Skip to content

Security1 publisher2 min readPublished

TeamPCP's package attacks reused the stolen-token techniques of S1ngularity and Shai-Hulud

Two TeamPCP-linked actors are under arrest after package compromises that ReversingLabs says caused a suspected hundreds of millions of dollars in damages. The waves since September 2025 began with a stolen publishing credential and reached victims through updates their own pipelines installed.

The Watch · Security desk

Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

Illustration accompanying TeamPCP's package attacks reused the stolen-token techniques of S1ngularity and Shai-Hulud
Generated illustration

What happened

  • In September 2025, S1ngularity hijacked several Nx packages and pushed malicious versions that made victims' machines upload secrets to GitHub repositories later made public.
  • Shai-Hulud followed within weeks, running on credentials S1ngularity had stolen and spreading a worm that exfiltrated secrets through GitHub.
  • TeamPCP's attacks began in spring 2026, and ReversingLabs puts the group behind CanisterWorm, CanisterSprawl and Mini Shai-Hulud.
  • The malicious versions in these attacks usually stayed online for only a few hours, which ReversingLabs says was enough to reach many victims.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • exposure Security scanners and AI tools are on the target list. Software a team installs to check or speed up its builds can itself carry an attacker into those builds.
  • decision A maintainer who still publishes with a long-lived token that needs no second check is one stolen secret away from shipping malware to every downstream install. How long that token lives, and what it can do, is the choice these waves force.
  • precedent Each wave fed on credentials an earlier one stole. Tokens exposed in the 2025 dumps to public GitHub repositories and never rotated remain an entry point for anyone holding them, arrests or not.

Every intrusion ReversingLabs describes starts with a credential belonging to the supplier. S1ngularity pulled a token from a repository and used its generous read/write permissions [6]. The firm lists misconfigured repositories and upload pipelines as one of the most common ways attackers get such credentials. Reuse of credentials stolen earlier and social engineering are the others [14]. Publishers had long used long-lived tokens to speed up releases, and publishing needed nothing beyond the token [15].

Both 2025 payloads used what they found on the victim's machine. The Shai-Hulud worm searched for npm tokens and used them to push updates to other packages [8]. S1ngularity used the AI agents already on the machine to move its attack forward [5].

The malicious code went out through the supplier's own release channel. Attackers pick packages drawing upwards of millions of downloads a week [13]. Many sit on GitHub and npm, which already have established ways to push out updates [17]. Victims then take the new version automatically or by hand [16]. ReversingLabs argues that automated updating assumes every update is safe, and that the assumption fails in practice [18]. By the firm's own account, a pipeline that holds new releases for longer than the few hours a malicious version usually stays up would have skipped the typical poisoned release [1].

The technique predates TeamPCP. ReversingLabs counted a 73% increase in detected malicious open source packages in 2025 [3]. It does not tie TeamPCP directly to S1ngularity or the original Shai-Hulud. It says the 2025 attacks cannot be clearly attributed to the group, though comparisons are often drawn, and that TeamPCP used similar techniques [9].

All of the attribution here comes from ReversingLabs. The firm sells Spectra Assure, a software supply chain security product [19]. It says TeamPCP was responsible for many of the recent compromises [2]. It did not name the two people arrested, the arresting authority or the charges [1].

What to watch

  • Whether the arresting authority names the two TeamPCP-linked actors and files charges covering CanisterWorm, CanisterSprawl or Mini Shai-Hulud.
  • New npm or GitHub package compromises that harvest publishing tokens after the arrests, which would show the method has outlasted the group.
  • An estimate of TeamPCP's damages from someone other than ReversingLabs, as a check on the suspected hundreds of millions of dollars.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories