Application Security
TeamPCP Leaked the Shai-Hulud Source. Within a Week, a Copycat Pushed Clones to npm.
A single npm user account pushed four malicious packages, including a near-verbatim clone of the Shai-Hulud worm, within a week of TeamPCP open-sourcing the worm source on BreachForums. Mini Shai-Hulud has graduated from a campaign to an ecosystem capability.