threat_intelligence2770 wordsRead on Huntaegis

Restrospective: How Malicious Updates Poison Your Environment

Spectra Assure Free Trial Get your 14-day free trial of Spectra Assure for Software Supply Chain Security Get Free TrialMore about Spectra Assure Free TrialIn 2026, supply chain attacks took center stage. The spring was a storm of open source packages being compromised into pushing malicious updates, infecting a variety of targets and causing untold amounts of damages. Recently, two actors associated with TeamPCP were arrested. TeamPCP was responsible for many of the recent supply chain compromises, making this an apt time to reflect on those attacks. This retrospective covers attacks from late 2025 to present day, explains how and why they work — and what lessons can be learned from them. Over the past year, a variety of attacks have happened in the software supply chain space. These attacks have been occurring for years, but 2025 brought a staggering 73% increase in detected malicious open source packages. Some heavy hitters occurred in 2025, predating TeamPCPs attacks starting in spring of 2026. The 2025 attacks are not clearly attributable to TeamPCP, although comparisons are frequently drawn. One big wave was in September 2025, with S1ngularity, which hijacked several Nx packages and pushed malicious versions, compromising the machines of users into uploading secrets to GitHub repositories which were later made public. This attack leveraged AI agents on the target machine to progress their attack. Shai-Hulud happened only a few weeks later, using credentials compromised by S1ngularity and distributing a worm that also exfiltrated secrets through GitHub. The worm propagated by finding npm tokens to further push updates to other packages, amplifying its effects. Going into 2026, TeamPCP took this ecosystem by storm, rapidly conducting attacks. While they are not directly tied to S1ngularity or the original Shai-Hulud, they did leverage similar techniques. They were behind CanisterWorm, CanisterSprawl and Mini Shai-Hulud. They focused heavily on this indirect method of attacks, targeting open source tools and GitHub repositories. TeamPCP has caused a suspected hundreds of millions of dollars in damages through their supply chain techniques. These attacks chain together a series of weaknesses to get their desired results. They reach victims by targeting open source packages and products, instead of directly targeting individuals. This allows the malicious code to sneak into user environments automatically and unannounced. Usually, these malicious versions are only online for a few hours, but that is more than enough time to compromise many victims. The stage is set with an initial compromise. First, attackers need to select the appropriate victim. Many targets are on GitHub and npm, platforms which already have tried and true methods for pushing out updates. Attackers seek out popular packages that get upwards of millions of downloads per week. Targets are things like development platforms, security scanners, AI tools, or other tools that people use to help their workflows. These platforms and tools are the suppliers in the supply chain attack. Attackers gain their access by compromising important credentials and tokens related to the supplier. One of the most used methods for obtaining these credentials is through exploiting misconfigurations in the repositories or upload pipeline. This is how the S1ngularity attack started, pulling a token from the repository and capitalizing on its generous read/write permissions. Another common method is leveraging previously compromised credentials, meaning many of these attacks occur consecutively and chain together. Social engineering is another potential vector for extracting these credentials. Historically, long lived publishing tokens were used to streamline the publishing process, but that left organizations vulnerable to attacks when those tokens were compromised. No other authentication was required aside from the token, making it a very big hazard when compromised. With the compromised credentials, attackers then exploit other weaknesses, misconfigurations, or other elements of the CI/CD pipeline to push out their malicious version. The published version then cascades into multiple compromises. Once the version is pushed, it may be automatically or manually updated by victims, infecting them with malware. Technology moves fast. Automation speeds things up and in a perfect world, every update is safe. Unfortunately, reality is cruel, and that trust in an idealized system leaves organizations vulnerable. If the update or dependency is compromised, anyone who uses it can also be compromised. Something thought to be trusted may also bypass usual security controls, as opposed to entirely unknown downloads. The pipelines are designed for speed and efficiency, leaving security on the back burner, and the supply chain attack is the consequence. The nature of these attacks is explosive. It’s easy to visualize as a bomb going off, and many use the term “blast radius” to quantify the amount of damage done by supply chain attacks. By honing in on specific types of targets, attackers can compromise one link in the supply chain and then spread the damage across many other victims. Suppliers provide for many organizations, and have direct ties to their users. That relationship is what is being exploited. TeamPCP’s attack serves as an example to this effect, first targeting one organization, then finding other supplier targets within their initial victim pool to compromise next, continuing to spread their malware around. Within the past year there have been plenty of supply chain attacks, providing examples on overall trends and specific campaign nuances. These following are three examples of supply chain threats. Each of the examples holds many commonalities, but also have unique defining features. Examples are ordered chronologically, showing the progression of this attack type over the past year. These examples were chosen for notoriety and their individual novel features. The