TeamPCP Shai-Hulud: GitHub, OpenAI, Mistral Breached via Supply Chain Escalation

TeamPCP's Shai-Hulud campaign reached GitHub, OpenAI, Grafana Labs, and Mistral AI in a single week—via a trojanized VS Code extension, a poisoned Microsoft Python SDK, and 639 malicious npm packages.

2026-05-31T10:06:30.118Z
Rudra Verma, Senior Security Architect & Researcher