Mini Shai-Hulud is a supply-chain threat cluster associated with TeamPCP and focused on compromising open-source software ecosystems, especially npm and PyPI, to steal credentials and propagate through developer and CI/CD environments. The activity has been linked to broader related clusters and variants including Miasma and Hades. Operations attributed to this lineage have targeted widely used JavaScript and Python packages, including SAP-related npm packages, TanStack packages, bioinformatics and computational genomics tooling, MCP- and AI-themed Python packages, and the official durabletask Python SDK for Azure Durable Functions. The actor’s tradecraft centers on trusted-package compromise, maintainer account takeover, abuse of CI/CD publishing workflows, and malicious package updates signed or published through legitimate channels. Reported intrusion paths include theft or misuse of package publishing credentials, exploitation of GitHub Actions trust-boundary weaknesses such as pull_request_target and cache poisoning, and theft of OIDC tokens from GitHub Actions runners to publish malicious releases with valid provenance. In multiple campaigns, the actor used package installation or import-time execution to deploy loaders that fetched or launched obfuscated secondary payloads, including JavaScript executed via the Bun runtime and Python-based cloud intrusion tooling. Mini Shai-Hulud malware is primarily designed for credential theft and post-compromise expansion. Reported payloads harvested secrets from developer workstations and CI/CD systems, including GitHub, npm, PyPI, RubyGems, JFrog, cloud-provider credentials for AWS, Azure, and GCP, Kubernetes material, SSH keys, Docker configuration, shell histories, .env files, browser-stored credentials, and AI developer tool configurations. Exfiltration has been conducted through attacker-controlled infrastructure and through public repositories created using stolen victim tokens. The actor has also used encrypted exfiltration workflows and anti-analysis or evasion logic, including locale-based exclusions affecting Russian-language environments. A notable characteristic of this lineage is aggressive self-propagation and persistence in software development environments. Observed mechanisms include injecting malicious GitHub Actions workflows to steal repository secrets and publish further poisoned packages, modifying IDE task configurations to trigger execution when repositories are opened, abusing Claude Code SessionStart hooks, planting persistence through systemd user services and macOS LaunchAgents, and poisoning AI-enabled developer workflows. Related Hades variants also used Python .pth startup hooks, native extension loading, and split-staged loaders to evade source review and detection. The cluster has shown broad targeting of the open-source software supply chain rather than a single victim set, with emphasis on developers, maintainers, CI/CD pipelines, cloud workloads, and research-oriented Python users. Bioinformatics and computational genomics packages were specifically affected in PyPI waves, while enterprise JavaScript ecosystems and popular developer libraries were affected in npm campaigns. One linked operation against a cloud SDK also included lateral movement through AWS SSM and Kubernetes execution paths and a geographically conditioned destructive component affecting systems associated with Israel or Iran. Distinctive campaign markers reported for Mini Shai-Hulud include Dune-themed naming and repository descriptions, and the lineage has been publicly described as one of the earliest supply-chain campaigns to leverage AI coding-agent configuration as a persistence and propagation vector. The dominant pattern across reporting is financially motivated theft of credentials and access at scale through trusted software distribution channels.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
37 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
1 indicator attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A named worm variant referenced in reporting on malicious PyPI wheels targeting developers, likely related to the broader Shai-Hulud activity.
Part of a broader supply chain campaign affecting npm and PyPI, involving malicious package artifacts targeting developers and software supply chains.
Open-source supply chain threat lineage conducting malicious package campaigns across npm, Packagist, and now PyPI. In this wave it distributed malicious Python wheel artifacts that abuse .pth startup hooks, bootstrap the Bun JavaScript runtime, execute an obfuscated payload, harvest cloud and developer secrets, and exfiltrate them to attacker-controlled GitHub repositories.
A supply-chain campaign that compromised several open-source projects and pushed malicious updates; the group also compromised an OpenAI developer.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.