A wave of software supply-chain attacks spanning late 2025 through September 2026 compromised package-publishing and CI/CD credentials to push malicious updates into trusted ecosystems. Campaigns tracked as S1ngularity, Shai-Hulud, and TeamPCP stole secrets, infected downstream users, and in some cases republished themselves through additional packages. S1ngularity compromised Nx packages and abused victim-hosted AI agents and GitHub repositories to find and exfiltrate credentials, while Shai-Hulud expanded the approach with worm-like propagation using stolen npm credentials.
TeamPCP was linked to similar compromises affecting Trivy, Checkmarx, LiteLLM, Telnyx, TanStack, and more than 60 npm packages; reporting attributes suspected losses of hundreds of millions of dollars to the group and notes the arrest of two people in Australia in connection with it. Microsoft published detection, investigation, and defensive guidance for Shai-Hulud 2.0, underscoring the need for organizations to investigate exposed publishing credentials, review package releases and CI/CD activity, rotate compromised secrets, and assess downstream environments for malicious dependency updates.

Trace attribution and downstream blast radius.
10 events from the most recent confirmed update back to the earliest known activity.
TeamPCP allegedly used the compromised Trivy service account to modify existing version tags and publish a malicious update through Trivy's automated systems. The implanted malware identified itself as "TeamPCP Cloud stealer."
TeamPCP allegedly extracted a privileged access token from Trivy. Trivy detected the exposure, but incomplete credential rotation allegedly left a compromised service account usable.
TeamPCP published an open-source Shai-Hulud variant called Mini Shai-Hulud and offered a US$1,000 reward for the largest supply-chain attack using it.
Shai-Hulud, also called Shai-Hulud 2.0 or SHA1-Hulud, returned in two attacks. One used a Pwn Request and malicious OpenVSX extension to exfiltrate a CI token; the other targeted projects including Zapier, PostHog, and Postman using long-lived credentials exposed in compromised repositories and executed its payload with Bun.
The initial Shai-Hulud campaign began targeting open-source tools, collecting secrets, and exfiltrating data through GitHub accounts. It propagated worm-like by stealing npm publishing credentials and using them to publish malicious updates to further packages.
S1ngularity compromised several Nx packages after using a crafted pull request and chained weaknesses to obtain a repository token. It replaced a legitimate CI script, triggered package publishing with an exfiltrated npm token, and distributed infected updates.
The retrospective attributes compromises of Checkmarx, LiteLLM, and Telnyx to TeamPCP-related activity. LiteLLM and Telnyx were allegedly compromised through malicious packages uploaded to PyPI.
During the Trivy compromise, TeamPCP allegedly harvested npm tokens and used them to distribute CanisterWorm to more than 60 npm packages. CanisterWorm stole victim npm tokens and overwrote associated packages with malicious versions to continue propagating.
The ChainDrop campaign used Mini Shai-Hulud with an obfuscated Bun JavaScript payload and reportedly produced more than 400 patches while active. It attempted HTTPS exfiltration before creating a public GitHub repository named "Shai-Hulud: Here We Go Again" when that failed.
Microsoft Defender Security Research Team released guidance for detecting, investigating, and defending against the Shai-Hulud 2.0 supply-chain attack.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See attribution and downstream blast radius, and whether this package or vendor reaches your builds.
3 references tracked. Mallory keeps watching after this page renders.
reversinglabs.com
Open sourcemicrosoft.com
Open sourcenx.dev
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.