{"id":26257,"date":"2026-09-25T17:00:32","date_gmt":"2026-09-26T01:00:32","guid":{"rendered":"https:\/\/www.palada.net\/index.php\/2026\/09\/25\/shai-hulud-worm-arrests-why-this-is-not-the-end-2\/"},"modified":"2026-09-25T17:00:32","modified_gmt":"2026-09-26T01:00:32","slug":"shai-hulud-worm-arrests-why-this-is-not-the-end-2","status":"publish","type":"post","link":"https:\/\/www.palada.net\/index.php\/2026\/09\/25\/shai-hulud-worm-arrests-why-this-is-not-the-end-2\/","title":{"rendered":"Shai-Hulud worm arrests: Why this is not the end"},"content":{"rendered":"<div class=\"rich-text_richText__UyrDZ\" data-anchor-headings=\"true\" data-component=\"rich-text\" data-reader-view=\"false\">\n<div class=\"payload-richtext\">\n<div class=\"callout-block_highlight__zUB32\" data-accent-bar=\"true\" data-background=\"highlight-gray\" data-component=\"callout-block\">\n<p class=\"callout-block_heading__sSD7c\" data-subtitle=\"lg\">Key takeaways<\/p>\n<div class=\"rich-text_richText__UyrDZ\" data-component=\"rich-text\" data-reader-view=\"false\">\n<div class=\"payload-richtext\">\n<ul class=\"list-bullet\">\n<li class=\"\" value=\"1\">TeamPCP franchised its own attack. <\/li>\n<li class=\"\" value=\"2\">Arrests don&#8217;t unpublish code. <\/li>\n<li class=\"\" value=\"3\">The fix is pipeline hygiene, not law enforcement. <\/li>\n<li class=\"\" value=\"4\">Supply chain integrity is now table stakes. <\/li>\n<\/ul>\n<\/div>\n<\/div>\n<\/div>\n<p>Australian law enforcement officials, working with the U.S. Federal Bureau of Investigation, arrested two men Wednesday on cybercrime charges. The men allegedly are members of a global cybercrime syndicate suspected of creating the Shai-Hulud worm, malicious software that victimized thousands of businesses around the world.<\/p>\n<p>The Australian Federal Police said the syndicate, TeamPCP, is estimated to have enabled the theft of more than 500,000 credentials and at least 300GB of data. The financial impact of the gang\u2019s activities includes global remediation costs in the hundreds of millions of dollars, the AFP said.<\/p>\n<p>The group made headlines in late 2025 when it began compromising corporate cloud environments with the self-propagating worm. Shai-Hulud stole credentials from developers working on projects that use open source code repositories such as GitHub and npm.<\/p>\n<p>It was<a href=\"https:\/\/www.reversinglabs.com\/blog\/shai-hulud-worm-npm\"> <span style=\"text-decoration:underline\">originally documented in 2025 by ReversingLabs (RL) researchers<\/span><\/a>, who noted that Shai-Hulud systematically harvested npm tokens, GitHub credentials, and cloud provider secrets from compromised developer environments using tools such as TruffleHog. The malware then leveraged those credentials to tamper with additional packages and repositories, effectively turning the software supply chain itself into a propagation mechanism.<\/p>\n<p>AFP Commander Graeme Marshall<a href=\"https:\/\/www.afp.gov.au\/news-centre\/media-release\/two-wa-men-charged-following-afp-fbi-wapf-disruption-alleged-global\"> <span style=\"text-decoration:underline\">said in a statement<\/span><\/a> about the arrests:<\/p>\n<p style=\"padding-inline-start:40px\"><em>\u201cCybercrime syndicates are becoming increasingly organized and often operate like professional businesses, but our investigators are relentless in tracking down criminals who attempt to exploit digital anonymity to attack our community.\u201d<\/em><\/p>\n<p>Here\u2019s what the arrests of the two alleged threat actors involved in the cascading supply chain attack means.<\/p>\n<p>[ <a href=\"https:\/\/www.reversinglabs.com\/blog\/why-rl-built-spectra-assure-community\"><strong>Why RL Built Spectra Assure Community<\/strong><\/a><strong> | <\/strong><a href=\"https:\/\/secure.software\/user\/signup?