S1ngularity compromise happened on August 26, 2025, making it the earliest event this blog will cover. Other supply chain attacks predate it, but it came at the right time and with the right intensity to gain notoriety. It used some novel techniques, being one of the first major attacks to directly target AI tools against the target. It also sought out GitHub credentials and used them as part of the exfiltration route, much like patterns later attacks would follow. The attack targeted Nx, a build system used by developers. Nx has millions of weekly downloads. Multiple vulnerabilities were chained together to achieve the full compromise, starting with a carefully crafted pull request to Nx’s repository and extraction of a token. The attackers used this token to replace legitimate CI script with a malicious version and trigger a publishing workflow, and then covered their tracks by deleting branches and workflow runs. The script was used to exfiltrate Nx’s NPM token, which was used to publish infected Nx packages. What was delivered by this infection were post install hooks that scanned systems to find critical information, such as credentials, tokens, or SSH keys, then leaked said information on public GitHub repositories. By using GitHub credentials found on the victim's machine, the malware would post stolen information. These published repositories were all titled “s1ngularity-repository”, making it easy for attackers to search for the credentials and collect the data. The unique spelling helped make the target content easily searchable. Image 1.1, S1ngularity sample code showing the usage of “s1ngularity-repository” as the attacker’s exfiltration vector. Sample: d2438106211ebd12c4f0a248848bc9864c97a3c0 Something that made this attack stand out is the attacker’s usage of a victim's own AI tools against their machine. The malicious update contained code to query AI agents to search the file system and find files of interest. Image 1.2, Screenshot of prompt that was initially used by S1ngularity to get AI agents to seek out files that may contain credentials and other target information. Sample: b4f20b39aa6df1002872f07973024d85aa49abaf Image 1.3, Screenshot of revised prompt used by S1ngularity to get AI agents to seek out files that may contain credentials and other target information. The prompt asks the AI to use a penetration tester persona for seeking out the files. Sample d2438106211ebd12c4f0a248848bc9864c97a3c0 Image 1.4, Screenshot of revised prompt to get agent to seek out information attacker is interested, this time with the persona of working as a file-search agent. Sample: 2379ac0e03b1a67c4ca5693136eff4945e644a91 Figure 1.5, Screenshot of the final version of the prompt, released before the threat was taken down. Uses similar file-search agent prompt to image 1.4, but adds more specificity (Linux environment, excluding files based on directory). Sample: e5d1f3c45ee7cca6ae59cf64e0573050bbe136ec The prompt was intended to generate leads to potential locations for GitHub or NPM tokens, Cloud credentials, or SSH keys. Iteration on the prompt was likely an attempt to hone in on what prompt provided the most results while also avoiding the agent’s safeguards. At the time, not many attacks were leveraging AI tools to use in a living off the land like manner. In response to this attack, Nx’s moved to GitHubs Trusted Publisher model. This model seeks to stop the usage of long lasting tokens, replacing them with something short-lived and per-run. It helps eliminate token theft as a potential vulnerability for these types of compromise. It has been a little over a year exactly since Shai-Hulud took security by storm. Many attacks mirror the techniques from the initial wave, and variations of it continue to be used. Shai-Hulud initial wave on September 12, 2025, reused many of the techniques S1ngularity focused on, such as targeting open source tools, collecting secrets, and using GitHub accounts to exfiltrate its findings. The key differentiator was the worm functionality of Shai-Hulud. This method was very effective and led to rapid propagation. Shai-Hulud achieved its worm-like effect by targeting npm publishing credentials, then using said credentials to publish itself. Doing so allowed the worm to propagate without a specific software vulnerability. The continued use of Shai-Hulud variants goes to show how dangerous this self propagation is. After its initial wave, Shai-Hulud returned at the end of November in two separate attacks. These attacks are called Shai-Hulud 2.0 or SHA1-Hulud. Different outlets use these two names to describe one or both of the attacks. One attack started with a Pwn Request to exfiltrate a CI token, then deployed the worm through a malicious OpenVSX extension. The other attack targeted projects like Zapier, PostHog, and Postman by exploiting long-lived credentials found in compromised repositories. Both of these attacks had a more sophisticated version of Shai-Hulud. The second wave leveraged bun to execute the file with the malicious code. The worm traveled far and infected many systems. TeamPCP, which will be further discussed later, released a version of Shai-Hulud as open source in April of 2026. They readily encouraged other threat actors to use it, offering a $1000 USD reward to whoever conducted the biggest supply chain attack, utilizing their version of Shai-Hulud. Different attacks have been carried out with this version, which is referred to as Mini Shai-Hulud. Mini Shai Hulud is definitely connected to TeamPCP, but the 2025 Shai-Hulud activity is difficult to attribute. August brought one of the most recent Mini Shai Hulud attacks. ChainDrop utilized the Mini Shai-Hulud variant, combined with an obfuscated Bun JavaScript payload. Over 400 patches were released during the time it was active. The exfiltration will first attempt to be delivered through an HTTPS endpoint, but if that is unavailable, the malware creates a public GitHub repository, with a title that reinforces its identity: Shai-Hulud: Here We Go Again. Since Mini Shai-Hulud is already open source, it’s