Mini Shai-Hulud: Frequently asked questions about the TeamPCP npm and PyPI supply chain campaign
2026-05-21T20:52:18Z•e54b6680024974eb2e7f7c3998b87bc1832c343ef90a0fe293440d8199f989dc
CVE-2026-20127CVE-2026-20182CVE-2026-9082CiscoDrupalMini Shai-HuludPyPISD-WANSLSASQL-injectionTeamPCPTenable-Hexa-AI','agentic-AI','DBIR-2026','cloud-security','zombTenable-Oneactive-exploitationauthentication-bypasscredential-theftnpmpatchingprovenanceself-propagatingsoftware-supply-chainsupply-chainvulnerability-managementwormzero-day
What happened
The feed highlights multiple high‑impact security developments from May 2026. The standout item is Mini Shai‑Hulud, a self‑propagating worm by TeamPCP that has compromised >170 npm and PyPI packages, stolen developer/cloud credentials, and published poisoned packages — notably defeating SLSA Build Level 3 provenance attestations; any system that installed a compromised package should be treated as fully compromised. Separately, Drupal disclosed CVE‑2026‑9082, a highly critical unauthenticated SQL injection affecting PostgreSQL sites (vendor-rated "Highly Critical"). Cisco Catalyst SD‑WAN has a
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- tenable_blog
- Record identifier
- e54b6680024974eb2e7f7c3998b87bc1832c343ef90a0fe293440d8199f989dc
- Enrichment time
- 2026-05-21T20:52:18Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.