Mini Shai-Hulud: Frequently asked questions about the TeamPCP npm and PyPI supply chain campaign

2026-05-21T20:52:18Ze54b6680024974eb2e7f7c3998b87bc1832c343ef90a0fe293440d8199f989dc
CVE-2026-20127CVE-2026-20182CVE-2026-9082CiscoDrupalMini Shai-HuludPyPISD-WANSLSASQL-injectionTeamPCPTenable-Hexa-AI','agentic-AI','DBIR-2026','cloud-security','zombTenable-Oneactive-exploitationauthentication-bypasscredential-theftnpmpatchingprovenanceself-propagatingsoftware-supply-chainsupply-chainvulnerability-managementwormzero-day

What happened

The feed highlights multiple high‑impact security developments from May 2026. The standout item is Mini Shai‑Hulud, a self‑propagating worm by TeamPCP that has compromised >170 npm and PyPI packages, stolen developer/cloud credentials, and published poisoned packages — notably defeating SLSA Build Level 3 provenance attestations; any system that installed a compromised package should be treated as fully compromised. Separately, Drupal disclosed CVE‑2026‑9082, a highly critical unauthenticated SQL injection affecting PostgreSQL sites (vendor-rated "Highly Critical"). Cisco Catalyst SD‑WAN has a

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
tenable_blog
Record identifier
e54b6680024974eb2e7f7c3998b87bc1832c343ef90a0fe293440d8199f989dc
Enrichment time
2026-05-21T20:52:18Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Mini Shai-Hulud: Frequently asked questions about the TeamPCP npm and PyPI supply chain campaign · Baitaphish