VORANT. Threat Intelligence Sign in Get the full feed

TeamPCP — Shai-Hulud, mini Shai-Hulud

high threat technology

French CERT warns of actively exploited Drupal SQL injection, Linux kernel privilege escalation flaws, and TeamPCP supply-chain attacks compromising NPM/PyPI packages.

The French national CERT (CERT-FR) has issued a weekly security bulletin highlighting several critical vulnerability clusters and an active supply-chain campaign. CVE-2026-9082 in Drupal affects PostgreSQL-backed instances, enabling SQL injection with public exploits and confirmed active exploitation. Multiple Linux kernel vulnerabilities discovered in recent weeks—including Dirty Frag, Fragnesia, Copy Fail, and Pintheft—allow privilege escalation and are being actively exploited, though patches remain incomplete across distributions and embedded Linux products. Additionally, SonicWall updated guidance on CVE-2024-12802, clarifying that patching GEN6 VPN appliances requires manual LDAP configuration changes beyond applying the software update.

The bulletin's primary focus is a sophisticated supply-chain operation by the cybercriminal group TeamPCP, active since September 2025 and financially motivated. Since late April 2026, TeamPCP has compromised numerous popular NPM, PyPI, and GitHub packages—including @cap-js, @tanstack, @mistralai, lightning, and over 300 @antv packages. The malicious code deploys the 'mini Shai-Hulud' worm, which harvests credentials for GitHub, NPM, cloud platforms (AWS, Azure), databases, and SSH keys, then propagates by injecting itself into victims' own packages. The worm establishes persistence via daemon processes and includes a destructive mechanism (rm -rf ~/) if tampering is detected. TeamPCP published Shai-Hulud's source code on the Breached forum on May 13, 2026, enabling copycat attacks. CERT-FR confirms multiple French organizations are affected and urges immediate inspection of dependency lock files, removal of persistence mechanisms, credential rotation, and hunting for compromise indicators.

Mentioned in this report

Vulnerabilities CVE-2024-12802CVE-2026-31431KEVCVE-2026-31635CVE-2026-43284weaponizedCVE-2026-43494CVE-2026-43500weaponizedCVE-2026-46300pocCVE-2026-9082KEV
Threat actors TeamPCP
Malware Shai-Huludmini Shai-Hulud

Source reporting: https://www.cert.ssi.gouv.fr/actualite/CERTFR-2026-ACT-023

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free