Shai-Hulud Worm Clones Spread After Code Release

2026-05-18T20:51:38Z0e51f10ce9d7c6c1d497a28719357cbbe35073cc75f8c415220c39e3390b49d8
AI-assisted attacksCVSS 10.0Cisco SD‑WANClaude Code Cursor CLI Gemini CLI Copilot CLI risk","ShinyHunersDirty FragDirty PipeHugging FaceLLM exploitationLinux privilege escalationPCPJackRubyGemsShai‑HuludTanStackTeamPCPTrustFallcode executioncredential theftexploit developmentmodel poisoningnpmpackage poisoningsupply chaintokenizer attackvulnerability exploitationworm

What happened

A wide-ranging Dark Reading feed highlights an elevated threat landscape driven by self-propagating malware, supply-chain and ML/model attacks, high-severity exploited flaws, and growing use of AI by adversaries. Key items: public release of the Shai‑Hulud worm source has spawned clones and infected hundreds of npm/TanStack packages (supply‑chain credential theft); TeamPCP/PCPJack continue stealthy cloud‑secrets exfiltration; attackers weaponize package repositories (RubyGems, Hugging Face tokenizers) to hijack models and exfiltrate data; attackers increasingly use AI agents and LLMs to find,

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
darkreading
Record identifier
0e51f10ce9d7c6c1d497a28719357cbbe35073cc75f8c415220c39e3390b49d8
Enrichment time
2026-05-18T20:51:38Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Shai-Hulud Worm Clones Spread After Code Release · Baitaphish