TeamPCP Used Mini Shai-Hulud Worm to Poison Over 400 npm and PyPI Packages
Source: Hackread · Category: Supply Chain
TeamPCP used Mini Shai-Hulud self-propagating worm to hijack OIDC tokens and poison 400+ npm and PyPI packages (TanStack, Mistral AI, UiPath). Law firms relying on these open-source dependencies or advising software clients must audit package versions and rebuild any internal tools using affected libraries.