MEDIUMSupply Chain
Global

Worm Redux: Fresh Mini Shai-Hulud Infections Bite Supply Chain

·Source: Dark Reading

Updated:

Executive Summary

Hundreds of npm packages infected by the self-propagating, credential-stealing worm from TeamPCP are related to the open source TanStack ecosystem.

Analysis

Hundreds of npm packages infected by the self-propagating, credential-stealing worm from TeamPCP are related to the open source TanStack ecosystem.
Source Attribution

Originally published by Dark Reading on May 12, 2026.

Related Threats