www.securityweek.com 6/9/2026, 12:01:29 PM · external

Supply chain malware Shai-Hulud targets NPM and PyPI packages

Supply chain malware Shai-Hulud targets NPM and PyPI packages
CyberSIXT Evidence Panel
Primary Source harness.io
Threat Actor

SECURITY researchers have reported new iterations of the Shai-Hulud supply chain attack, which have affected over 100 packages across the NPM and PyPI ecosystems since September 2025. The malware, demonstrated by the hacking group TeamPCP, has resulted in multiple campaigns targeting the open source software community, with growing attack waves. Two notable variants are the Miasma and Hades.

View Primary Source Via www.securityweek.com

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline