Your Agent Was the Payload: S1ngularity, Shai-Hulud, and TeamPCP, One Year On

On 30 September 2026, ReversingLabs threat researcher Zaria Vuksan published a year-long post-mortem — Restrospective: How Malicious Updates Poison Your Environment — covering three campaigns that defined the modern software supply chain attack: S1ngularity, Shai-Hulud, and TeamPCP. We never gave S1ngularity its own briefing when it happened, and the retrospective plus this week's analysis wave makes the omission worth correcting now — because the through-line is squarely our beat: the first notable supply-chain attack to turn the victim's own AI agents into the credential-hunting payload.

S1ngularity: the crafted PR that bought an ecosystem

The compromise landed on 26 August 2025 against Nx, a build system with millions of weekly downloads. Per the retrospective, the attackers chained multiple weaknesses: a carefully crafted pull request to Nx's repository yielded a token with generous read/write permissions; that token replaced a legitimate CI script with a malicious version and triggered a publishing workflow; the attackers then deleted branches and workflow runs to cover their tracks. The script exfiltrated Nx's npm token, which published infected Nx packages. Victims who updated got post-install hooks that scanned for credentials, tokens, and SSH keys — then leaked them through public GitHub repositories all titled s1ngularity-repository, a deliberately unique spelling that made the loot searchable.

The novel half was the AI abuse. The malicious update contained prompts instructing the victim's own AI agents and coding tools to hunt the filesystem for files of interest — iterating through personas (a penetration tester, then a file-search agent, then a Linux-specific variant with directory exclusions) in what reads like prompt-tuning against the agents' own safeguards. At the time, almost nobody was using AI tools in this living-off-the-land manner. Fourteen months later, after GitSpawn's RCE across seven coding agents and the RubyGems campaign that gated on developer workstations, it looks less like a curiosity and more like the template: the machine an agent runs on — SSH keys, registry credentials, cloud tokens within reach — is precisely the machine these payloads are written for.

Nx's structural response is the one to copy: it moved to GitHub's Trusted Publisher model, replacing long-lived publishing tokens with short-lived, per-run credentials so there is no standing token left to steal. npm's trusted-publisher documentation describes the same exchange — a per-run OIDC token swapped for a short-lived publish grant. Every registry workflow still running on a static secret is accepting the exact risk S1ngularity collected on.

Shai-Hulud: the worm that needed no vulnerability

Weeks after S1ngularity — 12 September 2025 — Shai-Hulud reused the playbook (open-source tooling targets, secret collection, GitHub-account exfiltration) and added the differentiator: worm functionality. It harvested npm publishing credentials from victims and used them to republish itself into further packages, propagating without exploiting any software vulnerability at all. The November 2025 follow-ons, variously called Shai-Hulud 2.0 or SHA1-Hulud, refined the formula — one entered through a Pwn Request that exfiltrated a CI token and deployed via a malicious OpenVSX extension; the other rode long-lived credentials found in compromised repositories into projects including Zapier, PostHog, and Postman, with the second wave executing through bun.

Then came the force-multiplier: TeamPCP published an open-source Shai-Hulud variant in spring 2026 — Mini Shai-Hulud — and offered a $1,000 reward for the biggest supply-chain attack built on it. August 2026 brought ChainDrop, a Mini variant with an obfuscated Bun payload; over 400 downstream patches shipped while it was active, and its exfiltration falls back from an HTTPS endpoint to a public GitHub repository titled “Shai-Hulud: Here We Go Again.” Open-sourcing the worm means attribution for any given Mini incident is genuinely uncertain — and that the capability is now a commodity other actors rent.

