Malware crew TeamPCP open-sources its Shai-Hulud worm on GitHub

2026-05-13T07:23:57Z1eef91b14f936fa10c5f758a12455cbf694ab1ec2c26803a8cdd49d726951127
AI-securityCopyFailDirty FragFoxconnJenkinsMicrosoft patchesShinyHuntersTanStackTeamPCPcPanelcookie theftcredential theftdisk wipingfake installersmalwarenpmopen-source malwareransomwaresupply-chainworm

What happened

Batch of high-impact security stories: malware crew ‘TeamPCP’ publicly released its Shai‑Hulud worm on GitHub and has been tied to Jenkins-plugin sabotage; a fast supply‑chain cache‑poisoning attack pushed 84 malicious TanStack npm versions with credential‑theft and disk‑wiping payloads; major Patch Tuesday included ~30 critical Microsoft CVEs; Foxconn confirmed a cyberattack with alleged theft of Apple/NVIDIA files; active exploitation reported for several Linux issues (CopyFail, Dirty Frag) and a critical cPanel flaw; ShinyHunters and other extortion actors continue breaching organisations;톱

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
theregister_security
Record identifier
1eef91b14f936fa10c5f758a12455cbf694ab1ec2c26803a8cdd49d726951127
Enrichment time
2026-05-13T07:23:57Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.