Risky Bulletin Newsletter
May 15, 2026
Risky Bulletin: Shai-Hulud goes open-source
Presented by
News Editor
Individuals claiming to be associated with the TeamPCP hacking group have released the source code of the Shai-Hulud worm that has devastated open-source libraries across the npm and PyPI ecosystems.
The code was released this week on the Breached[.]st hacking forum.
It was released two days after it was used in a supply chain attack that compromised the TanStack React framework and then spread to almost 400 packages, including libraries at AI company Mistral and business automation giant UiPath.