← Back

Wire · market

New Actors Deploy Shai-Hulud Clones: TeamPCP Copycats Are Here

Published

18 July 2026

Topic

market

Sectors

CybersecurityDeveloper Tools

Geography

United States

Source

Read at ox.security

Verified

Fusion42 · 18 July 2026 · Fusion42 review

Four malicious npm packages were detected containing infostealer malware and DDoS botnet code, including a direct unobfuscated clone of the Shai-Hulud malware that TeamPCP leaked the previous week. The typo-squatting campaign targets Axios users and other common package names, with 2,678 weekly downloads across affected packages.

This Wire brief sits within Fusion42's coverage of Cybersecurity and Developer Tools.

◆ The Wire takeaway

If your Node.js app uses Axios or common utility packages, check your node_modules right now—four typo-squatted malware packages are actively stealing credentials, SSH keys, and cloud configs from development machines. The threat actor copied TeamPCP's leaked code verbatim and added new C2 servers, meaning your devs installing chalk-tempalte or axois-utils are handing over their entire credential store.

Coverage

1 source · 18 Jul 2026

Related on Wire

Topics

CybersecurityDeveloper Toolsnpm-securitysupply-chain-attacktypo-squattingmalware-clonecredential-theft