# TeamPCP — Shai-Hulud, mini Shai-Hulud

Published: 2026-05-26 · Severity: high · Sectors: technology
Canonical: https://vorant.io/reports/86cbd3c3-7c81-443e-9609-9e8fc803cb7d/teampcp-shai-hulud-mini-shai-hulud

> French CERT warns of actively exploited Drupal SQL injection, Linux kernel privilege escalation flaws, and TeamPCP supply-chain attacks compromising NPM/PyPI packages.

The French national CERT (CERT-FR) has issued a weekly security bulletin highlighting several critical vulnerability clusters and an active supply-chain campaign. CVE-2026-9082 in Drupal affects PostgreSQL-backed instances, enabling SQL injection with public exploits and confirmed active exploitation. Multiple Linux kernel vulnerabilities discovered in recent weeks—including Dirty Frag, Fragnesia, Copy Fail, and Pintheft—allow privilege escalation and are being actively exploited, though patches remain incomplete across distributions and embedded Linux products. Additionally, SonicWall updated guidance on CVE-2024-12802, clarifying that patching GEN6 VPN appliances requires manual LDAP configuration changes beyond applying the software update.

The bulletin's primary focus is a sophisticated supply-chain operation by the cybercriminal group TeamPCP, active since September 2025 and financially motivated. Since late April 2026, TeamPCP has compromised numerous popular NPM, PyPI, and GitHub packages—including @cap-js, @tanstack, @mistralai, lightning, and over 300 @antv packages. The malicious code deploys the 'mini Shai-Hulud' worm, which harvests credentials for GitHub, NPM, cloud platforms (AWS, Azure), databases, and SSH keys, then propagates by injecting itself into victims' own packages. The worm establishes persistence via daemon processes and includes a destructive mechanism (rm -rf ~/) if tampering is detected. TeamPCP published Shai-Hulud's source code on the Breached forum on May 13, 2026, enabling copycat attacks. CERT-FR confirms multiple French organizations are affected and urges immediate inspection of dependency lock files, removal of persistence mechanisms, credential rotation, and hunting for compromise indicators.

## Mentioned in this report

- Vulnerabilities: CVE-2024-12802, CVE-2026-31431 (KEV), CVE-2026-31635, CVE-2026-43284 (weaponized), CVE-2026-43494, CVE-2026-43500 (weaponized), CVE-2026-46300 (poc), CVE-2026-9082 (KEV)
- Threat actors: TeamPCP
- Malware: Shai-Hulud, mini Shai-Hulud

Source reporting: https://www.cert.ssi.gouv.fr/actualite/CERTFR-2026-ACT-023

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/86cbd3c3-7c81-443e-9609-9e8fc803cb7d/teampcp-shai-hulud-mini-shai-hulud.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
