Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
package-repository-poisoningoffensive-tooling-releasecredential-stealer-activitybuild-pipeline-compromise

TeamPCP’s Shai-Hulud Supply-Chain Worm Leaked on GitHub, Spurring Copycat Attacks

Updated 15d agoFirst seen May 19, 20268 sources

Source code for the Shai-Hulud supply-chain worm attributed to TeamPCP was briefly exposed on GitHub, with repositories reportedly inviting others to modify keys and command-and-control settings and, in some cases, released under the MIT License. Researchers said the leaked code closely matched malware used in recent npm and PyPI compromises tied to packages associated with TanStack, Mistral AI, and OpenSearch, and revealed a modular framework built to steal credentials from developer workstations, CI/CD runners, cloud environments, Kubernetes, and HashiCorp Vault. The malware propagates by abusing stolen GitHub, npm, cloud, and OIDC credentials to poison repositories and publish backdoored packages, while maintaining persistence through GitHub workflows, Python .pth hooks, IDE and AI coding assistant configuration changes, system services, and Windows Startup entries.

Analysis of the leaked framework showed encrypted exfiltration, GitHub dead-drop and signed-commit fallback channels, Sigstore provenance forgery, and destructive behavior including an org-membership-gated wiper and coercive deadman switch. GitHub removed the original repositories and has reportedly been taking down reposted copies, but forks and modified variants were already observed, and within days copycat actors began publishing Shai-Hulud-derived malicious npm packages such as chalk-tempalte and Axios-themed typosquats. Security firms warned that the public release turns an already successful credential-theft and software supply-chain operation into a reusable toolkit for other threat actors, increasing the likelihood of broader attacks across npm, PyPI, GitHub Actions, Docker Hub, OpenVSX, and developer tooling ecosystems.

Share:
TeamPCP’s Shai-Hulud Supply-Chain Worm Leaked on GitHub, Spurring Copycat Attacks
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

9 events from the most recent confirmed update back to the earliest known activity.

9 EVENTS
May 19, 20261mo ago

Copycat Shai-Hulud campaigns appear on npm after leak

Within days of the source-code leak, copycat campaigns emerged targeting npm developers with modified Shai-Hulud-based packages. Ox Security reported at least one actor published a near-direct clone called "chalk-tempalte," alongside other typo-squatted packages and one package with DDoS botnet functionality.

Shai-Hulud worm copycats emerge after source code leak
May 15, 20261mo ago

GitHub removes original Shai-Hulud repositories

SC Media reported that GitHub removed the original repositories containing the Shai-Hulud source code and appeared to be rapidly removing reposted copies. Forks were still observed despite the removals.

TeamPCP releases ‘vibe coded’ Shai-Hulud source code, issues challenge | news | SC Media

Recent npm and PyPI campaign hits major package ecosystems

SC Media reports that a recent TeamPCP-linked npm and PyPI supply-chain campaign spread credential-stealing malware through compromised developer accounts. Affected packages were associated with TanStack, Mistral AI, OpenSearch, and others.

TeamPCP releases ‘vibe coded’ Shai-Hulud source code, issues challenge | news | SC Media
May 13, 20261mo ago

TeamPCP conducts months-long supply-chain credential theft campaign

Sources describe TeamPCP as running an extended campaign across 2025 and 2026 that targeted npm, PyPI, GitHub Actions, Docker Hub, OpenVSX, IDE integrations, and CI/CD workflows to steal credentials and republish backdoored packages. Akamai characterizes the operation as an eight-month campaign focused on harvesting secrets and expanding access across repositories and developer tooling.

Sha1-Hulud Worm Analysis: Polymorphism, Persistence & IOCs

Independent actors begin forking and modifying leaked Shai-Hulud

After the GitHub publication, researchers observed independent threat actors forking and modifying the malware. Reporting said the repositories remained online for at least 12 hours, enabling reuse before takedowns.

Malware crew TeamPCP open-sources its Shai-Hulud worm on GitHub

Researchers analyze leaked framework and tie it to prior attacks

Static analysis of the leaked code found a modular TypeScript/Bun toolkit for credential theft, CI/CD compromise, encrypted exfiltration, and propagation through poisoned GitHub repositories and npm packages. Researchers said the code matched previously observed TeamPCP artifacts and revealed added capabilities such as AI coding assistant persistence, Sigstore provenance forgery, signed-commit C2 fallback, and a deadman switch.

Shai-Hulud Goes Open Source | Datadog Security Labs

Shai-Hulud source code is exposed on GitHub

Researchers reported that a GitHub repository briefly exposed what appears to be the full source code of the Shai-Hulud offensive framework attributed to TeamPCP. OX Security and other reporting said TeamPCP appeared to have published the code openly, inviting others to modify keys and command-and-control settings.

Shai-Hulud Goes Open Source | Datadog Security Labs
Nov 1, 20258mo ago

A stronger Shai-Hulud variant emerges

A more capable variant of Shai-Hulud emerged in November 2025, according to reporting on the malware's evolution. Later analyses describe subsequent variants and copycats proliferating after this point.

Malware crew TeamPCP open-sources its Shai-Hulud worm on GitHub
Sep 1, 202510mo ago

Researchers first identify Shai-Hulud malware

Reporting states that researchers first found the Shai-Hulud malware in September 2025. The malware was linked to software supply-chain attacks targeting npm ecosystems.

Malware crew TeamPCP open-sources its Shai-Hulud worm on GitHub
LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

64 LINKEDOpen in app
Threat actors
2 linked
Affected products
19 linked
LitellmClaude CodeGithubAmazon Web ServicesVisual Studio CodeKubernetesSigstoreBunTrivyAxiosPosthogVaultNpmFulcioRekorLitellmAws-Secrets-ManagerGuardrails AiOpensearch
Organizations
26 linked
GitHubCheckmarxSAPBitwardenOx SecuritySecurity AffairsTanstackUipathAmazon Web ServicesCheck Point Software TechnologiesLitellmAxiosMistral AIAnthropicHashicorpPosthogCrowdStrikeMicrosoft CorporationAqua SecurityOpen-XchangePhoenix SecurityTelnyxGuardrails AIOpenSearch Software FoundationVectMistal AI
Breaches
10 linked
TRIVY-2026-03KICS-2026-03TANSTACK-2026-05UIPATH-2026-05GUARDRAILSAI-2026-05MISTRALAI-2026-05OPENSEARCH-2026-05LITELLM-2026-05TELNYX-2026-05BITWARDEN-2026-05
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.

TeamPCP’s Shai-Hulud Supply-Chain Worm Leaked on GitHub, Spurring Copycat Attacks | Mallory