Mini Shai-Hulud is a software supply-chain threat cluster focused on compromising open-source package ecosystems, developer accounts, CI/CD workflows, and developer workstations. It has been linked by researchers to TeamPCP and overlaps with the related Miasma and Hades activity clusters. Operations have compromised npm, PyPI, GitHub Actions, and trusted package-publishing workflows, including packages used in SAP-oriented JavaScript development, bioinformatics, and AI/MCP development. The cluster steals developer credentials and secrets, including source-control and package-registry tokens, cloud credentials, CI/CD secrets, browser-stored credentials, SSH keys, container and Kubernetes material, environment files, and AI-development-tool configurations. Stolen data is encrypted and exfiltrated through attacker-controlled infrastructure and repositories created with victims' source-control tokens. The malware can use those tokens to poison repositories, inject malicious workflows, and publish further compromised package releases. Mini Shai-Hulud campaigns have used installation-time package hooks, Python interpreter startup hooks, malicious native-extension loading, compromised GitHub Actions, and abuse of OIDC trusted-publishing configurations. Payloads have used Bun to run obfuscated JavaScript across Python and JavaScript ecosystems. Persistence and propagation mechanisms include developer IDE tasks, AI coding-agent hooks, source-control workflows, Linux user services, and macOS launch agents. Hades variants have added obfuscation, anti-analysis logic—including Russian-locale exclusions and LLM-targeted non-executing comments—and lateral propagation through cloud-management and Kubernetes execution mechanisms. A linked cloud-intrusion payload included a geographically selective destructive capability against systems assessed as being in Israel or Iran.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
36 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
1 indicator attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Supply-chain activity linked to the compromise of two actions-cool GitHub Actions and @antv npm packages. The malicious GitHub Actions code harvested CI/CD-pipeline credentials and exfiltrated them to an attacker-controlled server; compromised mutable release tags could execute the payload again when the repositories were temporarily re-enabled.
A named worm variant referenced in reporting on malicious PyPI wheels targeting developers, likely related to the broader Shai-Hulud activity.
Part of a broader supply chain campaign affecting npm and PyPI, involving malicious package artifacts targeting developers and software supply chains.
Open-source supply chain threat lineage conducting malicious package campaigns across npm, Packagist, and now PyPI. In this wave it distributed malicious Python wheel artifacts that abuse .pth startup hooks, bootstrap the Bun JavaScript runtime, execute an obfuscated payload, harvest cloud and developer secrets, and exfiltrate them to attacker-controlled GitHub repositories.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.