<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>RuntimeRebel — #Shai Hulud</title><description>Cybersecurity articles tagged #Shai Hulud on RuntimeRebel.</description><link>https://runtimerebel.com</link><item><title>TeamPCP Hackers Arrested in Australia Over Supply Chain Attacks</title><link>https://runtimerebel.com/blog/teampcp-hackers-arrested-in-australia-over-supply-chain-attacks</link><guid isPermaLink="true">https://runtimerebel.com/blog/teampcp-hackers-arrested-in-australia-over-supply-chain-attacks</guid><description>Australian Federal Police arrest two men linked to TeamPCP, a cybercrime syndicate behind major software supply chain attacks and data extortion.</description><pubDate>Tue, 01 Sep 2026 02:41:36 GMT</pubDate><category>TeamPCP</category><category>Supply Chain Attack</category><category>Shai Hulud</category><category>GitHub</category><category>LiteLLM</category></item><item><title>TeamPCP Supply Chain Attack: Trivy Compromise Impacts 2,500 Orgs</title><link>https://runtimerebel.com/blog/teampcp-supply-chain-attack-trivy-compromise-impacts-2500-orgs</link><guid isPermaLink="true">https://runtimerebel.com/blog/teampcp-supply-chain-attack-trivy-compromise-impacts-2500-orgs</guid><description>A supply chain attack attributed to TeamPCP compromised over 2,500 organizations, primarily through Aqua Security&apos;s Trivy scanner, not LiteLLM.</description><pubDate>Sat, 15 Aug 2026 00:42:24 GMT</pubDate><category>TeamPCP</category><category>Trivy</category><category>LiteLLM</category><category>Supply Chain Attack</category><category>Shai Hulud</category></item><item><title>npm Supply Chain Attacks: Shai-Hulud, Miasma, and CI/CD Compromises</title><link>https://runtimerebel.com/blog/npm-supply-chain-attacks-shai-hulud-miasma-and-ci-cd-compromises</link><guid isPermaLink="true">https://runtimerebel.com/blog/npm-supply-chain-attacks-shai-hulud-miasma-and-ci-cd-compromises</guid><description>The npm ecosystem faces escalating supply chain attacks like Shai-Hulud and Miasma RAT, leading to credential theft and widespread package compromise.</description><pubDate>Sat, 08 Aug 2026 16:26:28 GMT</pubDate><category>NPM</category><category>Supply Chain Attack</category><category>Shai Hulud</category><category>TeamPCP</category><category>CI CD Security</category></item><item><title>Shai-Hulud Attack: Trojanized PyPI Packages Steal Developer Secrets</title><link>https://runtimerebel.com/blog/shai-hulud-attack-trojanized-pypi-packages-steal-developer-secrets</link><guid isPermaLink="true">https://runtimerebel.com/blog/shai-hulud-attack-trojanized-pypi-packages-steal-developer-secrets</guid><description>New Shai-Hulud supply chain attack compromises 19 science-focused PyPI packages, distributing malware to steal developer credentials and secrets.</description><pubDate>Mon, 08 Jun 2026 20:57:57 GMT</pubDate><category>Shai Hulud</category><category>PyPI</category><category>Supply Chain Attack</category><category>Malware</category><category>Developer Secrets</category><category>Python</category><category>Open Source Security</category></item><item><title>Red Hat npm Supply Chain Compromise: Miasma Steals Dev Credentials</title><link>https://runtimerebel.com/blog/red-hat-npm-supply-chain-compromise-miasma-steals-dev-credentials</link><guid isPermaLink="true">https://runtimerebel.com/blog/red-hat-npm-supply-chain-compromise-miasma-steals-dev-credentials</guid><description>Over 30 Red Hat npm packages under @redhat-cloud-services were compromised in a supply chain attack distributing Miasma malware to steal developer credentials.