TeamPCP Used Mini Shai-Hulud Worm to Poison Over 400 npm and PyPI Packages

2026-05-13T20:51:43Z6037f9a3693bef21d1f1cf17e554f15084bf080516321fcc65798d6716accf55
AI-assisted-exploitMini-Shai-HuludOIDCPwn2OwnTeamPCPcredential-stealerdomain-suspensionfake-installermalwarenpmoperation-humanitarianbaitpackage-poisoningpypipython-spywareshinyhunterssupply-chaintelecom-targetingtoken-hijackingwormzero-day

What happened

Feed highlights multiple high-impact threats. Most urgent: researchers attribute a widespread supply‑chain poisoning campaign to TeamPCP, who used an OIDC token hijack and a self‑propagating “Mini Shai‑Hulud” worm to backdoor and poison over 400 npm and PyPI packages (including packages tied to TanStack, Mistral AI, and UiPath). Other notable items: a fake “Claude Code” installer campaign stealing browser credentials and cookies; rejected Pwn2Own Berlin participants publicly releasing zero‑day exploits (targets include Firefox, NVIDIA, and AI platforms); Google reporting adversaries used AI to

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
hackread
Record identifier
6037f9a3693bef21d1f1cf17e554f15084bf080516321fcc65798d6716accf55
Enrichment time
2026-05-13T20:51:43Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.