Shai-Hulud is a self-replicating software supply-chain worm targeting the npm and Node.js ecosystem, first discovered in mid-September 2025. It compromises trusted packages and executes malicious JavaScript through package-installation lifecycle hooks. It targets developer workstations, build runners, CI/CD pipelines, and connected cloud environments, harvesting npm publishing tokens, GitHub tokens, SSH keys, cloud credentials, Kubernetes authentication material, and other organizational secrets. Stolen data is exfiltrated to attacker-controlled infrastructure or public GitHub repositories.
The worm propagates by enumerating packages accessible through compromised publishing identities, injecting its payload, and republishing malicious versions. It also modifies repositories and injects GitHub Actions workflows to collect additional secrets and maintain access. Shai-Hulud 2.0 introduced preinstall execution, Bun-based payloads, and backdoored self-hosted runners. Later variants establish persistence through IDE and AI coding-tool configurations, Linux user services, macOS launch agents, and Windows scheduled tasks. Some variants steal browser credentials, cookies, and cryptocurrency-wallet data, support remotely supplied code execution, and use Ethereum-based dead drops to resolve remote infrastructure.
Certain variants include a destructive token-monitoring mechanism that can delete the infected user's home directory when a monitored GitHub token becomes invalid. Compromised releases can retain valid build-provenance attestations when legitimate release workflows publish already-malicious source code. TeamPCP has been associated with Shai-Hulud-related supply-chain operations, but this association does not establish attribution for every subsequent variant or campaign.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
9 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
MITRE CONTEXT — Exploits Vulnerabilities: CVE-2024-3400. Threat Names: Shai-Hulud.
MITRE CONTEXT — Exploits Vulnerabilities: CVE-2021-4436. Threat Names: Shai-Hulud.
MITRE CONTEXT — Exploits Vulnerabilities: CVE-2023-46747. Threat Names: Shai-Hulud.
MITRE CONTEXT — Exploits Vulnerabilities: CVE-2024-1709. Threat Names: Shai-Hulud.
MITRE CONTEXT — Exploits Vulnerabilities: CVE-2025-0282. Threat Names: Shai-Hulud.
CVE-2025-10894 highlights how a single workflow misconfiguration can cascade into widespread compromise across the JavaScript ecosystem. The attack chain for CVE-2025-10894 began with exploitation of a GitHub Actions workflow in the Nx repository. The workflow used the pull_request_target trigger, which grants elevated permissions (including a writable GITHUB_TOKEN) to workflows running on pull requests from forks. Attackers crafted pull requests with titles containing bash injection payloads. | The campaign escalated with the release of a self-replicating worm (Shai-Hulud) that used harvested npm credentials to infect additional packages, resulting in over 500 compromised npm projects.
Shai-Hulud is a self-propagating, info-stealing malware that infects software components, uses the access to publish poisoned versions, and then harvests the repository accounts of those affected by the malware downstream.
359 GitHub repos created with encrypted stolen credentials — “Shai-Hulud: Here We Go Again.” CVE-2026-45321 published CVSS 9.6 critical. Mitre, CISA, and major registry operators issue coordinated advisories. | Shai-Hulud is, at this point, a very familiar name... The most recent one being the so-called Mini Shai-Hulud... they are back again... compromising the TanStack Router packages, and starting a brand new campaign based on Mini Shai-Hulud.
In the Shai-Hulud incident, the compromised packages (MAL-2025-46974 and CVE-2025-59144) were identified early, providing actionable findings that customers could remediate quickly.
8 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
A malicious version of tensorlake (version 0.5.144) was hijacked with Shai-Hulud malware.
In the Shai-Hulud / Miasma family of supply chain worms, the description stamped onto attacker-created GitHub dead-drop repos has functioned as a campaign signature since the original wave hit in September 2025.
In the Shai-Hulud / Miasma family of supply chain worms, the description stamped onto attacker-created GitHub dead-drop repos has functioned as a campaign signature since the original wave hit in September 2025.
The group often uses a purpose-built, self-replicating npm worm it developed called Shai-Hulud to infect GitHub projects.
researchers say are enabling variants of the Shai-Hulud supply-chain worm to infect and compromise hundreds of software packages and developer accounts worldwide.
A new wave of the Shai-Hulud supply chain campaign, adding 23 newly discovered malicious PyPI package-version artifacts to an already alarming operation that previously compromised 37 packages.
37 distinct techniques documented for this family, organized by ATT&CK tactic.
These credentials are then encoded and exfiltrated to attacker-controlled endpoints.
The S1ngularity script exfiltrated Nx's NPM token; Shai-Hulud and CanisterWorm searched victim machines for npm tokens to publish malicious versions of associated packages.
These credentials are then encoded and exfiltrated to attacker-controlled endpoints, as well as uploaded to a public GitHub repository named Shai-Hulud.
284 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
200 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
The reported variant compromises developer workstations and CI/CD runners through tensorlake@0.5.144. A preinstall dropper downloads Bun and executes the core payload, which steals browser data, cryptocurrency wallet information, and development and cloud credentials. It persists through IDE tasks and AI-agent configuration changes, uses an Ethereum smart contract to retrieve fallback C2 destinations, and stages stolen data through GitHub repositories if other channels fail. Stolen publishing credentials enable propagation into additional npm packages and repositories. A background monitor reportedly triggers destructive wiping when a stolen GitHub token becomes invalid. The malicious Tensorlake release carried valid Sigstore provenance, demonstrating that build provenance alone does not establish code safety.
Self-propagating credential-stealing malware distributed through compromised npm packages. The Tensorlake SDK infection executes during installation with the installing process’s permissions, outside Tensorlake’s sandbox protections. It steals crypto wallets, browser passwords, GitHub Actions secrets, cloud credentials, and service-account tokens, exfiltrates data, and maintains command-and-control communications for further instructions. Under specific conditions, revocation of monitored stolen GitHub tokens can trigger deletion of the infected user’s home directory. The malicious SDK version was flagged 11 minutes after publication, removed from npm, and superseded by version 0.5.145; the extent of compromise remains unknown.
The variant embedded in tensorlake@0.5.144 executes during installation through an obscured preinstall loader, downloads the Bun runtime, and launches lib/Math_Symbol.js. It collects developer, cloud, CI/CD, SSH, Vault, browser, and cryptocurrency-wallet secrets and can use stolen publishing credentials to propagate through software supply chains. Its hardcoded command-and-control domain is iseekaigogo[.]com, with an Ethereum smart contract providing an alternative destination. The report also describes a destructive dead-man’s switch capable of wiping infected machines when an embedded GitHub token is revoked.
Referenced as a comparison for persistence through injected GitHub Actions workflows that continue collecting secrets after an initial npm supply-chain compromise. The article does not establish an operational connection to GhostAction.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.