Wire · market
New Actors Deploy Shai-Hulud Clones: TeamPCP Copycats Are Here
◆ Sectors
◆ Geography
◆ Source
◆ Verified
Fusion42 · 18 July 2026 · Fusion42 review
Four malicious npm packages were detected containing infostealer malware and DDoS botnet code, including a direct unobfuscated clone of the Shai-Hulud malware that TeamPCP leaked the previous week. The typo-squatting campaign targets Axios users and other common package names, with 2,678 weekly downloads across affected packages.
This Wire brief sits within Fusion42's coverage of Cybersecurity and Developer Tools.
◆ ◆ The Wire takeaway
If your Node.js app uses Axios or common utility packages, check your node_modules right now—four typo-squatted malware packages are actively stealing credentials, SSH keys, and cloud configs from development machines. The threat actor copied TeamPCP's leaked code verbatim and added new C2 servers, meaning your devs installing chalk-tempalte or axois-utils are handing over their entire credential store.
◆ Coverage
1 source · 18 Jul 2026
◆ Related on Wire
◆ Topics