TeamPCP has open sourced their Shai-Hulud project.

It can be downloaded here.

https://vx-underground.org/tmp

#cybersecurity #infosec #teampcp #shaihuludmalware #supplychainattack

🐛🤖 "Shai-Hulud-themed malware" in PyTorch Lightning? Really? What's next, a Bene Gesserit ransomware? This is just another excuse for a #cybersecurity company to throw #buzzwords like multimodal and AI at us while riding the #sandworm of #fearmongering. 📈🔒
https://semgrep.dev/blog/2026/malicious-dependency-in-pytorch-lightning-used-for-ai-training/ #ShaiHuludMalware #PyTorchLightning #HackerNews #ngated
Shai-Hulud Themed Malware Found in the PyTorch Lightning AI Training Library

The PyPI package lightning was compromised in versions 2.6.2 and 2.6.3 with Mini Shai-Hulud themed malicious code to execute credential-stealing malware on import.

Semgrep