← العودة للجدول
Mini Shai-Hulud: Frequently asked questions about the TeamPCP npm and PyPI supply chain campaign
📅 2026-05-21 18:28:22
🟢 Low 🔥 No Tenable Blog Supply Chain Network

📋 الوصف الكامل

A self-propagating worm has compromised more than 170 npm and PyPI packages, defeating provenance attestation and breaching OpenAI and Mistral AI. Here is what you need to know.Key takeawaysMini Shai-Hulud is a self-propagating worm by TeamPCP that steals developer and cloud credentials across the npm and PyPI ecosystems.The campaign achieved a critical security first by compromising packages with

💻 الأنظمة المتأثرة

⚠️ نوع التهديد

Supply Chain

📡 المصدر

Tenable Blog

✅ الحلول والتخفيف

Apply vendor security patch

🔗 المصدر الأصلي ←