Shai-Hulud Worm Clones Spread After Code Release
2026-05-18T20:51:38Z•0e51f10ce9d7c6c1d497a28719357cbbe35073cc75f8c415220c39e3390b49d8
AI-assisted attacksCVSS 10.0Cisco SD‑WANClaude Code Cursor CLI Gemini CLI Copilot CLI risk","ShinyHunersDirty FragDirty PipeHugging FaceLLM exploitationLinux privilege escalationPCPJackRubyGemsShai‑HuludTanStackTeamPCPTrustFallcode executioncredential theftexploit developmentmodel poisoningnpmpackage poisoningsupply chaintokenizer attackvulnerability exploitationworm
What happened
A wide-ranging Dark Reading feed highlights an elevated threat landscape driven by self-propagating malware, supply-chain and ML/model attacks, high-severity exploited flaws, and growing use of AI by adversaries. Key items: public release of the Shai‑Hulud worm source has spawned clones and infected hundreds of npm/TanStack packages (supply‑chain credential theft); TeamPCP/PCPJack continue stealthy cloud‑secrets exfiltration; attackers weaponize package repositories (RubyGems, Hugging Face tokenizers) to hijack models and exfiltrate data; attackers increasingly use AI agents and LLMs to find,
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- darkreading
- Record identifier
- 0e51f10ce9d7c6c1d497a28719357cbbe35073cc75f8c415220c39e3390b49d8
- Enrichment time
- 2026-05-18T20:51:38Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.