PyPI packages (over 400 malicious versions across ~172 packages) by abusing CI/CD via stolen OIDC tokens and valid SLSA attestations. The malicious packages delivered a self-propagating worm and credential-stealer targeting AWS, Vault, and GitHub tokens, used stolen tokens to spread further in projects, and exfiltrated data via the Oxen network; registries and vendors have removed/quarantined affected releases and recommend immediate lockfile audits and full credential rotations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
