Mini Shai-Hulud is a self-replicating credential-stealing software supply-chain worm targeting open-source package ecosystems, principally npm and PyPI. It is delivered in trojanized package releases and executes through installation-time package hooks or equivalent package-loading mechanisms on developer workstations and CI/CD runners. The malware searches local files, environment variables, process memory, cloud metadata services, source-control settings, shell history, SSH material, package-manager configuration, and developer-tool configuration for package-registry credentials, code-hosting tokens, cloud credentials, CI/CD secrets, and AI-development-tool data. It validates recovered credentials and uses package-publishing permissions to inject its payload into additional packages, increment versions, and republish them, enabling rapid worm-like propagation across maintainers and organizations. Variants can enumerate repositories, cloud resources, secret stores, and workflow permissions; encrypt collected data prior to exfiltration; create public source-control repositories for data staging; modify source-control workflows; and establish persistence through development-tool configuration. ChainDrop and Miasma are reported variants or related evolutions of the Mini Shai-Hulud lineage. The malware has been associated in reporting and law-enforcement allegations with TeamPCP, though attribution should be distinguished from the separate original Shai-Hulud campaign. Its activity particularly threatens software publishers, developer endpoints, CI/CD infrastructure, and organizations whose build environments hold privileged publishing or cloud credentials.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The tracking identifier is CVE-2026-45321 (CVSS 9.6 per The Hacker News; advisory GHSA-g7cv-rxg3-hmpx per Snyk). | a new self-spreading Mini Shai-Hulud worm across npm and PyPI... poisoned roughly 170 npm and PyPI packages... plus a 1-in-6 disk-wipe payload on Israeli and Iranian locale hosts.
The four CVEs associated with this campaign are CVE-2026-33634, CVE-2026-48027, CVE-2026-45321, and CVE-2025-55182. | Mini Shai-Hulud was a self-replicating worm designed to spread across both npm and PyPI registries.
The four CVEs associated with this campaign are CVE-2026-33634, CVE-2026-48027, CVE-2026-45321, and CVE-2025-55182. | Mini Shai-Hulud was a self-replicating worm designed to spread across both npm and PyPI registries.
The four CVEs associated with this campaign are CVE-2026-33634, CVE-2026-48027, CVE-2026-45321, and CVE-2025-55182. | Mini Shai-Hulud was a self-replicating worm designed to spread across both npm and PyPI registries.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
“Mini Shai-Hulud was a self-replicating worm designed to spread across both npm and PyPI registries.”
TanStack npm packages compromised: inside the Mini Shai-Hulud supply chain attack ... The TanStack attack is not an isolated incident. It is the latest wave in a series of npm supply chain attacks using the Shai-Hulud worm toolchain.
29 distinct techniques documented for this family, organized by ATT&CK tactic.
The stolen material is encrypted and committed to public repositories using the victim's GitHub token. The malware can use recovered publishing access to modify and republish packages.
The attacker compromised the GitHub account of the maintainer of the keyv ecosystem, injecting malicious code into the source repository. This caused the project’s own GitHub Actions-based release pipeline to build and publish poisoned versions of packages including keyv, cacheable, flat-cache, and file-entry-cache.
In May, a piece of self-replicating malware known as “mini Shai-Hulud” targeted prominent software libraries, including TanStack, UiPath, and MistralAI, embedding credential-stealing code into development tools downloaded millions of times a week.
The C2 can respond with a code value that can specify a command to arm the dead-man switch
The malicious releases can run while a developer installs dependencies or when npm processes a specially crafted build configuration file... Four later versions also added a preinstall hook.
The stolen material is encrypted and committed to public repositories using the victim's GitHub token. The malware can use recovered publishing access to modify and republish packages.
macOS persistence ~/Library/LaunchAgents/com.user.systemd-detect-fash.plist, ~/Library/LaunchAgents/com.user.sysvinit-detect-fash.plist.
The stolen material is encrypted and committed to public repositories using the victim's GitHub token. The malware can use recovered publishing access to modify and republish packages.
macOS persistence ~/Library/LaunchAgents/com.user.systemd-detect-fash.plist, ~/Library/LaunchAgents/com.user.sysvinit-detect-fash.plist.
The loader is heavily disguised. It can download the Bun runtime if absent, decrypt the malware, run it from a temporary location, and remove that file afterward.
Active credential-stealing campaigns, such as Mini Shai-Hulud, Miasma, and Hades, embedding fake headers specifically engineered to fool AI-assisted review tools into marking code as benign.
Upon locating a GitHub token, it exfiltrates everything to a new public repo... If it finds an npm token, it calls the registry’s API to list every package the compromised developer maintains.
[bundle.js] searches the infected machine for anything resembling credentials, including npm and GitHub personal access tokens, AWS or GCP secrets, and whatever it can extract from a cloud instance’s metadata service.
AADInternals can gather unsecured credentials for Azure AD services, such as Azure AD Connect, from a local machine... Agent Tesla has the ability to extract credentials from configuration or support files... APT33 has used a variety of publicly available tools like LaZagne to gather credentials.
The malware added the feature of sending a unique value for each machine alongside the exfiltrated credentials. This value is a SHA256 hash of a concatenated list of system properties.
Investigators estimate the campaign exposed more than 500,000 credentials, removed at least 300 gigabytes of data ... masscan[.]cloud ... served as command server for mini Shai-Hulud.
230 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
119 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Shai-Hulud descendant focused on stealing credentials for AI coding tools, specifically Claude, Codex, Cursor, and Gemini.
Developer-environment and software-supply-chain malware that executes during package installation, steals developer, cloud, CI/CD, and package-registry credentials from files, environment variables, and Linux process memory; validates credentials; exfiltrates encrypted data through GitHub; establishes macOS/Linux and developer-tool persistence; poisons packages; modifies GitHub Actions workflows; and propagates through SSH. The content cautions that behavioral overlap does not conclusively attribute this incident to the same operator.
A worm for which masscan[.]cloud is identified as command-and-control infrastructure in the article; no further functionality is described.
Credential-stealing malware campaign that embeds fake prompt-injection-style headers intended to deceive AI-assisted code-review tools.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.