惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Engineering at Meta
Engineering at Meta
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
小众软件
小众软件
博客园_首页
T
Tailwind CSS Blog
美团技术团队
博客园 - 叶小钗
Microsoft Security Blog
Microsoft Security Blog
有赞技术团队
有赞技术团队
Apple Machine Learning Research
Apple Machine Learning Research
大猫的无限游戏
大猫的无限游戏
Microsoft Azure Blog
Microsoft Azure Blog
H
Hackread – Cybersecurity News, Data Breaches, AI and More
I
InfoQ
MongoDB | Blog
MongoDB | Blog
The Cloudflare Blog
J
Java Code Geeks
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
博客园 - 聂微东
酷 壳 – CoolShell
酷 壳 – CoolShell
Blog — PlanetScale
Blog — PlanetScale
IT之家
IT之家
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
Y
Y Combinator Blog

Socket

Fake Corepack Site Distributes Infostealer and Proxyware to ... Large-Scale GitHub Actions Abuse Powers a Distributed cPanel... New Study Identifies 53 Slopsquatting Targets Across 5 Front... White House Launches Gold Eagle Initiative to Manage Surge i... Suno Breached via Shai-Hulud Worm, Leaked Code Exposes AI Mu... Next.js moves to scheduled security releases - Socket 11 Malicious NuGet Tools Pose as Game Cheats to Drop a Windo... Compromised npm Packages in the AsyncAPI Namespace Deliver M... jscrambler npm Package Compromised in Supply Chain Attack - ... Fake Braintree NuGet Package Skims Credit Cards and Harvests... Compromised Injective SDK npm Package Exfiltrates Wallet Key... npm v12 Ships With Install Scripts Off by Default, Begins De... Malicious Go Module Exposes GitHub Malware Lure Network Span... pnpm 11.10 Hardens Registry Authentication to Block Token Re... Coordinated npm and PyPI Campaign Typosquats Popular Secure ... Node.js Considers Public Workflow for Security Reports Amid ... PolinRider: North Korea-Linked Supply Chain Campaign Expands... Risky Biz Podcast: AI Agents Are Raising the Stakes for Soft... Chrome and Firefox Extensions Posing as Free VPNs Add Clipbo... Miasma Mini Shai-Hulud Hits ImmobiliareLabs npm Packages - S... Rolldown Pulls Rust React Compiler Integration After Binary ... Miasma Mini Shai-Hulud Hits LeoPlatform npm Packages and Git... Frontier AI Is Now Critical Infrastructure - Socket The Code You Didn't Write Is Still Yours to Defend - Socket GitHub Actions Checkout Now Blocks Risky pull_request_target... Introducing Repository Access Permissions and Custom Roles -... Socket MCP Adds Org Alerts, Threat Feed Review, and Package ... Socket Firewall Now Blocks Malicious VS Code and Open VSX Ex... 140+ Mastra npm Packages Compromised in Coordinated Supply C... npm Package Uses Prompt Injection and Token Flooding to Disr...
TeamPCP and BreachForums Launch $1,000 Contest for Supply...
Sarah Goodin · 2026-05-14 · via Socket

Sidebar CTA Background

Secure your dependencies with us

Socket proactively blocks malicious open source packages in your code.

Install

After months of targeting security tools, CI/CD workflows, and open source packages, TeamPCP is now promoting Shai-Hulud as required tooling for a competition that rewards the biggest compromise with a tiny crypto payout.

According to Dark Web Informer, the competition was announced on BreachForums by an account identified as the forum’s owner, in collaboration with TeamPCP. Participants are being offered $1,000 USD in Monero to compromise open source packages with Shai-Hulud, along with the usual cybercrime forum currency of reputation and bragging rights.

Source: Dark Web Informer

The post says participants must use Shai-Hulud in their attacks, submit their forum handle or Breached profile, and provide “reasonable proof” of access.

The winner will be determined by weekly and monthly download counts for the compromised packages. Smaller package compromises can also be combined toward the total, turning package reach into the scoreboard.

Under that scoring system, a high-download package is the obvious prize. But a pile of smaller compromises can also count, giving participants a reason to go broad across the ecosystem instead of only chasing a single marquee target. The rule rewards a worm that devours indiscriminately.

Source: Dark Web Informer

The prize, however, is almost comically small for the kind of access TeamPCP is asking participants to burn. A successful supply chain compromise can expose CI/CD secrets, cloud credentials, maintainer tokens, source code access, and downstream enterprise environments. That access is worth far more than $1,000 to actors who know how to monetize it.

The contest essentially functions as a public recruitment stunt, turning supply chain compromise into a leaderboard for lower-tier actors willing to trade risk for recognition.

Open Source Malware for Open Source Attacks#

TeamPCP, never ones to miss a punchline, also released Shai-Hulud as open source attack tooling, hosted on the Breached CDN. A GitHub-hosted copy circulated before being taken down, according to users tracking the repository on X.

TeamPCP has been systematically targeting security tools and critical open source infrastructure. In forum posts, the group has called out security vendors directly: “These companies were built to protect your supply chains yet they can't even protect their own, the state of modern security research is a joke, as a result we're gonna be around for a long time stealing terrabytes of trade secrets with our new partners.”

Socket has been tracking TeamPCP’s activity across security tools, CI/CD workflows, GitHub Actions, Docker images, OpenVSX extensions, npm, PyPI, and Packagist. The group frequently targets tools that already run inside developer and enterprise environments, then uses that access to harvest credentials for follow-on attacks.

Recruiting Around Stolen Access#

It is possible that a $1,000 prize will not motivate skilled operators to burn high-value access. The amount is negligible compared to the value of credentials stolen from CI/CD pipelines, cloud environments, maintainer accounts, and enterprise developer tooling.

TeamPCP has become one of the more successful access-broker operations in recent supply chain activity because it focuses on compromising tools that already have privileged access built in. That is why these incidents keep producing downstream victims.

Vect announced its TeamPCP partnership on BreachForums less than seven weeks ago, though in supply chain attack time it already feels like 84 years. Since then, ransomware and extortion claims tied to the broader TeamPCP credential-theft fallout have touched AI training data, AI model development, property management technology, manufacturing, sports data infrastructure, and government cloud platforms, with other alleged claims spanning pharmaceuticals, financial data services, and major enterprise tech. Reporting has also pointed to overlapping claims from Vect, ShinyHunters, and Lapsus$, making attribution messy even when the credential-theft pipeline traces back to the same supply chain activity.

The contest extends that pipeline outward. TeamPCP has already been positioning supply chain compromise as a way to harvest credentials, expose enterprise environments, and hand access to groups that know how to monetize it. Now it is giving forum users an open source worm, a scoring system, and a reason to rack up compromises.

A $1,000 prize may not bring in serious operators. It can still bring in reckless ones. For maintainers and security teams already tired of the constant stream of open source supply chain attacks, the contest adds another weight they did not need: a public incentive for copycat attempts against package ecosystems.