Hackers Poison Trusted Software Updates to Steal Developer and Cloud Credentials
ReversingLabs traces S1ngularity, Shai-Hulud, and TeamPCP campaigns that poisoned npm updates to steal developer and cloud credentials.
A ReversingLabs report summarized by Cyber Security News describes supply-chain malware in which S1ngularity, the Shai-Hulud worm, and activity linked to TeamPCP poisoned trusted package updates to steal developer and cloud credentials. In August 2025, attackers compromised Nx packages through a crafted pull request, replaced a CI script, and published packages whose post-install hooks harvested tokens, SSH keys, and cloud secrets, created public GitHub repositories for exfiltration, and prompted local AI tools to find credentials. Shai-Hulud reused stolen npm publishing tokens to infect further releases. TeamPCP later used an unrotated Trivy token to poison CI/CD version tags on March 19, 2026, and distributed CanisterWorm to more than 60 npm packages, with Checkmarx, LiteLLM, and Telnyx also affected.
- S1ngularity compromised Nx packages in August 2025 via a crafted pull request and stolen token.
- Post-install hooks stole tokens, SSH keys, and cloud credentials, then exfiltrated them to public GitHub repos.
- The payload prompted local AI tools to search machines for credential locations.
- Shai-Hulud reused npm publishing tokens to insert malware into further package releases.
- After Trivy tag poisoning, CanisterWorm hit 60-plus npm packages, plus Checkmarx, LiteLLM, and Telnyx.
Indicators of compromiseauto-extracted · verify before use · export allAll →
| Type | Indicator | Context |
|---|---|---|
| sha1 | 2379ac0e03b1a67c4ca5693136eff4945e644a91 | y malware sample referenced in the source SHA-1 sample hash 2379ac0e03b1a67c4ca5693136eff4945e644a91 S1ngularity malware sample referenced in the source SHA-1 s |
| sha1 | b4f20b39aa6df1002872f07973024d85aa49abaf | y malware sample referenced in the source SHA-1 sample hash b4f20b39aa6df1002872f07973024d85aa49abaf S1ngularity malware sample referenced in the source SHA-1 s |
| sha1 | d2438106211ebd12c4f0a248848bc9864c97a3c0 | S1ngularity to expose stolen information SHA-1 sample hash d2438106211ebd12c4f0a248848bc9864c97a3c0 S1ngularity malware sample referenced in the source SHA-1 s |
| sha1 | e5d1f3c45ee7cca6ae59cf64e0573050bbe136ec | y malware sample referenced in the source SHA-1 sample hash e5d1f3c45ee7cca6ae59cf64e0573050bbe136ec S1ngularity malware sample referenced in the source Note: I |
Full article836 words · extracted from cybersecuritynews.com · click to collapse
Hackers are turning trusted software updates into a route for stealing developer and cloud credentials. Recent supply chain incidents show how a single altered package, build action, or publishing token can place malware inside routine development workflows.
The risk is not limited to one product or programming community. After obtaining a maintainer token or access to an automated release pipeline, attackers can deliver code through an update that users and security tools may already trust.
ReversingLabs said in a report shared with Cyber Security News (CSN) that S1ngularity, Shai-Hulud, and TeamPCP show how quickly a compromise can spread from one supplier to many downstream organizations.
The report describes a chain of stolen credentials, poisoned releases, and repeat attacks across open source ecosystems.
The consequences reach beyond a developer laptop. Stolen GitHub, npm, cloud, and SSH credentials can expose source code, cloud resources, deployment systems, and other packages. In several cases, malware used credentials taken from one victim to publish the next poisoned update.
Hackers Poison Trusted Software Updates
The S1ngularity incident illustrates why trusted software distribution is a valuable target. Attackers compromised Nx packages after using a crafted pull request to obtain a token, replace a CI script, and trigger a publishing workflow.
The infected packages then ran post-install hooks on developer machines, a pattern detailed in CSN’s coverage of Nx package credential theft during the 2025 campaign.
Those hooks searched for valuable data, including tokens, credentials, and SSH keys. They also used GitHub credentials found on the host to create public repositories, giving the attackers a direct route to retrieve stolen material.
The campaign was unusual because its malicious code also prompted local AI tools to search the file system for likely credential locations.
The report, published September 30, 2026, places the Nx compromise on August 26, 2025. It treats the original campaigns separately from TeamPCP, whose involvement in earlier incidents remains unproven.
.webp)
The report says the prompts sought leads to GitHub and npm tokens, cloud credentials, and SSH keys. This makes the attack more than a conventional password stealer: it attempted to turn a developer’s own assistant into a local discovery tool.
Readers can see the broader impact in AI tool credential targeting, including the data the malware sought from affected systems.
S1ngularity also showed why long-lived publishing tokens are risky. The stolen npm token enabled infected packages to be released, while compromised updates gained the benefit of an established package’s reputation.
Nx later adopted a trusted-publisher approach using short-lived, per-run credentials, reducing the value of a token stolen from a repository.
Credential Worms
Shai-Hulud expanded this model by making it self-propagating. The worm searched compromised systems for npm publishing credentials, used them to identify packages a victim could publish, and inserted malicious code into further releases.
That let it spread without a separate software flaw at each target, as explained in the Shai-Hulud worm attack investigation. Later activity attributed to or associated with TeamPCP showed how attackers can reuse an earlier breach.
In the Trivy incident, a privileged token was extracted in February 2026, but incomplete credential rotation left a path for attackers to publish a malicious update on March 19 through an automated system.
The attackers altered version tags used by CI/CD workflows, a technique covered in CSN’s report on Trivy tag poisoning attack. The credential-stealing payload targeted running workflows, where secrets can be especially valuable.
After the Trivy compromise, the group used harvested npm tokens to distribute CanisterWorm, which compromised more than 60 npm packages. Checkmarx, LiteLLM, and Telnyx were also affected, showing how stolen access can support successive intrusions.
Organizations should treat a poisoned update as a potential full credential compromise. They should replace long-lived publishing secrets with short-lived credentials, tightly limit token permissions, pin CI/CD dependencies to reviewed commits, and monitor publishing and repository activity for unexpected changes.
Teams that may have run an affected release should rotate exposed tokens promptly and check for unauthorized repositories, workflows, and package publications.
Indicators of compromise (IoCs):-
| Type | Indicator | Description |
|---|---|---|
| Repository name | s1ngularity-repository | Public GitHub repository name used by S1ngularity to expose stolen information |
| SHA-1 sample hash | d2438106211ebd12c4f0a248848bc9864c97a3c0 | S1ngularity malware sample referenced in the source |
| SHA-1 sample hash | b4f20b39aa6df1002872f07973024d85aa49abaf | S1ngularity malware sample referenced in the source |
| SHA-1 sample hash | 2379ac0e03b1a67c4ca5693136eff4945e644a91 | S1ngularity malware sample referenced in the source |
| SHA-1 sample hash | e5d1f3c45ee7cca6ae59cf64e0573050bbe136ec | S1ngularity malware sample referenced in the source |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC
Tushar is a senior cybersecurity and breach reporter. He specializes in covering cybersecurity news, trends, and emerging threats, data breaches, and malware attacks. With years of experience, he brings clarity and depth to complex security topics.