Menu

Categories

Tags

Revoking a stolen GitHub token triggers this worm to shred your home directory

May 14, 2026 | alex | Developer, Microsoft | 135 views 0 comments

The hacker group TeamPCP, responsible for the npm supply chain attack that compromised packages including TanStack, has open-sourced the worm's full source code on GitHub under the MIT license. But the code contains a hidden dead man's switch: if a victim developer revokes the stolen GitHub or cloud credentials without fully cleaning up the worm's files, the malware immediately wipes the entire home directory.

Security researchers confirm the worm installs a daemon on macOS or Linux that checks every minute whether the stolen tokens are still valid. Once the server rejects them — meaning the victim has rotated their credentials — the worm runs the system's shred command to irreversibly overwrite all writable files in the current user's home directory. This upends the standard security response: companies usually revoke credentials immediately after a leak, but in this case that action triggers a destructive local wipe. The worm has been confirmed to infect nearly 400 versions of over 170 packages, including TanStack, UiPath, and Mistral AI. The hacker, operating under the account 'PedroTortoriello,' published the code and taunted 'open-sourcing the slaughter,' prompting a third party to submit a pull request adding FreeBSD support. Microsoft quickly banned the account and removed all GitHub repositories and forks, but the leaked source code continues to circulate elsewhere.

Tags: #Github

Leave a Reply

Your email address will not be published. Required fields are marked *