__hstc=60854195.09b88d157f9d43142772cad20253e99d.1783549571086.1787926704216.1787935178947.109&amp;__hssc=60854195.2.1787935178947&amp;__hsfp=1efe410361bbe9ac5c4b17bb92851af3\"><strong>Sign up for Free <\/strong><\/a><strong>]<\/strong><\/p>\n<h2 id=\"a-collaborative-effort\">A collaborative effort<\/h2>\n<p>TeamPCP has been one of the most active threat actors over the last year, said Danny Jenkins, CEO of Threatlocker, and arrests in connection with the group are an incredibly important step toward dismantling it.<\/p>\n<p style=\"padding-inline-start:40px\"><em>\u201cLike with most organized crime investigations, law enforcement will be looking to learn as much as they can from the individuals arrested. The arrests also speak well of the extensive cooperation the U.S. and Australia have had on cybersecurity through both law enforcement and the Five Eyes intelligence-sharing network.\u201d<\/em><br \/><em>\u2014<\/em><a href=\"https:\/\/www.linkedin.com\/in\/dannyjenkinscyber\"><span style=\"text-decoration:underline\">Danny Jenkins<\/span><\/a><\/p>\n<p>Lina Dabit, executive director and field CISO at Optiv Canada, said she is impressed to see collaboration beyond just law enforcement agencies to include private-sector organizations.<\/p>\n<p style=\"padding-inline-start:40px\"><em>\u201cMake no mistake, threat actor groups collaborate better than we do. Seeing investigations like this one highlights how critical it is for defenders to work better together.\u201d<\/em><br \/><em>\u2014<\/em><a href=\"https:\/\/www.linkedin.com\/in\/lina-dabit-7a78a8173?originalSubdomain=ca\"><span style=\"text-decoration:underline\">Lina Dabit<\/span><\/a><\/p>\n<p>However, Dabit said that arresting two principal participants won\u2019t end TeamPCP because \u201coftentimes when you cut the head off the snake, it grows two more.\u201d<\/p>\n<p>Jacob Krell, senior director for secure AI solutions and cybersecurity at Suzu Labs, said the arrests show the value of private-sector intelligence feeding into traditional law enforcement.<\/p>\n<p style=\"padding-inline-start:40px\"><em>\u201cThe joint AFP-FBI investigation began in April after cybersecurity companies provided key information, and arrests followed months later.\u201d<\/em><br \/>\u2014<a href=\"https:\/\/www.linkedin.com\/in\/jacob-krell\"><span style=\"text-decoration:underline\">Jacob Krell<\/span><\/a><\/p>\n<h2 id=\"an-attack-with-scale-via-open-sourcing\">An attack with scale via open-sourcing<\/h2>\n<p>Krell said one thing that distinguishes TeamPCP in the cybercrime sphere is scale.<\/p>\n<p>TeamPCP is blamed for what<a href=\"https:\/\/krebsonsecurity.com\/2026\/08\/two-alleged-teampcp-hackers-arrested-in-australia\/\"> <span style=\"text-decoration:underline\">KrebsOnSecurity<\/span><\/a> describes as the longest-running spree of software supply chain attacks on record, Krell noted.\u00a0<\/p>\n<p>They are also efficient. \u201cIn just one five-day period in March, CloudSEK data analyzed by StepSecurity showed 78,330 secrets exfiltrated from the CI\/CD pipelines of 2,186 organizations, including public companies with a combined market capitalization above $6 trillion,\u201d he said.<\/p>\n<p>Another distinguishing feature of the group is the way it <a href=\"https:\/\/www.reversinglabs.com\/blog\/the-shai-hulud-code-drop\"><span style=\"text-decoration:underline\">franchised supply chain attacks by open-sourcing the technique<\/span><\/a>.<\/p>\n<p style=\"padding-inline-start:40px\"><em>\u201cRansomware-as-a-service groups generally control access to their operational tooling through an affiliate structure. TeamPCP did something different. It released Shai-Hulud as open-source attack tooling and then crowdsourced its deployment through a paid contest.\u201d<\/em><br \/><em>\u2014<\/em>Jacob Krell<\/p>\n<p>Collin Hogue-Spears, senior director of solution management at Black Duck Software, said TeamPCP targets an organization\u2019s security tooling \u2014 the scanners that run inside build pipelines. \u201cOne poisoned release turned an auditor into a thief across the pipelines that pulled it,\u201d he said.