TeamPCP Used Mini Shai-Hulud Worm to Poison Over 400 npm and PyPI Packages
2026-05-13T20:51:43Z•6037f9a3693bef21d1f1cf17e554f15084bf080516321fcc65798d6716accf55
AI-assisted-exploitMini-Shai-HuludOIDCPwn2OwnTeamPCPcredential-stealerdomain-suspensionfake-installermalwarenpmoperation-humanitarianbaitpackage-poisoningpypipython-spywareshinyhunterssupply-chaintelecom-targetingtoken-hijackingwormzero-day
What happened
Feed highlights multiple high-impact threats. Most urgent: researchers attribute a widespread supply‑chain poisoning campaign to TeamPCP, who used an OIDC token hijack and a self‑propagating “Mini Shai‑Hulud” worm to backdoor and poison over 400 npm and PyPI packages (including packages tied to TanStack, Mistral AI, and UiPath). Other notable items: a fake “Claude Code” installer campaign stealing browser credentials and cookies; rejected Pwn2Own Berlin participants publicly releasing zero‑day exploits (targets include Firefox, NVIDIA, and AI platforms); Google reporting adversaries used AI to
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- hackread
- Record identifier
- 6037f9a3693bef21d1f1cf17e554f15084bf080516321fcc65798d6716accf55
- Enrichment time
- 2026-05-13T20:51:43Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.