databreaches.net 6/17/2026, 12:31:47 PM · external

GitHub ignores alerts on ShaiHulud worm threatening dev supply

CyberSIXT Evidence Panel Source marked as original reporting
Primary Source therecord.media
Threat Actor

GITHUB rejected two vulnerability reports from Deep Specter Research concerning design flaws that may allow variants of the Shai-Hulud supply-chain worm to compromise numerous software packages and developer accounts globally. These reports were deemed ineligible and not a security risk, despite the ongoing threat posed by the worm.

Originating from the TeamPCP cybercrime group, these variants have been linked to significant breaches at organizations including the European Commission, AI firm Mercor, the LiteLLM package, GitHub itself, and Red Hat.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline