TeamPCP's Supply-Chain Attack Compromises 400+ NPM, PyPI Packages for Dev Credentials

A hacker group just dumped malicious code into hundreds of popular open-source packages. They're after developer credentials.

By Byte-Pulse Newsroom·AI-augmented editorial system·May 12, 2026·4 min read
Serhat Er — Founder & Editor-in-ChiefEdited bySerhat Er·Founder & Editor-in-Chief
Updated Jul 27, 2026
Reported fromGolem
TeamPCP's Supply-Chain Attack Compromises 400+ NPM, PyPI Packages for Dev Credentials
Byte-Pulse original cover. Source story: Golem.

TeamPCP's Supply-Chain Attack Compromises 400+ NPM, PyPI Packages for Dev Credentials

In the ever-evolving landscape of cybersecurity, supply-chain attacks have emerged as a formidable threat, exploiting the inherent trust in widely-used software packages to infiltrate systems. The latest breach, attributed to the cybercriminal group known as TeamPCP, has compromised over 400 packages across NPM and PyPI, two of the most popular repositories for developers. This attack is a stark reminder of the vulnerabilities present in the open-source ecosystem and the critical need for robust security measures.

The Attack Unfolds

Security researchers at Socket have dubbed this latest breach 'Mini-Shai-Hulud,' signaling its potential impact. Initially, the attack targeted NPM packages associated with SAP, but it quickly expanded its reach. Socket recently identified 84 additional compromised packages linked to the Tanstack Open-Source-App-Framework, bringing the total number of affected packages to over 400. This expansion underscores TeamPCP's ambitious agenda—harvesting sensitive developer credentials to infiltrate and compromise further software projects.

Among the targeted projects are prominent Tanstack offerings like @tanstack/react-router and @tanstack/history, which together boast over 11 million weekly downloads. Such a widespread infiltration illustrates the scale at which open-source projects can be affected. Furthermore, the attack is not confined to NPM packages alone; some PyPI packages, including those used by Mistral AI and Guardrails AI, have also been compromised. This broad targeting strategy highlights the attackers' focus on widespread disruption and data theft across multiple platforms.

Context: The Growing Threat of Supply-Chain Attacks

Supply-chain attacks have become increasingly common in recent years, exploiting the interconnected nature of modern software development. These attacks target the trust developers place in established packages, using them as vectors to distribute malicious code. TeamPCP has been linked to several such attacks, emphasizing the need for heightened vigilance and improved security protocols. The European Union, with its stringent data protection regulations, remains particularly sensitive to these threats, underscoring the global implications of such breaches.

Data at Risk

The malicious code introduced by TeamPCP is engineered to extract a wide array of sensitive data. The list of targeted information is extensive, including:

  • GitHub and NPM tokens
  • AWS access keys and metadata
  • Kubernetes service account tokens
  • Environment variables from CI/CD pipelines

Central to this data extraction is a heavily obfuscated file named router_init.js, which is around 2.3 MB in size. This file acts as the data extraction engine, systematically siphoning off credentials and other critical data. The theft of such information can lead to unauthorized access to repositories, further compromising the integrity of software projects and potentially leading to additional breaches.

Developer Response and Mitigation

For developers utilizing NPM or PyPI packages, the immediate response should involve scrutinizing systems for compromised versions. If any are found, it's crucial to assume the system has been compromised and to rotate all affected credentials without delay. Developers should also audit their code repositories for any unexplained changes, which could indicate further unauthorized access.

To aid in mitigation, Socket and Aikido have published detailed strategies and indicators of compromise on their blogs. These resources provide invaluable guidance for detecting and neutralizing the threats posed by this attack. Additionally, the developers of Tanstack have released a postmortem report, offering insights into the attack's effects on their packages and the steps they are taking to mitigate future vulnerabilities.

What This Means for You

For developers and organizations relying heavily on open-source packages, this attack serves as a critical wake-up call. The potential compromise of widely-used packages could have far-reaching consequences, affecting millions of downloads weekly and potentially disrupting countless applications and services. This incident underscores the importance of implementing stringent security practices, including regular audits, automated security checks, and the use of security-focused tools to monitor dependencies.

What's Still Unclear

Despite the extensive investigation, several questions remain unanswered:

  • The exact volume of data exfiltrated by TeamPCP is still unknown.
  • There could be additional compromised packages that have yet to be discovered.
  • The long-term impact on affected software projects and their users remains uncertain.

These uncertainties highlight the challenges in fully assessing the scope and impact of supply-chain attacks. Ongoing vigilance and continued analysis will be essential to understanding and mitigating the full repercussions of this breach.

A Call to Action for Enhanced Security

This latest attack by TeamPCP is a sobering reminder of the vulnerabilities inherent in our current software supply chains. As the reliance on open-source software continues to grow, so too does the risk of such breaches. Developers and organizations must prioritize security at every stage of the software development lifecycle, from initial coding to package management and deployment.

While this incident exposes significant weaknesses, it also presents an opportunity to strengthen our defenses. By adopting comprehensive security practices and leveraging the collective expertise of the cybersecurity community, we can better protect our digital infrastructure from future attacks.

In the end, the responsibility for securing our software systems rests with all of us—developers, organizations, and users alike. Through collaboration and vigilance, we can build a more resilient and secure digital ecosystem.

Discuss this story

Got a take, a correction, or a follow-up tip? Reply where you read — we read everything.

Found an error? File a correction at /corrections. Substantive corrections are logged publicly.

#security#supply-chain#npm#pypi#malware
Get the 5 tech stories worth your time — 3× a week

One short email. The most important Security news, fact-checked, no fluff. Free, unsubscribe anytime.

More from Security

About the author
AI-augmented editorial system

The Byte-Pulse Newsroom is the editorial system that produces Byte-Pulse's daily tech news coverage. Each story is cross-referenced across 3+ independent outlets, drafted with AI assistance by the newsroom system (Drafter → Editor → Fact-Checker → Polisher), and reviewed by Serhat Er, Editor-in-Chief, before publication. We disclose AI augmentation openly. Editorial accountability stays with the named editor on every article. Tips: editorial@byte-pulse.net.

HardwareAIGamingMobileSecurity
Editorially reviewed on . Spotted an error? Tell us.
From other sections

Don’t miss these

Zelnick's Streaming Vision: Hype or Hard Reality for GTA 6?
🎮 Gaming

Zelnick's Streaming Vision: Hype or Hard Reality for GTA 6?

Byte-Pulse examines Take-Two CEO Strauss Zelnick's bold prediction of widespread game streaming by 2029, contrasting it with the immediate demands of GTA 6 and the often-overlooked practicalities of European hardware logistics.

By Byte-Pulse Newsroom·1 day ago·7 min0
Ugreen's 200W Charger: Powerhouse or Marketing Hype?
⚙️ Hardware

Ugreen's 200W Charger: Powerhouse or Marketing Hype?

We analyze the Ugreen 200W charger's technical prowess, real-world utility, and the Amazon deal, highlighting its strengths and limitations

By Byte-Pulse Newsroom·3 days ago·4 min
Teclast P33: A Comprehensive Review of the 90-Euro Tablet Bundle
📱 Mobile

Teclast P33: A Comprehensive Review of the 90-Euro Tablet Bundle

Byte-Pulse investigates the Teclast P33 tablet's unprecedented 90-Euro bundle, dissecting its budget specs and real-world utility of its ten included accessories.

By Byte-Pulse Newsroom·4 days ago·3 min
Spotify Relaunches AI Running Mode for iOS Premium Users
🌐 Web & Apps

Spotify Relaunches AI Running Mode for iOS Premium Users

Spotify's new Running Mode for iOS uses AI to sync music with your stride, but its success hinges on AI quality and user input

By Byte-Pulse Newsroom·Jul 30, 2026·4 min
iOS 27 AI Tier: Latest iPhones Lock Full Potential
🤖 AI

iOS 27 AI Tier: Latest iPhones Lock Full Potential

Byte-Pulse examines iOS 27's public beta, revealing a tiered system where 'Apple Intelligence' features are gated by chip generations and RAM, creating an uneven experience for users

By Byte-Pulse Newsroom·Jul 15, 2026·4 min
Fire Emblem: Fortune's Weave — Nintendo's Time-Bending Switch 2 RPG
🎮 Gaming

Fire Emblem: Fortune's Weave — Nintendo's Time-Bending Switch 2 RPG

Fire Emblem: Fortune's Weave redefines the series with its complex narrative, time-travel mechanics, and parallel campaign progression, launching Sept. 17, 2026, on Nintendo Switch 2.

By Byte-Pulse Newsroom·5 days ago·5 min0
Cookies & ads

We fund this site through ads (Google AdSense and others) and use analytics to see what works. Both may set cookies. You decide what is OK — your choice is remembered.

Details in our Privacy Policy.