TeamPCP: hundreds of millions, then arrests

TeamPCP is the group, not the malware, and 2026 was its year. The spotlight moment was Trivy: a privileged access token extracted in February, detected but incompletely rotated, then a malicious update pushed on 19 March through Trivy's own automated systems with a compromised service account — modifying existing version tags, the references CI/CD pipelines actually resolve, with malware self-identifying as “TeamPCP Cloud stealer.” Stolen material became the seed corn for the next attacks: Checkmarx (whose data later surfaced on the dark web), malicious packages pushed to PyPI as LiteLLM and Telnyx, and CanisterWorm — built from Trivy-harvested npm tokens — compromising over 60 npm packages by finding tokens on victim devices and overwriting their associated packages. Side ventures included a credential pipeline to the Vect ransomware-as-a-service group and work with the LAPSUS$ extortion crew. Estimated damage: hundreds of millions of dollars.

The reason this retrospective exists now is that the run appears to be ending the way these runs end: open-source intelligence across overlapping usernames identified suspects, and two individuals in Australia were arrested — corroborated by Wired's investigation into the crew. The story is still developing, and arrests do not patch anything: the incomplete-rotation failure at Trivy, the tag-mutability abuse, and the standing-token problem are all still live in plenty of pipelines. Note the adjacent thread in our ShinyHunters briefing: extortion crews were reportedly operating with TeamPCP-derived access, which is what credential-theft-at-scale always becomes — somebody else's ransomware.

The pattern, stated plainly

ReversingLabs' structural observation is the one defenders should budget around: these attacks chain unremarkable weaknesses — an over-permissioned token here, a mutable tag there, a publishing pipeline with no step-up authentication — into blast radiuses no single weakness would justify. Malicious versions typically live only hours before takedown, and hours are enough; compare MALFEX's fourteen months without an advisory and DirtyBlanket's nine packages in 33 minutes for the range this class operates in. And 2025's backdrop — a 73% increase in detected malicious open-source packages — says the funnel is widening, a finding consistent with Microsoft's Digital Defense Report analysis of AI-accelerated exploitation, which also tracks the S1ngularity lineage.

What to do

  • Kill long-lived publishing tokens. Move npm, PyPI, and container publishing to OIDC trusted-publisher flows with short-lived, per-run grants. Audit for static tokens in CI secrets, and treat every surviving one as already compromised for planning purposes.
  • Pin tags and verify them. TeamPCP modified existing version tags because pipelines resolve tags. Pin dependencies by digest or immutable version, alert on tag moves, and require human approval for releases cut from automation.
  • Complete the rotation — then verify it. Trivy detected the February extraction and still shipped a March compromise through the unrotated remainder. Rotation is not done when the new secret works; it is done when the old secret provably does nothing.
  • Assume your agents are living-off-the-land binaries. S1ngularity tasked the victim's AI tools with credential discovery. Constrain what coding agents and MCP-connected tools can read (credential paths, cloud config directories), log their file-access patterns, and treat an agent enumerating secrets as a detection, not a feature.
  • Watch the exfiltration venue, not just the malware. Three campaigns in a row used attacker-searchable public GitHub repositories as the drop. Hunt for unexpected public repos, gists, and outbound HTTPS beacons from build and agent hosts — the s1ngularity-repository pattern is a detection signature for the whole class.

Verification note: campaign dates, the S1ngularity intrusion chain (crafted PR, token extraction, CI-script replacement, workflow trigger, branch/run deletion, npm-token theft, s1ngularity-repository exfiltration), the AI-prompt personas and iteration, the Shai-Hulud timeline (12 September 2025, November 2.0 waves, OpenVSX and bun details, $1,000 reward, ChainDrop's 400+ patches and fallback repo title), the TeamPCP/Trivy sequence (February extraction, 19 March malicious update, tag modification, “TeamPCP Cloud stealer”), the Checkmarx/LiteLLM/Telnyx/CanisterWorm/TanStack/Vect/LAPSUS$ claims, the damage estimate, the Australian arrests, and the 73% figure are taken from the ReversingLabs retrospective (Zaria Vuksan, 30 September 2026), which we read in full. The arrests are additionally corroborated by contemporaneous reporting on the Wired investigation. The Nx Trusted Publisher remediation is confirmed against npm's trusted-publisher documentation. We did not obtain malware samples and make no independent claim about payload behavior beyond the cited analysis. Internal links above are to our own prior briefings.

Sources: