Wire · founder news, decoded · market
New Actors Deploy Shai-Hulud Clones: TeamPCP Copycats Are Here
Four malicious npm packages were detected containing infostealer malware and DDoS botnet code, including a direct unobfuscated clone of the Shai-Hulud malware that TeamPCP leaked the previous week. The typo-squatting campaign targets Axios users and other common package names, with 2,678 weekly downloads across affected packages.
This Wire brief sits within Fusion42's coverage of Cybersecurity and Developer Tools. Wire is Fusion42's founder-focused intelligence feed: each story is connected to the funds and startups it names — every one with a live profile on Raise or Scout — so founders can follow the capital and the momentum behind the headline rather than just the headline itself. Wire analysis is one of the live surfaces Arthur, Fusion42's AI co-founder, reasons over.
The Wire takeaway
If your Node.js app uses Axios or common utility packages, check your node_modules right now—four typo-squatted malware packages are actively stealing credentials, SSH keys, and cloud configs from development machines. The threat actor copied TeamPCP's leaked code verbatim and added new C2 servers, meaning your devs installing chalk-tempalte or axois-utils are handing over their entire credential store.
Read the full story at ox.security →
Topics: Cybersecurity · Developer Tools · npm-security · supply-chain-attack · typo-squatting · malware-clone · credential-theft