Mini Shai-Hulud is a self-replicating software supply-chain worm associated primarily with the financially motivated threat cluster TeamPCP, also tracked as UNC6780. It is designed to compromise developer ecosystems and propagate across open-source package registries, especially npm and PyPI, by stealing CI/CD credentials, cloud access keys, personal access tokens, and other developer secrets from infected environments, then using those credentials to publish trojanized versions of additional packages. The malware has been described as an adapted version of a self-replicating worm first documented in 2025 and later publicized in a way that enabled broader imitation and derivative campaigns.
Operationally, Mini Shai-Hulud targets trusted software publishing workflows rather than end-user delivery channels. Reported campaigns abused legitimate release pipelines, GitHub Actions workflows, OIDC-based trusted publishing, and maintainer or publishing credentials to distribute malicious package versions with valid provenance attestations. In compromised packages, the malware has been observed harvesting secrets from CI/CD environments and developer workstations, including cloud credentials, API keys, SSH keys, Kubernetes secrets, and GitHub tokens. It has also been linked to persistence mechanisms on developer endpoints through modifications to common tooling and configuration locations, and to follow-on publication of infected packages across multiple ecosystems.
Mini Shai-Hulud has been tied to large-scale coordinated compromises affecting widely used developer and security tooling and package families, including incidents involving TanStack-related packages, PyPI packages, and other open-source ecosystems. Reporting also links the malware family to poisoned Visual Studio Code extension activity and broader TeamPCP intrusions into developer environments and internal repositories. Some waves introduced destructive behavior, including a probabilistic disk-wiping routine on systems matching specific regional settings, indicating that the malware evolved beyond credential theft and propagation into sabotage.
The malware family sits within a broader lineage that includes related or derivative campaigns such as Miasma and Hades. These descendants reused core tradecraft such as install-time execution, credential harvesting, GitHub Actions secret theft, configuration poisoning, and cross-ecosystem propagation. Mini Shai-Hulud is therefore best understood as both a specific worm and the foundation for a wider class of supply-chain malware focused on developer workstations, CI/CD infrastructure, cloud-connected build environments, and package publishing trust relationships.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The tracking identifier is CVE-2026-45321 (CVSS 9.6 per The Hacker News; advisory GHSA-g7cv-rxg3-hmpx per Snyk). | a new self-spreading Mini Shai-Hulud worm across npm and PyPI... poisoned roughly 170 npm and PyPI packages... plus a 1-in-6 disk-wipe payload on Israeli and Iranian locale hosts.
The four CVEs associated with this campaign are CVE-2026-33634, CVE-2026-48027, CVE-2026-45321, and CVE-2025-55182. | Mini Shai-Hulud was a self-replicating worm designed to spread across both npm and PyPI registries.
The four CVEs associated with this campaign are CVE-2026-33634, CVE-2026-48027, CVE-2026-45321, and CVE-2025-55182. | Mini Shai-Hulud was a self-replicating worm designed to spread across both npm and PyPI registries.
The four CVEs associated with this campaign are CVE-2026-33634, CVE-2026-48027, CVE-2026-45321, and CVE-2025-55182. | Mini Shai-Hulud was a self-replicating worm designed to spread across both npm and PyPI registries.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
a new self-spreading Mini Shai-Hulud worm across npm and PyPI... poisoned roughly 170 npm and PyPI packages... plus a 1-in-6 disk-wipe payload on Israeli and Iranian locale hosts.
TanStack npm packages compromised: inside the Mini Shai-Hulud supply chain attack ... The TanStack attack is not an isolated incident. It is the latest wave in a series of npm supply chain attacks using the Shai-Hulud worm toolchain.
28 distinct techniques documented for this family, organized by ATT&CK tactic.
the attacker never stole maintainer npm credentials... the malicious versions were published by TanStack's legitimate release pipeline using its own trusted OIDC identity
Topic 14 — AI Supply Chain Security ... The #1 trending model on Hugging Face was malware.
The first wave compromised dozens of packages in September 2025... Another variant, Mini Shai-Hulud, hit npm, PyPI, and Packagist in April and May 2026.
the worm injects persistence hooks into developer tooling, specifically .vscode/tasks.json and ~/.claude/settings.json , so it survives reboots on developer endpoints
a 1-in-6 chance of running a recursive wipe on systems matching Israeli or Iranian locales
TeamPCP modified tools including, but not limited to, Trivy, KICS, LiteLLM, and the Telnyx Python SDK. These tools are commonly integrated into enterprise development continuous integration (CI)/continuous delivery (CD) pipelines, cloud infrastructure, and security workflows.
the worm injects persistence hooks into developer tooling, specifically .vscode/tasks.json and ~/.claude/settings.json , so it survives reboots on developer endpoints
the attacker never stole maintainer npm credentials... the malicious versions were published by TanStack's legitimate release pipeline using its own trusted OIDC identity
TeamPCP modified tools including, but not limited to, Trivy, KICS, LiteLLM, and the Telnyx Python SDK. These tools are commonly integrated into enterprise development continuous integration (CI)/continuous delivery (CD) pipelines, cloud infrastructure, and security workflows.
the pipeline's OIDC token was extracted from runner process memory
If the machine is running inside AWS, it propagates itself to other EC2 instances using SSM.
Also notable is the use of the FIRESCALE mechanism to identify a backup command-and-control (C2) address in the event the primary domain is unreachable.
GitHub said... the activity involved exfiltration of GitHub-internal repositories only... the stealer is capable of harvesting credentials... and exfiltrating the data to the attacker-controlled domain.
198 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
91 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as part of an attacker playbook involving malicious software in software/model supply chains; described in connection with infostealer activity.
Cross-registry worm campaign affecting npm and PyPI packages in a coordinated supply-chain operation.
Self-propagating malware used by TeamPCP in software supply chain attacks to steal secrets and maintain access in compromised environments.
A self-replicating supply-chain worm that spreads autonomously across npm and PyPI registries, harvesting credentials and poisoning downstream packages and configuration files.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.