A ReversingLabs retrospective traces how three linked threats turned routine software updates into credential-stealing attacks. The latest development is the arrest of two Australian men tied to TeamPCP.
Spring 2026 was a rough season for open source maintainers. Package after package was hijacked to push malicious updates, and the damage reached into security scanners, AI tooling and developer platforms.
The firm reports a 73% rise in detected malicious open-source packages in 2025. Attackers have found that compromising one supplier gives them access to thousands of downstream users. Malicious versions often stay online for only a few hours, which is still long enough to hit many victims.
Two Arrested in Australia Over TeamPCP
The campaign began on August 26, 2025, against Nx, a build system with millions of weekly downloads. Attackers used a crafted pull request to extract a token from the repository.
They then swapped a legitimate CI script for a malicious one, triggered a publishing workflow, and deleted branches and workflow runs to hide their tracks.
The poisoned packages ran post-install hooks that hunted for GitHub and npm tokens, cloud credentials, and SSH keys. The stolen data was posted to public GitHub repositories named “s1ngularity-repository”.
The notable twist was that the malware prompted the victim’s own AI agents to search the file system. The attackers refined the prompts several times, using personas such as a penetration tester and a file-search agent, likely to avoid the agents’ safeguards.
Nx responded by moving to GitHub’s Trusted Publisher model. It replaces long-lived tokens with short-lived, per-run credentials.
Shai-Hulud first appeared on September 12, 2025. It stole npm publishing tokens and used them to republish itself, so it didn’t need a software vulnerability to spread.
It returned in late November as Shai-Hulud 2.0, also called SHA1-Hulud. That version used Bun to run its payload, and the campaign hit projects such as Zapier, PostHog, and Postman.
In April 2026, TeamPCP open-sourced a version called Mini Shai-Hulud. It offered a $1,000 reward for the biggest attack built on it. In August, the ChainDrop campaign used Mini Shai-Hulud with an obfuscated Bun payload, and more than 400 patches were released while it was active.
If its HTTPS exfiltration fails, it falls back to creating a public GitHub repository titled “Shai-Hulud: Here We Go Again”. ReversingLabs says the 2025 Shai-Hulud activity is hard to attribute. Mini Shai-Hulud is clearly tied to TeamPCP.
TeamPCP is a group, not a single malware family, and it rose to prominence with the Trivy compromise. Attackers took a privileged token in February.
Trivy detected the intrusion, but its credential rotation was incomplete. On March 19, the group pushed a malicious update through a compromised service account. It altered existing version tags, which CI/CD pipelines rely on.
The same access led to compromises of Checkmarx, LiteLLM, and Telnyx. The group also launched CanisterWorm, which hit more than 60 npm packages using harvested tokens.
TeamPCP has partnered with the Vect ransomware group and worked with the LAPSUS$ extortion group. Suspected damages run to hundreds of millions of dollars.
Investigators then linked overlapping usernames across accounts, which led to the identification of a suspect. Investigators arrested two men in Australia, and the case is still developing.
Mitigation
- Rotate every credential completely after any breach. The Trivy incident shows that a partial rotation can be enough for attackers to return.
- Replace long-lived publishing tokens with short-lived, per-run credentials such as Trusted Publishing.
- Audit repository and pipeline permissions, especially access granted to pull requests.
- Treat updates as untrusted until they are checked. Trusted dependencies can bypass the controls applied to unknown downloads.
- Limit what local AI agents can read, since S1ngularity showed they can be prompted to search for secrets.
Variants and copycats are expected to keep appearing now that Mini Shai-Hulud is public.
Site: Thecyberdef.com
Follow TheCyberDef on Google News, LinkedIn & X for the latest cybersecurity updates. Stay informed.