Retrospective: How Malicious Software Updates Poison Development Environments

Summary
A retrospective examines S1ngularity, Shai-Hulud and TeamPCP supply-chain attacks, detailing how stolen credentials and malicious package updates spread malware, steal secrets and compromise downstream projects.
Key points
- Attackers compromise supplier credentials or CI/CD pipelines to publish malicious updates to trusted open-source packages, which can automatically reach downstream users.
- S1ngularity used malicious Nx package updates to search for credentials, tokens and SSH keys, including by prompting victims’ local AI agents, then exfiltrated secrets through public GitHub repositories.
- Shai-Hulud stole npm publishing tokens and republished itself as a worm, spreading without requiring a software vulnerability; later variants included Mini Shai-Hulud.
- TeamPCP used credentials from the Trivy compromise in further supply-chain attacks, including compromises involving Checkmarx, LiteLLM, Telnyx and more than 60 npm packages.
- The article says Nx moved to GitHub Trusted Publisher to replace long-lived tokens with short-lived, per-run credentials; it also stresses credential rotation and CI/CD security.
- The article attributes suspected damages of hundreds of millions of dollars to TeamPCP and reports that two people in Australia were arrested in connection with the group.
Article Details
- Attack Vectors
- Attackers compromised publishing credentials or CI/CD access, then released malicious updates to popular open-source packages.
- In the S1ngularity attack, a crafted pull request helped attackers obtain a token, replace an Nx CI script, steal an npm publishing token, and publish infected packages.
- Malicious Nx post-install hooks searched for credentials and SSH keys, prompted local AI agents to find additional files, and exposed stolen information through public GitHub repositories.
- Shai-Hulud and CanisterWorm searched infected systems for npm publishing tokens and used them to publish malicious updates to additional packages.
- TeamPCP used a compromised service account to modify Trivy version tags relied on by running CI/CD workflows and distribute a malicious update.
- ChainDrop used a Mini Shai-Hulud variant with an obfuscated Bun JavaScript payload.
- Defensive Notes
- Nx moved to GitHub's Trusted Publisher model to replace long-lived publishing tokens with short-lived, per-run credentials.
- The Trivy incident illustrates the risk of incomplete credential rotation after a known compromise.
- Review repository and CI/CD pipeline misconfigurations, publishing-token permissions, and the trust placed in automated dependency updates.
Indicators of compromise
| Type | Indicator | Context |
|---|---|---|
| SHA1 | 2379ac0e03b1a67c4ca5693136eff4945e644a91 | Sample identified with a revised S1ngularity file-search prompt. |
| SHA1 | b4f20b39aa6df1002872f07973024d85aa49abaf | Sample identified with a S1ngularity prompt used to seek files containing credentials. |
| SHA1 | d2438106211ebd12c4f0a248848bc9864c97a3c0 | Sample identified in the article's analysis of malicious S1ngularity code and prompts. |
| SHA1 | e5d1f3c45ee7cca6ae59cf64e0573050bbe136ec | Sample identified with the final S1ngularity file-search prompt described in the article. |
MITRE ATT&CK
T1027 · Obfuscated Files or InformationChainDrop combined a Mini Shai-Hulud variant with an obfuscated Bun JavaScript payload.T1078 · Valid AccountsAttackers used stolen publishing tokens and a compromised Trivy service account to distribute malicious updates.T1195 · Supply Chain CompromiseAttackers published malicious versions of open-source packages and tools so downstream users would receive the code through software updates.T1528 · Steal Application Access TokenThe Nx attack stole an npm publishing token, while the Trivy compromise began with extraction of a privileged access token.T1567.001 · Exfiltration to Code RepositoryS1ngularity exposed stolen information in public GitHub repositories; ChainDrop could create a public GitHub repository as a fallback exfiltration route.
Threat Actors
LAPSUS$Extortion group that the article says worked with TeamPCP.TeamPCPGroup linked to the Trivy compromise, subsequent malicious package releases, CanisterWorm, and publication of Mini Shai-Hulud.VectRansomware-as-a-service group that, according to the article, partnered with TeamPCP and received credentials for attacks.
