Find notable cyber news and cases, enriched with sources, timelines, and signals.

TeamPCP Mini Shai-Hulud npm supply-chain campaign

Campaign
First reported
Last updated
Happening score
H score 75
3 unique sources, 6 articles

Summary

Hide ▲

The TeamPCP-linked Mini Shai-Hulud campaign is an active npm supply-chain operation that steals developer credentials and abuses trusted publishing paths to spread trojanized packages. A new Miasma wave compromised more than 30 npm packages in Red Hat's @redhat-cloud-services namespace and used preinstall hooks to steal GitHub Actions secrets, cloud credentials, SSH keys, npm tokens, and other sensitive files. Red Hat said it removed the affected packages and has not identified impact to customer, partner, or production environments, while the wider campaign has already compromised 309 GitHub repositories.

Related Happenings

AsyncAPI malicious npm package supply-chain malware

Malware Activity
H score21 First: 15.07.2026 18:37 Last: 15.07.2026 18:37 Sources 1

About this happening: Malicious AsyncAPI npm releases pushed a remote access trojan and info-stealing payload into packages with more than 2.25 million weekly downloads, putting downstr...

AsyncAPI repositories and npm publishing workflow hit by network compromise

Incident
H score27 First: 15.07.2026 12:16 Last: 15.07.2026 12:16 Sources 1

About this happening: The AsyncAPI npm publishing pipeline was compromised in a July 14 supply-chain attack that used the project’s normal GitHub Actions release path to publish trojani...

GitHub fake-repository infostealer campaign

Campaign
H score41 First: 14.07.2026 22:15 Last: 14.07.2026 22:15 Sources 1

About this happening: A GitHub impersonation campaign is distributing infostealer malware through 292 fake repositories, expanding the risk to users searching for trusted software downloads...

Jscrambler hit by network compromise

Incident
H score15 First: 13.07.2026 22:44 Last: 13.07.2026 22:44 Sources 1

About this happening: The Jscrambler npm package suffered an unauthorized publication of a malicious version that exposed developers to infostealer theft risk. The bad release stayed li...

OpenMandriva Linux project hit by cyberattack

Incident
H score32 First: 10.07.2026 01:14 Last: 10.07.2026 01:14 Sources 1

About this happening: The OpenMandriva Linux project is recovering from an attempted internal sabotage that deleted repositories and published an empty package that could have damaged user...

Timeline

  1. 12.05.2026 14:07 2 articles · 2mo ago

    Mini Shai-Hulud fresh wave compromises TanStack npm packages

    Initial Disclosure

    Researchers disclosed a fresh wave of TeamPCP-linked Mini Shai-Hulud infections across compromised npm packages in the TanStack developer ecosystem, including 373 malicious package-version entries across 169 npm package names and 84 compromised TanStack npm package artifacts. The malware steals credentials from developer machines and CI/CD runners, then abuses trusted publishing paths, GitHub Actions/OIDC, and maintainers’ publishing credentials to push trojanized package updates.

    Show sources
  2. 26.11.2025 20:08 4 articles · 7mo ago

    Shai-Hulud v2 expands from npm into Maven packages

    Campaign Scope Update

    Shai-Hulud v2 expanded from npm into Maven through org.mvnpm:posthog-node:4.18.1, which contained setup_bun.js and bun_environment.js. The campaign also abused GitHub Actions CI misconfigurations in projects associated with PostHog, AsyncAPI, and Postman, and the broader operation was linked to more than 28,000 affected repositories and widespread secret theft.

    Show sources