<\/p>\n<p style=\"padding-inline-start:40px\"><em>\u201cMost crews guard their tooling. This one published its worm framework on GitHub in May and, by Brian Krebs\u2019 account, ran a $1,000 contest for whoever used it to compromise the most-downloaded packages.\u201d<\/em><br \/>\u2014<a href=\"https:\/\/www.linkedin.com\/in\/collin-hogue-spears\"><span style=\"text-decoration:underline\">Collin Hogue-Spears<\/span><\/a><\/p>\n<p>Mini Shai-Hulud re-emerged in May, compromising more than 160 npm open-source software (OSS) packages, many of them popular and widely used, with millions of weekly downloads \u2014 <a href=\"https:\/\/www.reversinglabs.com\/blog\/mini-shai-hulud-tears-at-oss-trust\"><span style=\"text-decoration:underline\">which rocked trust in open-source repos.<\/span><\/p>\n<p><\/a>At the time, the TanStack team disclosed that attackers published malicious versions of 42 <em>@tanstack\/*<\/em> packages to npm after the threat actors successfully compromised publishing credentials. The breach includes packages like <em>@tanstack\/react-router<\/em> which has more than 12 million weekly downloads.<\/p>\n<p>Tomislav Peri\u010din, RL\u2019s co-founder and chief software architect, said TeamPCP was targeting strategic open-source assets.\u00a0<\/p>\n<p style=\"padding-inline-start:40px\"><em>\u201cThat\u2019s not a niche library; it\u2019s load-bearing infrastructure for huge swaths of the JavaScript ecosystem, consumed directly and transitively.\u201d<\/em><br \/>\u2014<a href=\"https:\/\/www.linkedin.com\/in\/tomislav-peri%C4%8Din-746064286?originalSubdomain=hr\"><span style=\"text-decoration:underline\">Tomislav Peri\u010din<\/span><\/a><\/p>\n<h2 id=\"shai-hulud-post-mortem-a-brazen-and-audacious-attack\">Shai-Hulud post-mortem: A brazen and audacious attack<\/h2>\n<p>TeamPCP is also distinguished by its brazenness and audacity in how it operates. \u201cThis trend really started emerging a few years ago,\u201d Dabit said. \u201cWe saw it with Scattered Spider, who ironically has some significant crossover with TeamPCP, and the profiles of the young people, often young men, whose sole purpose was to upstage their peers. The notoriety and bragging rights were often more important than the illicit gains.\u201d<\/p>\n<p>This need for oneupmanship has led to greater risks for victim organizations, including a move toward personal targeting of employees, Dabit said.<\/p>\n<p style=\"padding-inline-start:40px\"><em>\u201cTeamPCP points to a new breed of cybercriminal, ones who have no internal rules or constraints, as we saw in the past. This should concern all of us, because where does it stop? The line has been crossed.\u201d<\/em><br \/><em>\u2014<\/em>Lina Dabit<\/p>\n<p>Although the AFP did not release the names of the two alleged gang members that they arrested, they did release their ages: 21 and 23. Despite their youth, Dabit noted, they apparently were already successfully carrying out impactful exploits, and she wondered where might they be in five or 10 years.\u00a0<\/p>\n<h2 id=\"why-this-isnot-the-end-of-shai-hulud\">Why this is\u00a0not the end of Shai-Hulud<\/h2>\n<p>Krell doubted that the arrests would have a long-term impact on TeamPCP. The alleged leader told KrebsOnSecurity that he stopped operating with TeamPCP in March and that another individual had taken over. \u201cMore importantly, the August 4 Shai-Hulud wave hit more than 400 npm packages just three weeks before these arrests,\u201d he said.<\/p>\n<p>Krell also noted that TeamPCP had already open-sourced the worm and turned its use into a criminal contest. \u201cArresting the alleged operators doesn\u2019t recall the source code. Once offensive tooling has been published and copied, the capability no longer depends on the people who created it,\u201d Krell said.