Wireby Fusion42
Read this story on the live Wire →

Wire · founder news, decoded · market

New Actors Deploy Shai-Hulud Clones: TeamPCP Copycats Are Here

Four malicious npm packages were detected containing infostealer malware and DDoS botnet code, including a direct unobfuscated clone of the Shai-Hulud malware that TeamPCP leaked the previous week. The typo-squatting campaign targets Axios users and other common package names, with 2,678 weekly downloads across affected packages.

This Wire brief sits within Fusion42's coverage of Cybersecurity and Developer Tools. Wire is Fusion42's founder-focused intelligence feed: each story is connected to the funds and startups it names — every one with a live profile on Raise or Scout — so founders can follow the capital and the momentum behind the headline rather than just the headline itself. Wire analysis is one of the live surfaces Arthur, Fusion42's AI co-founder, reasons over.

The Wire takeaway

If your Node.js app uses Axios or common utility packages, check your node_modules right now—four typo-squatted malware packages are actively stealing credentials, SSH keys, and cloud configs from development machines. The threat actor copied TeamPCP's leaked code verbatim and added new C2 servers, meaning your devs installing chalk-tempalte or axois-utils are handing over their entire credential store.

Read the full story at ox.security

Topics: Cybersecurity · Developer Tools · npm-security · supply-chain-attack · typo-squatting · malware-clone · credential-theft

Related on Wire

Verified 18 July 2026 · Sources: Fusion42 review

New Actors Deploy Shai-Hulud Clones: TeamPCP Copycats… | Fusion42