Security0 views

Hackers Behind Shai-Hulud Malware Arrested After Compromising 1,000+ Organizations

Authorities arrested two alleged members of the TeamPCP hacker group, creators of the **Shai-Hulud** malware that targeted over 1,000 organizations worldwide. The group primarily focused on compromising repositories in npm and PyPI, the package managers for JavaScript and Python respectively.

The malware operated as a worm, capable of self-propagating by automatically infecting and republishing legitimate packages using stolen credentials and tokens. Once installed, it extracted credentials from major platforms including **GitHub**, **AWS**, and **Kubernetes**, giving attackers broad access to development infrastructure and cloud resources.

The defendants face sentencing of 10 to 20 years or more in prison. The scale of this operation highlights the ongoing risk posed by supply chain attacks targeting open-source repositories, where a single compromised package can reach thousands of downstream users and organizations.