As cited
Copy frozen at (site build).
threat intel
Risky Bulletin: Shai-Hulud goes open-source
Source code for the Shai-Hulud worm, used in recent supply chain attacks against npm and PyPI repositories, was publicly released on a hacking forum by individuals claiming affiliation with TeamPCP. The worm had previously compromised the TanStack React framework and spread to approximately 400 packages, including libraries used by Mistral and UiPath.
Why it matters: Open-source developers and security teams maintaining npm and PyPI dependencies face immediate risk from publicly available exploit code that has already demonstrated ability to compromise high-profile frameworks and propagate through package ecosystems.
- Source published
- First seen by Cybersecurity Tracker