TeamPCP / Mini Shai-Hulud npm Supply Chain Worm
Auto-generated score, not yet verified against the scoring model. Under review — treat as indicative, not a verdict.
anchored·4u7xtX…5UoLSummary
TeamPCP is a threat actor group responsible for the 'Mini Shai-Hulud' self-propagating npm supply chain worm, first deployed on May 11, 2026. The campaign compromised over 600 npm packages across major ecosystems including TanStack, Mistral AI, UiPath, Red Hat, and Mastra AI, reaching two OpenAI employee devices and exfiltrating approximately 3,800 GitHub internal repositories. The malware specifically targets 166 cryptocurrency-related browser extensions and local wallet files, creating direct financial risk for crypto developers and end users.
Connected Entities
10 entities · 60 linked investigations- TanStack npm Supply Chain Attack (Mini Shai-Hulud / TeamPCP)→mentioned with→Bitcoin(70%)
- TanStack npm Supply Chain Attack (Mini Shai-Hulud / TeamPCP)→mentioned with→Ethereum(60%)
- TanStack npm Supply Chain Attack (Mini Shai-Hulud / TeamPCP)→mentioned with→Monero(60%)
- Ethereum→mentioned with→Bitcoin(60%)
- TeamPCP / Mini Shai-Hulud npm Supply Chain Worm→mentioned with→Monero(80%)
- TeamPCP / Mini Shai-Hulud npm Supply Chain Worm→mentioned with→Ethereum(65%)
- TeamPCP / Mini Shai-Hulud npm Supply Chain Worm→mentioned with→Solana(65%)
- TeamPCP / Mini Shai-Hulud npm Supply Chain Worm→mentioned with→Bitcoin(75%)
- Monero→mentioned with→Bitcoin(60%)
- Phantom Wallet→mentioned with→Ethereum(70%)
- + 15 more
Timeline(14 events)
September 2025
Shai-Hulud worm activity first observed; earliest attributable TeamPCP supply chain operations begin (approximate date).
SecurityWeek22 April 2026
Earlier npm supply chain worm attack reported, attributed to TeamPCP activity.
The Register11 May 2026
Mini Shai-Hulud worm deployed; 84 malicious versions published across 42 @tanstack packages. Within five hours, over 400 malicious versions across 172 packages published. Two OpenAI employee devices compromised.
Orca Security / The Hacker News12 May 2026
TeamPCP publishes Mini Shai-Hulud full source code on GitHub under MIT license alongside BreachForums posts encouraging independent campaigns. 169 npm and 2 PyPI packages disclosed.
Orca Security18 May 2026
GitHub employee installs trojanized Nx Console VS Code extension (2.2 million installs, verified publisher); extension live for approximately 11 minutes before removal. TeamPCP exfiltrates approximately 3,800 GitHub internal repositories.
Phoenix Security19 May 2026
Atool maintainer account compromise published; 323 packages compromised including AntV, jest-canvas-mock, echarts-for-react.
Phoenix SecurityJune 2026
Miasma variant deployed against @redhat-cloud-services npm namespace. Compromised Red Hat employee GitHub account used to publish 96 malicious versions across 32 packages (116,991 combined weekly downloads). Two attack waves: 10:53 UTC and 13:44-13:46 UTC.
Wiz / Aikido Security / The Register5 June 2026
At least 57 npm packages and 300+ malicious versions identified under Miasma/Hades umbrella; 471 total malicious artifacts across ecosystems documented.
SecurityWeek8 June 2026
Hades PyPI variant second wave: at least 29 additional PyPI packages compromised, targeting bioinformatics, graph ML, and MCP-themed packages.
SecurityWeek12 June 2026
OpenAI deadline for users to update ChatGPT Desktop, Codex App, Codex CLI, and Atlas to versions signed with new certificates; old code-signing certificates revoked.
OpenAI17 June 2026
141 Mastra AI npm packages compromised in a 45-minute window by alleged North Korean APT Sapphire Sleet. Typosquat package easy-day-js injected into packages with ~8 million combined weekly downloads. Microsoft formally attributes attack to Sapphire Sleet (BlueNoroff).
Microsoft Security Blog / SecurityWeekDecision Log
- hash: tQsts2QsjZsTzzcgrdjQaQKD7twscgTS9PQrTpNbtyF
This investigation is cryptographically anchored to the Solana blockchain (1 event). 24 of 25 cited source URLs have an Internet Archive snapshot.
model: claude-sonnet-4-6
generated: 6/24/2026, 12:34:59 PM
last updated: 7/27/2026, 10:56:28 AM
3 viewsavoid.net — verified advice for a post-truth world