First Shai-Hulud Worm Clones Emerge
The first Shai-Hulud worm clones emerged only days after TeamPCP released the malware’s source code on GitHub, Ox Security reports.
Shai-Hulud was first used in supply chain attacks against the open source software ecosystem in September 2025, and then again in November, in campaigns that hit hundreds of NPM packages and likely infected thousands of developers.
The malware was designed to steal credentials, API keys, tokens, and other secrets from the infected machines and use them for self-propagation by injecting itself into the packages maintained by the victims and publishing malicious versions on their behalf.
It re-emerged in April, in supply chain attacks attributed to the TeamPCP hacking group, which mounted several campaigns against the open source software community since March, including the Trivy, Bitwarden, Checkmarx, SAP, and TanStack incidents.
Last week, several repositories containing the Shai-Hulud worm’s source code briefly appeared on GitHub, accompanied by...
Copyright of this story solely belongs to securityweek.com. To see the full text click HERE