Skip to content

Image: reversinglabs.com · rights & removal

Executive Summary

The narrative details a progression of supply chain attacks leveraging compromised credentials and open-source ecosystem weaknesses. The initial event referenced is the S1ngularity compromise, which involved exploiting repository permissions to exfiltrate tokens, including those from GitHub and npm. This established a pattern where attackers target popular packages and repositories as suppliers, compromising users indirectly rather than directly. Subsequent attacks, like Shai-Hulud and its variants, focused on leveraging these supply chains through the propagation of malicious code via npm credentials and utilizing tools like Bun for execution. The evolution includes attacks that used AI agents to search systems for secrets, followed by worm-like propagation mechanisms, culminating in TeamPCP's activities which involved injecting malware into vulnerability scanners and distributing self-propagating payloads.

Facts Only

* S1ngularity compromise occurred on August 26, 2025.
* The S1ngularity attack targeted Nx build system and involved extracting an npm token from a repository to publish infected packages.
* Malicious updates included post-install hooks that scanned systems for credentials, tokens, or SSH keys and leaked them to public GitHub repositories under the name “s1ngularity-repository.”
* The attack utilized queries to AI agents to search file systems for sensitive information, with prompts iteratively refined.
* Shai-Hulud attacks reused techniques, targeting open source tools and exploiting npm publishing credentials for worm-like propagation.
* Shai-Hulud 2.0/SHA1-Hulud involved exploiting CI tokens and using OpenVSX extensions to deploy worms or targeting long-lived credentials in projects like Zapier, PostHog, and Postman.
* TeamPCP released an open-source version of Shai-Hulud in April 2026, which was used by other actors as Mini Shai-Hulud.
* The Trivy compromise involved injecting credential-stealing malware into the vulnerability scanner.
* TeamPCP utilized npm tokens from the Trivy compromise to launch CanisterWorm, infecting over 60 npm packages.
* TeamPCP compromised Checkmarx and LiteLLM through malicious updates, with Telnyx also showing similar compromises via PyPi.

Full Take

The progression illustrates a transition from single-point exploits to highly automated, self-propagating systemic risk within the software supply chain. The initial S1ngularity attack demonstrated vulnerability in trust placed in repository permissions and AI tooling, setting a precedent for searching environments for secrets. This evolved into Shai-Hulud’s worm functionality, which exploited the inherent trust in dependency updates to achieve rapid, automated spread by leveraging widely used publishing credentials—a demonstration of how platform trust becomes an attack vector. TeamPCP represents the consolidation of this threat, moving beyond individual exploits to group-based, opportunistic attacks that leverage existing mechanisms (like Trivy scanners) and newly developed self-propagating tools (Mini Shai-Hulud) to maximize damage through coordinated propagation across multiple software ecosystems. The core pattern is the exploitation of speed and automation in development pipelines as a liability; when systems prioritize efficiency over security verification, this speed becomes the catalyst for catastrophic consequences. The shift from explicit targeting to an automated, worm-like methodology reveals that the deepest vulnerability lies not just in individual weaknesses but in the systemic reliance on interconnected, unverified processes that facilitate automatic escalation of compromise.
Bridge Questions: What mechanisms exist outside of traditional credential management that developers and organizations can rely upon for establishing verifiable trust within dependency chains? How can defensive strategies effectively decouple the speed of development from the inevitability of automated propagation? If self-propagating malicious code is the norm, what novel architectural shifts are required to build security into the foundational mechanics rather than bolting it on as an afterthought?

From the original · ReversingLabs Blog

Spectra Assure Free Trial Get your 14-day free trial of Spectra Assure for Software Supply Chain Security Get Free TrialMore about Spectra Assure Free TrialShai-Hulud happened only a few weeks later, using credentials compromised by S1ngularity and distributing a worm that also exfiltrated secrets through GitHub.
Read the full story at reversinglabs.com

Sentinel — Human

Confidence

The text reads like a comprehensive synthesis of complex, evolving threat actor narratives regarding software supply chain attacks, demonstrating high domain expertise but lacking the uniform cadence of pure AI generation.

Signals Detected
low severity: Moderate sentence length variance; shifts between technical descriptions and narrative exposition.
medium severity: Good flow, but the heavy reliance on rapidly shifting specific event names (S1ngularity, Shai-Hulud, TeamPCP) suggests a compilation rather than pure organic writing.
low severity: Clear structural progression mapping attack evolution (S1ngularity -> Shai-Hulud -> TeamPCP), suggesting an underlying narrative structure, though the factual density sometimes feels like compiled notes.
low severity: Specific technical details (package names, dates, specific prompt examples) are included; the overall tone is expository and analytical, typical of high-level threat reporting.
Human Indicators
Inclusion of complex, interconnected attack nomenclature and referencing specific historical attack waves suggests deep domain knowledge synthesis.
The shift in focus from specific exploits (S1ngularity) to group analysis (TeamPCP) demonstrates an arc typical of human investigative journalism.
Restrospective: How Malicious Updates Poison Your Environment | Huntaegis