1,800 Developers Hit in Mini Shai-Hulud Supply Chain Attack Across PyPI, NPM, and PHP
ID: cf6a6c2b-1262-598a-9f96-b2661334045c
STIX ID: report--cf6a6c2b-1262-598a-9f96-b2661334045c
Feed Name: Security Boulevard
Mini Shai-Hulud is a supply-chain campaign by TeamPCP that compromised popular packages across PyPI, NPM, and PHP (including Lightning 2.6.2/2.6.3, intercom-client 7.0.4/7.0.5, and intercom-php 5.0.2) to deploy an information-stealing payload that harvests credentials, keys, tokens, cloud secrets, and session tokens, actively scans Kubernetes and HashiCorp Vault, and exfiltrates data to GitHub repositories and the domain zero.masscan.cloud; the campaign impacted hundreds to thousands of developer repositories and leverages dynamic C2 fallback and downstream propagation via dependencies.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
