ADVERTISEMENT

Race to tear down open source: copycats reusing TeamPCP’s code in NPM attacks

Copycat hackers are competing to win $1,000 for the largest supply chain attack using Shai-Hulud, an open-sourced worm that has brought down a few major open-source projects. Malicious NPM packages are already appearing with nearly identical code, and researchers warn that this is only the beginning.

attack using Shai-Hulud

Image by Cybernews.

Ernestas Naprys
Ernestas Naprys Senior Journalist
May 18, 2026 Updated: May 18, 2026 3 min read
teampcp competition
Image by Cybernews.

New hackers adopting the malware

Jurgita Lapienyte justinasv Izabele Pukenaite vilius Ernestas Naprys Gintaras Radauskas
Don't miss our latest stories on Google News. Add us as your Preferred Source on Google
Add us as your Preferred Source on Google.
ADVERTISEMENT
  • @deadcode09284814/axios-util: a straightforward infostealer sending SSH keys, env variables, cloud credentials to an attacker-controlled server.
  • Axois-utils: runs a local DDoS botnet service written in GoLang, maintains persistence even after the malicious npm package is deleted. Targets the website with HTTP, TCP, UDP, and Reset requests.
  • Color-style-utils: another straightforward infostealer with no obfuscation or hiding techniques, collecting user IPs, geo location, and crypto wallets.

ADVERTISEMENT