Shai-Hulud is a self-propagating software supply-chain threat cluster centered on compromise of open-source package ecosystems, especially npm, with later activity and related variants extending into broader multi-ecosystem propagation. The name is most strongly associated with a September 2025 npm worm that harvested developer and CI/CD secrets from infected environments and then reused stolen publishing credentials to automatically trojanize additional packages controlled by the same maintainers. Security reporting commonly treats Shai-Hulud as a campaign family rather than a single incident, with later waves and adjacent variants including Shai-Hulud 2.0 and Mini Shai-Hulud; some reporting also discusses an evolutionary relationship with Miasma, though attribution between these labels is not always consistent and should be handled cautiously. The activity primarily targets developer workstations, CI/CD runners, source-code repositories, and package publishing pipelines. Victims have included maintainers of widely used JavaScript packages and organizations operating GitHub Actions-based release workflows. The campaign’s operational objective is credential theft and recursive propagation: malware implanted in a package steals GitHub tokens, npm tokens, cloud credentials, and other secrets, then abuses those credentials to publish malicious updates, alter repositories, create workflows, expose private repositories, or establish persistence inside developer tooling and automation environments. Observed tradecraft includes malicious npm lifecycle hooks and later payload embedding approaches designed to execute during installation or package use; secret discovery with tools and scripted searches; abuse of GitHub APIs and public repositories for exfiltration, dead-drop command retrieval, and covert command-and-control; creation or modification of GitHub Actions workflows to collect secrets; spoofing of trusted automation identities in commits; registration or abuse of self-hosted runners; and use of trusted publishing or OIDC-based release paths where available. Later variants associated with the broader cluster have also shown multi-stage loaders, Bun-based execution chains, encrypted payloads, repository poisoning, AI-editor persistence mechanisms, and attempts to spread across npm, PyPI, RubyGems, and Cargo when suitable credentials are found. Commonly reported victim data includes GitHub personal access tokens, package registry credentials, cloud provider credentials, Kubernetes and Vault secrets, environment variables, and other developer-resident secrets. Some variants have used GitHub-hosted infrastructure as the primary exfiltration and control channel, making activity blend with legitimate developer traffic. Reporting also notes locale-based guardrails in some related campaigns, including termination on Russian-language systems. Shai-Hulud is widely discussed alongside TeamPCP and Mini Shai-Hulud because of overlapping supply-chain tradecraft, GitHub-centric propagation, and credential-harvesting behavior. However, not every malware sample containing references to Shai-Hulud or Miasma is attributable to this cluster; multiple analyses explicitly note false-flag references and operationally adjacent copycats. High-confidence characterization therefore treats Shai-Hulud as a recurring supply-chain worm campaign focused on credential theft, repository compromise, CI/CD abuse, and automated republishing across maintainer-controlled packages.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
52 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced only for comparison; the article explicitly says the malware is not attributed to this campaign.
Conducted npm supply-chain compromise campaigns by trojanizing packages, harvesting GitHub/npm/cloud credentials, propagating automatically across maintainer-owned packages, exfiltrating secrets via GitHub workflows/webhooks, and in a later wave adding destructive file-wiping behavior when token theft failed.
Mentioned only as a comparison point; the report explicitly states the current AsyncAPI compromise is not attributed to this campaign.
Conducting a software supply chain attack by compromising AsyncAPI npm packages and injecting a multi-staged dropper into widely downloaded developer tooling.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.