unclear if this attack is specifically connected to any of the prior ones. Shai-Hulud is and will continue to be a nightmare scenario. While steps have been taken to mitigate its type of spread, it still manages to be used successfully. It perfectly demonstrates why supply chain attacks are so serious. It’s exploiting the existing framework that keeps development moving quickly. With the propagation being automatic, the actors can be hands off once it starts, allowing the worm to do all the work. TeamPCP differs from the previous two because it encapsulates a group, rather than the attacks themselves. Shai-Hulud and S1ngularity serve as a prologue to the story that is TeamPCPs reign of terror in 2026. TeamPCP has been prevalent and their recent member arrests sparked the inspiration for this blog. The group carried out many attacks in 2026, focusing specifically on the supply chain. They are heavily associated with the ongoing waves of Mini Shai-Hulud variants, as they were responsible for the open source version published in May. TeamPCP started gaining notoriety in 2026. While they did publish Mini Shai-Hulud, they are less affiliated with the original attacks. They utilize the same techniques of the original Shai-Hulud, but are not necessarily the same actor. TeamPCP uses the information they steal as a launching point for further attacks, or as a means of extracting money from their victims. They are known to have engaged in extortion, even partnering with other threat actor groups to do so. A partnership with Vect ransomware-as-a-service group had TeamPCP provide Vect with credentials to use to launch attacks. TeamPCP is also known to have worked with the LAPSUS$ extortion group. The Trivy compromise is what brought TeamPCP into the spotlight. Trivy is a vulnerability scanner that TeamPCP injected with credential stealing malware. The attack started in February, with the extraction of a privileged access token. While Trivy did detect this, their credential rotation was incomplete. On March 19th, TeamPCP was able to push out their malicious update, and published it through Trivy’s automated systems, using a compromised service account. The attack specifically targeted workflows that were already running by modifying existing version tags, as tags are what CI/CD pipelines rely on. The malware self identified as “TeamPCP Cloud stealer.” After Trivy, several other pieces of software were also compromised. One was Checkmarx, who was initially compromised in relation to the Trivy attack, and during that attack a similar malicious update was pushed. Later, stolen Checkmarx data was uploaded onto the dark web. Another victim was LiteLLM, where attackers uploaded a malicious package directly to PyPi. Telnyx had a similar compromise as LiteLLM, with publication through PyPi. To really capitalize on the compromise, TeamPCP also distributed CanisterWorm. Using npm tokens they harvested from the Trivy compromise, they launched CanisterWorm and compromised over 60 npm packages. This worm perpetuates itself by finding npm tokens on the victim’s device, then finding the associated package to overwrite it with a malicious one. The similarities to Shai-Hulud are obvious, both using the same tactics to achieve similar results. After these original attacks, TeamPCP continued to use the information they gathered to perpetuate more attacks. Checkmarx dealt with a large data leak after their compromise. TeamPCP also released Mini Shai-Hulud, as discussed above, as well as potentially being involved with a few Mini Shai-Hulud variants that occurred after its publishing. Since Mini Shai-Hulud is open source, it is unclear what TeamPCP was directly involved with. Around the time of Mini Shai-Hulud’s open source release, they compromised TanStack utilizing the worm. Safe to say, TeamPCP has caused a lot of damage. They have been the poster child of supply chain attacks. However, just because they were successful, does not mean they would be so forever. Open source intelligence was used to track down some of the members of TeamPCP. Using a series of accounts connected by overlapping usernames, a suspect was identified. Two individuals in Australia were arrested in relation to this information, and the story is still developing. S1ngularity, Shai-Hulud, and TeamPCP are just a few of many players attacking the software supply chain. Looking into each threat gives insight on how these attacks work and why they are concerning. S1ngularity hit hard, and was the first to noticeably attempt leveraging AI agents on the victims devices to further the damage. Shai-Hulud soon followed, and kept iterating to become more and more of a threat. It pioneered the worm style supply chain attack, seeking out victim credentials to utilize in republishing itself to further spread. With an open source version available, it remains a threat to be very aware of. Variants and copycats are sure to continue to be an issue. Finally, TeamPCP as a group encapsulates so many of the trends in these attacks and common behavior of the actors. They were very public, making many public statements to engage with other cyber criminals or mess with victims. They caused hundreds of millions in damages. They were highly opportunistic, and focused their attention on the supply chain, leading to major damage. Now, more caution is being given to the supply chain and CI/CD pipelines, to mitigate these threats. Attacks like this will continue to happen, but reflecting on what has happened already is one of the steps to better prepare. The package poses as a security tool targeting developers looking to implement Internet-based apps with telecom networks. Aurastealer, ACRStealer, and RemusStealer, a new potential LumaStealer variant, show MaaS in action. Here's what you need to know.

How it works

Once you click Generate, Ollama reads this article and crafts 5 comprehension questions. Your answers are graded against the article content — general knowledge won't be enough. Score 70+ to count toward your certificate.

Questions are cached — you'll always get the same 5 for this article.