Minacce · 135 giorni fa
Shai-Hulud non è più soltanto una campagna da tenere d’occhio. Il rilascio pubblico del source da parte di TeamPCP abbassa la barriera al riutilizzo, quindi il rischio si sposta da un singolo worm a un pattern di infezione ripetibile che altri attori possono clonare e riadattare negli ecosistemi npm. Ciò rende il blocco basato su hash e il framing specifico per attore troppo ristretti per la minaccia che ora hanno davanti gli sviluppatori.
6 fonti che coprono questa storia
Shai-Hulud Worm Clones Spread After Code Release
The release of Shai-Hulud source code spells trouble for software developers as researchers worry the self-replicating worm could scale.
Risky Bulletin: Shai-Hulud goes open-source
The source code for the Shai-Hulud worm has been released online, a dark web market admin was charged after a major OPSEC failure, France [Read More
TeamPCP Ups the Game, Releases Shai-Hulud Worm’s Source Code
The hacking group is encouraging miscreants to use the code in supply chain attacks, promising monetary rewards.
Malware crew TeamPCP open-sources its Shai-Hulud worm on GitHub
Where it’s been well and truly forked, seemingly without Microsoft’s code locker noticing
Shai-Hulud Goes Open Source | Datadog Security Labs
A static analysis of the open-sourced Shai-Hulud offensive framework attributed to TeamPCP, covering its credential harvesting, supply chain poisoning, and exfiltration capabilities.
The latest Shai-Hulud malware campaign weaponizes GitHub Actions, poisoned caches, IDE hooks, and dynamic infrastructure to spread across software supply chains while stealing cloud, AI, crypto, and developer credentials at scale.
Part of the PlainSec briefing for 2026-05-16