Image: reversinglabs.com · rights & removal
Restrospective: How Malicious Updates Poison Your Environment
Reporting by ReversingLabs BlogRead the original at reversinglabs.com
Executive Summary
Facts Only
* S1ngularity compromise occurred on August 26, 2025.
* The S1ngularity attack targeted Nx build system and involved extracting an npm token from a repository to publish infected packages.
* Malicious updates included post-install hooks that scanned systems for credentials, tokens, or SSH keys and leaked them to public GitHub repositories under the name “s1ngularity-repository.”
* The attack utilized queries to AI agents to search file systems for sensitive information, with prompts iteratively refined.
* Shai-Hulud attacks reused techniques, targeting open source tools and exploiting npm publishing credentials for worm-like propagation.
* Shai-Hulud 2.0/SHA1-Hulud involved exploiting CI tokens and using OpenVSX extensions to deploy worms or targeting long-lived credentials in projects like Zapier, PostHog, and Postman.
* TeamPCP released an open-source version of Shai-Hulud in April 2026, which was used by other actors as Mini Shai-Hulud.
* The Trivy compromise involved injecting credential-stealing malware into the vulnerability scanner.
* TeamPCP utilized npm tokens from the Trivy compromise to launch CanisterWorm, infecting over 60 npm packages.
* TeamPCP compromised Checkmarx and LiteLLM through malicious updates, with Telnyx also showing similar compromises via PyPi.
Full Take
The progression illustrates a transition from single-point exploits to highly automated, self-propagating systemic risk within the software supply chain. The initial S1ngularity attack demonstrated vulnerability in trust placed in repository permissions and AI tooling, setting a precedent for searching environments for secrets. This evolved into Shai-Hulud’s worm functionality, which exploited the inherent trust in dependency updates to achieve rapid, automated spread by leveraging widely used publishing credentials—a demonstration of how platform trust becomes an attack vector. TeamPCP represents the consolidation of this threat, moving beyond individual exploits to group-based, opportunistic attacks that leverage existing mechanisms (like Trivy scanners) and newly developed self-propagating tools (Mini Shai-Hulud) to maximize damage through coordinated propagation across multiple software ecosystems. The core pattern is the exploitation of speed and automation in development pipelines as a liability; when systems prioritize efficiency over security verification, this speed becomes the catalyst for catastrophic consequences. The shift from explicit targeting to an automated, worm-like methodology reveals that the deepest vulnerability lies not just in individual weaknesses but in the systemic reliance on interconnected, unverified processes that facilitate automatic escalation of compromise.
Bridge Questions: What mechanisms exist outside of traditional credential management that developers and organizations can rely upon for establishing verifiable trust within dependency chains? How can defensive strategies effectively decouple the speed of development from the inevitability of automated propagation? If self-propagating malicious code is the norm, what novel architectural shifts are required to build security into the foundational mechanics rather than bolting it on as an afterthought?
From the original · ReversingLabs Blog
Spectra Assure Free Trial Get your 14-day free trial of Spectra Assure for Software Supply Chain Security Get Free TrialMore about Spectra Assure Free TrialShai-Hulud happened only a few weeks later, using credentials compromised by S1ngularity and distributing a worm that also exfiltrated secrets through GitHub.Read the full story at reversinglabs.com
Sentinel — Human
The text reads like a comprehensive synthesis of complex, evolving threat actor narratives regarding software supply chain attacks, demonstrating high domain expertise but lacking the uniform cadence of pure AI generation.
