There you have it! A hacking group just pulled off the largest software supply chain attack in hi…
May 23, 2026 · 0 likes · 0 comments
Cybersecurity Workforce
There you have it! A hacking group just pulled off the largest software supply chain attack in history — and OpenAI was one of the victims.
They call it Mini Shai-Hulud. Named after the sandworms from Dune. And it moves like one.
Here's what happened in 48 hours.
Two dormant npm packages that hadn't published an update in three years suddenly pushed new versions at 1:39 AM UTC on May 19. By 2:06 AM — 27 minutes — the worm had spread across 323 packages and 639 malicious versions. One of them pulls 1.1 million downloads every week.
Then they hit node-ipc. Ten million weekly downloads. A stranger with zero prior releases published three poisoned versions across two major version lines at once. Anyone running npm install with a loose version pin got the payload. Automatically.
Now read the next sentence carefully.
633 malicious package versions passed Sigstore provenance verification — the developer ecosystem's last automated trust signal. The system checked the certificates, confirmed the CI environment, logged everything. Then waved the truck through. Because Sigstore verifies process, not intent. Valid credentials. Valid paperwork. Invalid motives.
The payload targets 90+ credential categories. AWS keys. Kubernetes tokens. SSH keys. GitHub tokens. Docker auth files. Database passwords. Shell history. Even Claude AI and Kiro IDE settings. If it finds a GitHub token, it creates repos under your account and commits the stolen data there. Your own infrastructure storing the loot. Over 2,500 GitHub repos now carry the marker.
One day before the npm wave, they hit the Nx Console VS Code extension — 2.2 million lifetime installs. The poisoned version stayed live for under 40 minutes. In that window? 6,000 developers infected. Not from downloading anything. From auto-update.
Auto-update delivered the malware. Nobody clicked a thing.
OpenAI? Two employee devices compromised. Code-signing certificates stolen for macOS, Windows, iOS, and Android. The certificates that tell your phone "this software is legitimately from OpenAI." All four platforms. macOS users have until June 12 to update or the old certs die.
Seven security layers failed in those 48 hours. Seven independent research teams confirmed it. No single vendor covers all the gaps.
The open-source ecosystem built the internet. TeamPCP just proved you can navigate it with a stolen badge and valid paperwork. Every package manager on Earth is a liability until the industry fixes the credential layer — not just the signing layer.
I've been sounding the alarm on supply chain attacks for years. This is exactly the kind of systemic vulnerability I write about in REPLACEMENT — out July 28.
Full deep dive on Unbiased Headlines: https://lnkd.in/eixNy9PS
They call it Mini Shai-Hulud. Named after the sandworms from Dune. And it moves like one.
Here's what happened in 48 hours.
Two dormant npm packages that hadn't published an update in three years suddenly pushed new versions at 1:39 AM UTC on May 19. By 2:06 AM — 27 minutes — the worm had spread across 323 packages and 639 malicious versions. One of them pulls 1.1 million downloads every week.
Then they hit node-ipc. Ten million weekly downloads. A stranger with zero prior releases published three poisoned versions across two major version lines at once. Anyone running npm install with a loose version pin got the payload. Automatically.
Now read the next sentence carefully.
633 malicious package versions passed Sigstore provenance verification — the developer ecosystem's last automated trust signal. The system checked the certificates, confirmed the CI environment, logged everything. Then waved the truck through. Because Sigstore verifies process, not intent. Valid credentials. Valid paperwork. Invalid motives.
The payload targets 90+ credential categories. AWS keys. Kubernetes tokens. SSH keys. GitHub tokens. Docker auth files. Database passwords. Shell history. Even Claude AI and Kiro IDE settings. If it finds a GitHub token, it creates repos under your account and commits the stolen data there. Your own infrastructure storing the loot. Over 2,500 GitHub repos now carry the marker.
One day before the npm wave, they hit the Nx Console VS Code extension — 2.2 million lifetime installs. The poisoned version stayed live for under 40 minutes. In that window? 6,000 developers infected. Not from downloading anything. From auto-update.
Auto-update delivered the malware. Nobody clicked a thing.
OpenAI? Two employee devices compromised. Code-signing certificates stolen for macOS, Windows, iOS, and Android. The certificates that tell your phone "this software is legitimately from OpenAI." All four platforms. macOS users have until June 12 to update or the old certs die.
Seven security layers failed in those 48 hours. Seven independent research teams confirmed it. No single vendor covers all the gaps.
The open-source ecosystem built the internet. TeamPCP just proved you can navigate it with a stolen badge and valid paperwork. Every package manager on Earth is a liability until the industry fixes the credential layer — not just the signing layer.
I've been sounding the alarm on supply chain attacks for years. This is exactly the kind of systemic vulnerability I write about in REPLACEMENT — out July 28.
Full deep dive on Unbiased Headlines: https://lnkd.in/eixNy9PS