Malware
CanisterSprawlor the original Shai-Hulud, they did leverage similar techniques. They were behind CanisterWorm, CanisterSprawl and Mini Shai-Hulud. They focused heavily on this indirect method of attacks, targeting open sourceCanisterWormto S1ngularity or the original Shai-Hulud, they did leverage similar techniques. They were behind CanisterWorm, CanisterSprawl and Mini Shai-Hulud. They focused heavily on this indirect method of attacks,Mini Shai-Huluditself without needing a software vulnerability. It has come back in new versions, including 2.0, Mini Shai-Hulud and ChainDrop.SHA1-Huludreturned at the end of November in two separate attacks. These attacks are called Shai-Hulud 2.0 or SHA1-Hulud. Different outlets use these two names to describe one or both of the attacks. One attack started withShai-HuludShai-Hulud showed how much damage a self-spreading worm can do. It steals npm publishing tokens and republishes itself without needing a software vulnerability. It has come back in new versions, including 2.0, MiniShai-Hulud 2.0wave, Shai-Hulud returned at the end of November in two separate attacks. These attacks are called Shai-Hulud 2.0 or SHA1-Hulud. Different outlets use these two names to describe one or both of the attacks. OneTeamPCP Cloud stealerexisting version tags, as tags are what CI/CD pipelines rely on. The malware self identified as “TeamPCP Cloud stealer.”
Vendors
Checkmarxlaunch the next attack. An incomplete credential rotation after the Trivy breach led to compromises of Checkmarx, LiteLLM, Telnyx and more than 60 npm packages. The damages reached hundreds of millions of dollars.GitHubS1ngularity turned AI agents against their own users. The malicious Nx update prompted victims' local AI tools to hunt for GitHub, npm, cloud and SSH credentials. It was the first notable attack to use this tactic.TelnyxAn incomplete credential rotation after the Trivy breach led to compromises of Checkmarx, LiteLLM, Telnyx and more than 60 npm packages. The damages reached hundreds of millions of dollars.
Products
BunBoth of these attacks had a more sophisticated version of Shai-Hulud. The second wave leveraged bun to execute the file with the malicious code. The worm traveled far and infected many systems. TeamPCP, which will beGitHubS1ngularity turned AI agents against their own users. The malicious Nx update prompted victims' local AI tools to hunt for GitHub, npm, cloud and SSH credentials. It was the first notable attack to use this tactic.LiteLLMnext attack. An incomplete credential rotation after the Trivy breach led to compromises of Checkmarx, LiteLLM, Telnyx and more than 60 npm packages. The damages reached hundreds of millions of dollars.npmS1ngularity turned AI agents against their own users. The malicious Nx update prompted victims' local AI tools to hunt for GitHub, npm, cloud and SSH credentials. It was the first notable attack to use this tactic.NxS1ngularity turned AI agents against their own users. The malicious Nx update prompted victims' local AI tools to hunt for GitHub, npm, cloud and SSH credentials. It was the first notable attack to use this tactic.OpenVSXattack started with a Pwn Request to exfiltrate a CI token, then deployed the worm through a malicious OpenVSX extension. The other attack targeted projects like Zapier, PostHog, and Postman by exploiting long-livedPyPIonto the dark web. Another victim was LiteLLM, where attackers uploaded a malicious package directly to PyPi. Telnyx had a similar compromise as LiteLLM, with publication through PyPi. TrivyTeamPCP used each stolen credential to launch the next attack. An incomplete credential rotation after the Trivy breach led to compromises of Checkmarx, LiteLLM, Telnyx and more than 60 npm packages. The damages reachedTrusted PublisherIn response to this attack, Nx’s moved to GitHubs Trusted Publisher model. This model seeks to stop the usage of long lasting tokens, replacing them with something short-lived and per-run. It helps eliminate token theft