Two TeamPCP-linked actors are under arrest after package compromises that ReversingLabs says caused a suspected hundreds of millions of dollars in damages. The waves since September 2025 began with a stolen publishing credential and reached victims through updates their own pipelines installed.
Reality
- Evidence35
- Adoption
- Insufficient
- Hype gap+25
- Incentives75
- Confidence35
Two men arrested in Australia this week are alleged TeamPCP members. The AFP estimate filed alongside the case puts the worm's take at more than 500,000 credentials and 300GB of data, and that scale makes token lifetime the live question.
Perspective Coverage
17 publishers
- Builder
- Builder 33%
- Operator
- Operator 50%
- Investor
- Investor 17%
Reality
- Evidence68
- Adoption
- Insufficient
- Hype gap+25
- Incentives55
- Confidence62
September's wave altered more than 500 npm package versions and November's backdoored 796, both by republishing under a fresh version number, which is exactly the thing an exact pin declines to fetch.
Reality
- Evidence62
- Adoption
- Insufficient
- Hype gap+15
- Incentives
- Insufficient
- Confidence58
ReversingLabs found tw-pkgprobe-7731 claiming to be an authorized Twilio HackerOne research probe while it tried to exfiltrate data, and its 2026 count of malicious npm packages passed all of 2024 by the end of August.
Reality
- Evidence60
- Adoption25
- Hype gap+15
- Incentives78
- Confidence55
GitGuardian says the ChainDrop worm reached 444 npm packages by planting a SessionStart hook in Claude Code and a folderOpen task in VS Code, and the publishing credential it steals is used to republish inside the same session.
Reality
- Evidence45
- Adoption55
- Hype gap+22
- Incentives80
- Confidence42
GitGuardian counted a 34 percent rise in new leaked secrets against 43 percent growth in commits, so the rate per commit slipped about six percent even as the raw total set the company's single-year record.
Publishers:blog.gitguardian.com
Reality
- Evidence42
- Adoption66
- Hype gap+28
- Incentives80
- Confidence55
GTIG's 2026 accounting traces one crew from package-registry compromises on PyPI, npm and Docker Hub to agent instructions that planned and ran the campaign, then out to public malware releases anyone can reuse.
Reality
- Evidence48
- Adoption45
- Hype gap+22
- Incentives72
- Confidence45
Aikido says the pair, both in their early 20s, ran TeamPCP's npm supply chain campaigns with a worm they cloned from Shai-Hulud. Whoever wrote the original is still unidentified, and the code is still published.
Reality
- Evidence41
- Adoption44
- Hype gap−6
- Incentives63
- Confidence45
Four core SAP build packages shipped an identical 11.6MB credential stealer. Because npm trusted the whole cap-js repository rather than one branch, a commit pushed to an unused branch was enough to publish them.
Publishers:stepsecurity.io
Reality
- Evidence60
- Adoption38
- Hype gap+15
- Incentives78
- Confidence55
Mandiant traced the Q2 2026 campaign to an AI coding chatbot, one prompt and a set of agent instructions that ran the scanning pipeline, fixed its own errors and rotated IPs with nobody at the keyboard.
Perspective Coverage
3 publishers
- Builder
- Builder 30%
- Operator
- Operator 57%
- Investor
- Investor 13%
Reality
- Evidence58
- Adoption62
- Hype gap+24
- Incentives70
- Confidence66
The provenance on @7nohe/openapi-react-query-codegen was accurate about every question it was built to answer, which is why the Docker Security Dispatch reaches instead for a five-day resolution cooldown that npm ci does not apply.
Reality
- Evidence47
- Adoption
- Insufficient
- Hype gap+12
- Incentives72
- Confidence55
The count of places this worm looks for secrets more than doubled between builds, and the additions sit in CI/CD and developer tooling, which is where the standing tokens that make a supply chain attack portable actually live.
Reality
- Evidence44
- Adoption
- Insufficient
- Hype gap+26
- Incentives78
- Confidence52
Shai-Hulud is on its fourth iteration. Trivy, Axios and LiteLLM have all shipped compromised releases. ReversingLabs is giving away a plugin that checks every package request against a reputation index inside Artifactory itself.
Reality
- Evidence38
- Adoption8
- Hype gap+22
- Incentives85
- Confidence45
StepSecurity's first annual report logs 56 confirmed supply chain compromises and says plainly that these are its own alerts. The February change is the finding; explaining it is the hard part.
Reality
- Evidence46
- Adoption42
- Hype gap+16
- Incentives79
- Confidence51
Unit 42 says a worm hidden in more than 400 npm packages read GitHub Actions runner memory for temporary OIDC tokens. An SBOM generated at the end of the build would not have seen any of it.
Reality
- Evidence55
- Adoption62
- Hype gap+18
- Incentives80
- Confidence52
The poisoned keyv releases were signed by GitHub Actions and the attestation was accurate. It certified a build whose source had already been taken over.
Reality
- Evidence34
- Adoption46
- Hype gap+18
- Incentives76
- Confidence41
A dev.to post scanned the domains behind the top 5,000 npm packages and found 18 with registration or email-security anomalies. The aggregate numbers matter more than the 18, and the headline overstates both.
Reality
- Evidence24
- Adoption
- Insufficient
- Hype gap+58
- Incentives62
- Confidence30
SOCRadar's record-level data puts 95 percent of identified victims before the poisoned LiteLLM packages ever hit PyPI. Anyone who rotated only what LiteLLM touched is still exposed.
Reality
- Evidence52
- Adoption68
- Hype gap+12
- Incentives66
- Confidence55