Shai-Hulud is a self-propagating npm software supply-chain campaign first identified in September 2025. It compromises trusted JavaScript packages to execute credential-stealing payloads on developer workstations and CI/CD runners. The malware searches for GitHub, npm, cloud-provider, SSH, Kubernetes, and other development secrets, then uses stolen package-publishing credentials to inject malicious releases into additional packages controlled by affected maintainers. This credential-driven republishing gives the campaign worm-like propagation within the npm ecosystem. The campaign has used package lifecycle hooks, obfuscated JavaScript payloads, GitHub-based secret staging and exfiltration, and abuse of legitimate repository and automation features. Later activity tracked as Shai-Hulud or Shai-Hulud 2.0, also called SHA1-Hulud, used the Bun runtime, targeted cloud and CI/CD credentials, and added malicious workflows or developer-environment configuration hooks for persistence and continued collection. Some later variants included destructive fallback behavior when usable credentials could not be obtained. Shai-Hulud is closely associated operationally with the late-2025 s1ngularity/Nx compromise because stolen credentials from that incident were used in subsequent propagation. Some 2026 activity has been linked by researchers to related variants known as Mini Shai-Hulud and to the modular Miasma framework; however, attribution of the original Shai-Hulud activity to TeamPCP remains unconfirmed. Other malware families that merely contain Shai-Hulud or Miasma references are not necessarily attributable to this campaign.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
45 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
3 malware families attributed to this actor across reporting.
5 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A self-propagating software-supply-chain worm activity that steals npm tokens and secrets, uses stolen publishing credentials to infect additional packages, and exfiltrates collected data through GitHub. Later variants used malicious OpenVSX extensions, compromised CI tokens, long-lived repository credentials, and Bun-based execution.
Named npm worm activity associated with a software supply-chain compromise affecting popular npm packages. The operation uses compromised maintainer access to publish malicious package versions, steals cloud and developer credentials, republishes trojanized packages using stolen tokens/OIDC trusted publishing, stages exfiltrated data in GitHub repositories, and establishes persistence via developer tooling and OS autostart mechanisms.
Referenced only for comparison; the article explicitly says the malware is not attributed to this campaign.
Named as a self-propagating npm malware/worm campaign used as comparative context for the evolution of npm supply-chain threats; not directly tied in the content to the main axios incident attribution.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.