Hackers Poison Trusted Software Updates to Steal Developer and Cloud Credentials
ReversingLabs traces S1ngularity, Shai-Hulud, and TeamPCP campaigns that poisoned npm updates to steal developer and cloud credentials.
A ReversingLabs report summarized by Cyber Security News describes supply-chain malware in which S1ngularity, the Shai-Hulud worm, and activity linked to TeamPCP poisoned trusted package updates to steal developer and cloud credentials. In August 2025, attackers compromised Nx packages through a crafted pull request, replaced a CI script, and published packages whose post-install hooks harvested tokens, SSH keys, and cloud secrets, created public GitHub repositories for exfiltration, and prompted local AI tools to find credentials. Shai-Hulud reused stolen npm publishing tokens to infect further releases. TeamPCP later used an unrotated Trivy token to poison CI/CD version tags on March 19, 2026, and distributed CanisterWorm to more than 60 npm packages, with Checkmarx, LiteLLM, and Telnyx also affected.