Malware crew TeamPCP open-sources its Shai-Hulud worm on GitHub
2026-05-13T07:23:57Z•1eef91b14f936fa10c5f758a12455cbf694ab1ec2c26803a8cdd49d726951127
AI-securityCopyFailDirty FragFoxconnJenkinsMicrosoft patchesShinyHuntersTanStackTeamPCPcPanelcookie theftcredential theftdisk wipingfake installersmalwarenpmopen-source malwareransomwaresupply-chainworm
What happened
Batch of high-impact security stories: malware crew ‘TeamPCP’ publicly released its Shai‑Hulud worm on GitHub and has been tied to Jenkins-plugin sabotage; a fast supply‑chain cache‑poisoning attack pushed 84 malicious TanStack npm versions with credential‑theft and disk‑wiping payloads; major Patch Tuesday included ~30 critical Microsoft CVEs; Foxconn confirmed a cyberattack with alleged theft of Apple/NVIDIA files; active exploitation reported for several Linux issues (CopyFail, Dirty Frag) and a critical cPanel flaw; ShinyHunters and other extortion actors continue breaching organisations;톱
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- theregister_security
- Record identifier
- 1eef91b14f936fa10c5f758a12455cbf694ab1ec2c26803a8cdd49d726951127
- Enrichment time
- 2026-05-13T07:23:57Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.