TeamPCP's Supply-Chain Attack Compromises 400+ NPM, PyPI Packages for Dev Credentials
A hacker group just dumped malicious code into hundreds of popular open-source packages. They're after developer credentials.

Another day, another supply-chain attack. This time, it's TeamPCP. The hacker group just compromised over 400 NPM and PyPI packages. Their goal? Simple: extract sensitive developer data. We're talking credentials, access tokens, the works.
The Attack Unfolds
Security researchers at Socket are calling this one 'Mini-Shai-Hulud.' It started small, hitting NPM packages tied to SAP. But it's grown. A lot. Now, Socket says they've found 84 more compromised packages. These are linked to the Tanstack Open-Source-App-Framework. That brings the total past 400.
It's all part of TeamPCP's ongoing campaign. Collect login credentials. Then what? Infiltrate more software projects.
Popular Tanstack projects are on the list: @tanstack/react-router and @tanstack/history. Each clocks over 11 million weekly downloads. NPM packages aren't the only victims. Some PyPI packages are hit too. Think Mistral AI, Guardrails AI.
Data at Risk
So, what are they after? The malicious code TeamPCP dumped is designed to grab all sorts of sensitive data:
- GitHub and NPM tokens
- AWS access and metadata
- Kubernetes service account tokens
- Environment variables and other confidential information from CI/CD pipelines
The whole thing hinges on a heavily obfuscated file: router_init.js. It's about 2.3 MB. That's the data extraction engine.
Developer Response
If you're a developer using NPM or PyPI packages, you need to move. Fast. Check your systems for compromised versions. Found one? Consider your system compromised. Rotate any affected credentials. Immediately. Also, take a good look at your code repositories. Any unusual changes? Red flag.
Need more info on what to do? Socket and Aikido have detailed mitigation strategies and indicators of compromise in their blog posts. The Tanstack developers? They've put out a postmortem report explaining the attack's impact on their packages.
Background: Supply-Chain Attacks
Supply-chain attacks are a growing headache in the software world. Why? They exploit trust. That trust in widely-used packages to spread malware. TeamPCP, by the way, has been busy. They've been linked to several of these attacks lately. It just screams for better security in software development, doesn't it?
What's Still Unclear:
- How much data did TeamPCP actually get out?
- Are there more compromised packages out there? Undiscovered?
- What's the long-term damage to affected software projects?
Why This Matters:
Look, attacks like this? They really show how vulnerable the open-source software ecosystem is. Millions of downloads affected weekly. Think about the ripple effect. Developers, businesses. Could be huge. It's a pretty stark reminder. We need robust security practices. Everywhere. Software development. Package management. All of it.
Hardware keys and password managers used by security pros.
Shop security gear →More from Security

Instructure Cuts Deal with Hackers to Stop Data Leak
Instructure paid off ShinyHunters to stop a 3.6TB data leak from its Canvas LMS. Sure, the data's back, but what's next for security?

FCC Extends Waiver for Foreign Router Updates Until 2029
The FCC's decision allows foreign routers on the Covered List to get software updates until 2029, easing potential consumer harm.

GM Agrees to $12.75M Settlement Over Driver Data Sales in California
GM strikes a $12.75M deal with California over claims of illegal driver data sales, spotlighting privacy enforcement.

Checkmarx Jenkins Plugin Compromised by TeamPCP Malware
TeamPCP infiltrated Checkmarx's Jenkins AST plugin with credential-stealing malware. Users should rotate secrets and check for breaches.
Don’t miss these

Film Crews Are Swapping iPads for E-Readers. Seriously.
Forget the iPad. For quick notes and script changes on a busy film set, the Onyx Boox Tab Ultra C delivered a paper-like feel and astonishing battery life, making it a dark horse for production pros.

Heise Academy's Guide to Safe GPT Use for Businesses
Companies are wrestling with AI. A new guide from Heise Academy explains how to adopt GPT safely, scale it, and plug it into existing workflows without chaos.

Forza Horizon 6 Leak: Not Steam's Fault, Devs Blame Early Access
That big Forza Horizon 6 leak? Not Steam. Playground Games points to early access folk – reviewers, influencers – as the likely source.

Microsoft Promises Fewer Windows 11 Update Headaches by 2026
Microsoft just detailed a major overhaul for Windows 11 updates, promising users more control, less downtime, and a smoother experience by 2026.

Instagram Tests Per-Slide Captions for Carousels
Instagram is reportedly testing a new feature allowing separate captions for each slide in carousel posts. It's a small tweak, sure, but it could seriously change how content is made and consumed.

Philips Launches HDMI Sync Box 2.1 with 8K Support in June 2026
Philips introduces the HDMI Sync Box 2.1 for 8K and 4K displays. Set for release in June 2026, it aims to transform home lighting integration.