TeamPCP Used Mini Shai-Hulud Worm to Poison Over 400 npm and PyPI Packages. TeamPCP executed a coordinated attack compromising 400+ packages across npm and PyPI by hijacking OpenID Connect tokens to gain CI/CD access, targeting TanStack, Mistral AI, UiPath, and OpenSearch with a self-propagating credential-stealing worm.
OpenAI Hit by TanStack Supply Chain Attack. OpenAI disclosed impact from the TanStack attack, with two employee devices infected and limited credential material plus code-signing certificates for iOS, macOS, Windows, and Android exfiltrated from repositories.
Hundreds of Malicious Packages Force RubyGems to Suspend Registrations. RubyGems disabled new registrations after threat actors published 500+ malicious packages via bot accounts targeting RubyGems infrastructure with XSS and data exfiltration attempts.
TeamPCP Ups the Game, Releases Shai-Hulud Worm's Source Code. TeamPCP publicly released Shai-Hulud source code on GitHub with deployment instructions and launched a supply chain challenge offering monetary rewards to cybercriminals who use the worm.
Key Takeaway
Implement SLSA attestation validation, audit CI/CD permissions, and monitor package dependencies for unexpected changes.
