Mark RadarMARK RADAR
About
EN
Sign in

‘Mini Shai-Hulud’ Supply-Chain Attack Targets AntV Ecosystem and Claude Code

1 reports · First detected 2026-05-24 · Last active 2026-05-24

“Mini Shai-Hulud” is a supply-chain attack targeting the distribution pipeline for open-source packages. The TeamPCP hacking group compromised Alibaba-owned data visualization library AntV to spread malware into developer environments. With the affected ecosystem recording 1.5 million downloads a week, the threat can propagate through project dependencies and expose cloud accounts, cryptocurrency assets and corporate source code.

The latest investigation found that TeamPCP had published more than 600 malicious packages designed to steal cloud-service credentials and cryptocurrency wallet data. The packages specifically target Anthropic’s Claude Code and Microsoft Visual Studio Code for backdoor installation. Reports have not disclosed the exact date the attack was first detected, the number of victims or the amount of losses. The key measure of its scale currently available is 1.5 million weekly downloads.

All Coverage

1 original reports

The Backstory

The history behind this event
TeamPCP Uses Mini Shai-Hulud Worm to Infiltrate More Than 400 NPM and PyPI Packages2026-05-21 · 3 reports · similarity 0.84

TeamPCP used the Mini Shai-Hulud worm to launch a software supply-chain attack targeting the widely used NPM and PyPI package ecosystems. Victims include Mistral AI, TanStack and Guardrails AI. The malware can spread when packages are installed, exposing downstream projects and corporate systems to the theft of code, credentials and internal data.

Cybersecurity companies have described the incident as the largest code-repository attack of 2026 so far. TeamPCP has infiltrated more than 400 NPM and PyPI packages and is offering nearly 450 Mistral AI code repositories for sale. The latest investigation shows that the attack has spread further to GitHub, exposing nearly 3,800 internal repositories as its reach continues to expand.

SAP Ecosystem Hit by Mini Shai-Hulud Supply-Chain Attack Exploiting Claude Code Hooks2026-04-30 · 1 reports · similarity 0.82

SAP’s NPM packages sit within the enterprise software development supply chain, meaning malware inserted into the publishing process or dependencies could spread through the installation chain into development environments. The Mini Shai-Hulud attack involved hacker group TeamPCP, which sought to steal cloud account credentials and development credentials while using trusted packages to conceal the intrusion.

Cybersecurity companies recently disclosed that TeamPCP planted malicious scripts in NPM packages within the SAP ecosystem and abused Anthropic’s Claude Code hooks to automatically commit malicious content to victims’ code repositories. As of July 20, 2026, reports had not disclosed the number of affected organizations, financial losses, the exact discovery date or the versions of the affected packages.

Mark Radar|MARK RADAR

If you search news on Google, you can set Mark Radar as a preferred source—our coverage will show up more often in your results. Set as preferred source on Google →

All times are in Taipei time (GMT+8)