</description><pubDate>Tue, 02 Jun 2026 01:03:30 GMT</pubDate><category>Red Hat</category><category>NPM</category><category>Supply Chain Attack</category><category>Miasma</category><category>Shai Hulud</category><category>Developer Credentials</category><category>Credential Theft</category></item><item><title>Shai-Hulud Campaign: TeamPCP Targets Open-Source Supply Chain</title><link>https://runtimerebel.com/blog/shai-hulud-campaign-teampcp-targets-open-source-supply-chain</link><guid isPermaLink="true">https://runtimerebel.com/blog/shai-hulud-campaign-teampcp-targets-open-source-supply-chain</guid><description>Analysis of the Shai-Hulud campaign by TeamPCP, detailing their open-source supply chain attacks, TTPs, and critical mitigation strategies.</description><pubDate>Tue, 26 May 2026 20:47:57 GMT</pubDate><category>TeamPCP</category><category>Shai Hulud</category><category>Supply Chain Attack</category><category>Open Source Security</category><category>NPM</category><category>PyPI</category><category>Malicious Packages</category></item><item><title>Shai-Hulud Worm Code Leak: How Clones Threaten Developer Environments</title><link>https://runtimerebel.com/blog/shai-hulud-worm-code-leak-how-clones-threaten-developer-environments</link><guid isPermaLink="true">https://runtimerebel.com/blog/shai-hulud-worm-code-leak-how-clones-threaten-developer-environments</guid><description>The release of Shai-Hulud worm source code triggers a surge in self-replicating clones, targeting software developers and automated CI/CD pipelines.</description><pubDate>Mon, 18 May 2026 20:37:43 GMT</pubDate><category>Shai Hulud</category><category>Worm</category><category>Developer Security</category><category>Source Code Leak</category><category>Malware Analysis</category></item><item><title>Shai-Hulud Infostealer Surfaces in Malicious npm Package Campaign</title><link>https://runtimerebel.com/blog/shai-hulud-infostealer-surfaces-in-malicious-npm-package-campaign</link><guid isPermaLink="true">https://runtimerebel.com/blog/shai-hulud-infostealer-surfaces-in-malicious-npm-package-campaign</guid><description>Leaked Shai-Hulud malware is targeting Node.js developers via malicious npm packages, exfiltrating sensitive data and credentials to Telegram-based C2.</description><pubDate>Mon, 18 May 2026 20:37:20 GMT</pubDate><category>NPM</category><category>Shai Hulud</category><category>Infostealer</category><category>Supply Chain Attack</category><category>Malicious Packages</category></item><item><title>Shai-Hulud Supply Chain Attack: Malicious npm and Mistral Packages</title><link>https://runtimerebel.com/blog/shai-hulud-supply-chain-attack-malicious-npm-and-mistral-packages</link><guid isPermaLink="true">https://runtimerebel.com/blog/shai-hulud-supply-chain-attack-malicious-npm-and-mistral-packages</guid><description>The Shai-Hulud campaign targets developers with over 300 signed npm and PyPI packages impersonating TanStack and Mistral to steal sensitive credentials.</description><pubDate>Tue, 12 May 2026 12:48:53 GMT</pubDate><category>Shai Hulud</category><category>NPM</category><category>PyPI</category><category>Supply Chain Attack</category><category>Mistral AI</category><category>TanStack</category><category>Credential Stealer</category></item><item><title>Bitwarden NPM Supply Chain Attack: Analyzing the TeamPCP Campaign</title><link>https://runtimerebel.com/blog/bitwarden-npm-supply-chain-attack-analyzing-the-teampcp-campaign</link><guid isPermaLink="true">https://runtimerebel.com/blog/bitwarden-npm-supply-chain-attack-analyzing-the-teampcp-campaign</guid><description>A malicious npm package impersonating Bitwarden was discovered exfiltrating sensitive data via the Shai-Hulud worm in a recent supply chain attack.</description><pubDate>Fri, 24 Apr 2026 08:49:11 GMT</pubDate><category>NPM</category><category>Bitwarden</category><category>TeamPCP</category><category>Shai Hulud</category><category>Supply Chain Security</category></item></channel></rss>