<\/p>\n<p style=\"padding-inline-start:40px\"><em>\u201cThat\u2019s the uncomfortable legacy of this campaign. Law enforcement can arrest alleged operators, but it can\u2019t make a published technique unpublished.\u201d<\/em><br \/><em>\u2014<\/em>Jacob Krell<\/p>\n<p>Hogue-Spears advised that the strategic takeaway for security leaders is that they must pin every third-party GitHub Action and container image to an immutable commit SHA or digest, not a version tag. They must also rotate every long-lived personal access token and registry publish token a CI runner has held at any point since February, he added.\u00a0<\/p>\n<p style=\"padding-inline-start:40px\"><em>\u201cIf your pipeline still pulls a dependency by tag and keeps a long-lived token in the runner, the next poisoned tag harvests that token. No arrest changes that.\u201d<\/em><br \/>\u2014Collin Hogue-Spears<\/p>\n<h2 id=\"why-software-integrity-and-transparency-are-critical\">Why software integrity and transparency are critical<\/h2>\n<p>Shai-Hulud is here to stay. RL\u2019s Peri\u010din has stressed that Shai-Hulud underscored the importance of <a href=\"https:\/\/www.reversinglabs.com\/blog\/shai-hulud-worms-eat-devops\"><span style=\"text-decoration:underline\">transparency and integrity across open-source ecosystems, dependencies, and CI\/CD pipelines<\/span><\/a>. To respond, developers and development organizations must back efforts to strengthen both, which GitHub agrees with.<\/p>\n<p>Peri\u010din stressed that the industry needs to enable comprehensive software supply chain security. \u201cUntil that happens, another self-replicating malware could worm its way into trusted development infrastructure,\u201d he said.<\/p>\n<p style=\"padding-inline-start:40px\"><em>\u201cAfter all, if you don\u2019t know which packages you\u2019re building software with \u2014 the content of your build pipeline \u2014 then someone else will figure it out and use that knowledge against you. Embracing package reputation; SBOMs; deferred package updates; and artifact provenance are no longer nice-to-haves. They\u2019re essential to modern cyber defense as attackers look to compromise sensitive organizations by injecting malicious code upstream in their software supply chain.\u201d<\/em><br \/>\u2014Tomislav Peri\u010din<\/p>\n<p>The software supply chain is complex and\u00a0 requires augmentation of traditional application security (AppSec) checks with more nuanced, behavioral-based detection that can spot malicious code and other anomalies, he said.<\/p>\n<p style=\"padding-inline-start:40px\"><em>\u201cThese software supply chain security measures won\u2019t end attacks for good, but they will raise the bar and block many noisy, disruptive campaigns \u2014 for the benefit of everyone.\u201d<\/em><br \/>\u2014Tomislav Peri\u010din<\/p>\n<\/p>\n<\/div>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>Key takeawaysTeamPCP franchised its own attack.Arrests don&#8217;t unpublish code.The fix is pipeline hygiene, not law enforcement.Supply chain integrity is now table stakes.Australian law enforcement officials, working with the U.S. Federal Bureau of Investigation, arrested two men Wednesday on cybercrime charges. The men allegedly are members of a global cybercrime syndicate suspected of creating the Shai-Hulud worm, malicious software that victimized thousands of businesses around the world.The Aus<\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[32775],"tags":[],"class_list":["post-26257","post","type-post","status-publish","format-standard","hentry","category-reversinglabs"],"_links":{"self":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/26257","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=26257"}],"version-history":[{"count":0,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/26257\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=26257"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=26257"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=26257"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}