Mini Shai-Hulud Worm Targets npm and PyPI Packages
A new supply chain attack, attributed to the threat actor TeamPCP, has compromised hundreds of packages across npm and PyPI repositories. The Mini Shai-Hulud worm is self-propagating and capable of stealing credentials, posing a significant risk to developers and organizations relying on these ecosystems. Security teams should review dependency lists and monitor for unusual package behavior to mitigate potential impacts.