Corpus graph previewActor to Incident
Supply Chain GraphPan, zoom, and select actor, campaign, and incident tiers.

Supply Chain graph is loading. Keyboard controls become available after graph initialization.

Supply Chain Incident

Focused Graph View

The persistent graph is framed to this incident while the canonical page heading and details continue below.

270 nodes467 edgesCold links hydrate here

Supply Chain Incident

Shai-Hulud 2.0 npm supply-chain worm wave

A second Shai-Hulud wave compromised hundreds of npm packages through install-time malware, GitHub token theft, and public repositories containing exfiltrated secrets.

ConfidenceHigh
Evidence LevelVendor
Attack StagePackage Publish
Source Artifact DivergenceNo
Attribution ConfidenceLikely

Affected Packages

No structured records.

Affected Releases

No structured records.

Repositories

No structured records.

Organizations

No structured records.

Maintainers

No structured records.

Threat Actors

Campaigns

Build Systems

  • GitHub Actions

Distribution Channels

  • GitHub repositories
  • npm registry

Compromised Accounts

  • compromised npm maintainer tokens
  • victim GitHub tokens

Connected Entities

  • compromised npm maintainer tokensCompromised Account
  • GitHub ActionsBuild System
  • GitHub repositoriesDistribution Channel
  • npm registryDistribution Channel
  • TeamPCPThreat Actor
  • TeamPCP Multi-Ecosystem Supply Chain CampaignCampaign
  • victim GitHub tokensCompromised Account

Attribution Evidence

References