TeamPCP Used Mini Shai-Hulud Worm to Poison Over 400 npm and PyPI Packages
TeamPCP Used Mini Shai-Hulud Worm to Poison Over 400 npm and PyPI Packages
Wed May 13 2026
Development
Malware
Open Source
hackread.com
Research reveals that TeamPCP hijacked OIDC tokens to poison hundreds of TanStack, Mistral AI, and UiPath packages with the self-propagating Mini Shai-Hulud worm.