Mini Shai-Hulud is a self-propagating credential-stealing worm associated with the cybercriminal group TeamPCP. Released as an open-source Shai-Hulud derivative in 2026, it targets developer workstations and CI/CD runners on Linux, macOS, and Windows. It spreads through software supply-chain compromises, including poisoned npm and PyPI packages and compromised GitHub Actions. Stolen publishing credentials enable it to enumerate accessible packages and distribute additional infected releases, extending compromises across projects and organizations.
The malware harvests package-registry tokens, GitHub credentials, cloud access keys, SSH keys, environment variables, Kubernetes credentials, and HashiCorp Vault secrets. Its collectors also target configuration data and credentials associated with AI development tools, including Claude, Codex, Cursor, and Gemini. Bun-based variants execute heavily obfuscated JavaScript through package installation hooks. Stolen information is exfiltrated through attacker-controlled infrastructure or public GitHub repositories created using compromised accounts. Variants encrypt collected data and retrieve command-and-control destinations from Ethereum smart contracts.
Mini Shai-Hulud establishes persistence by modifying Claude Code and Visual Studio Code configurations so that opening a project can re-execute the payload after the malicious dependency has been removed. Its ChainDrop variant abuses legitimate release workflows, allowing poisoned packages to carry valid publishing provenance and attestations. Some variants monitor stolen GitHub tokens and execute attacker-supplied code when those tokens are revoked. The family also uses misleading embedded text intended to interfere with AI-assisted security review.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The tracking identifier is CVE-2026-45321 (CVSS 9.6 per The Hacker News; advisory GHSA-g7cv-rxg3-hmpx per Snyk). | a new self-spreading Mini Shai-Hulud worm across npm and PyPI... poisoned roughly 170 npm and PyPI packages... plus a 1-in-6 disk-wipe payload on Israeli and Iranian locale hosts.
The four CVEs associated with this campaign are CVE-2026-33634, CVE-2026-48027, CVE-2026-45321, and CVE-2025-55182. | Mini Shai-Hulud was a self-replicating worm designed to spread across both npm and PyPI registries.
The four CVEs associated with this campaign are CVE-2026-33634, CVE-2026-48027, CVE-2026-45321, and CVE-2025-55182. | Mini Shai-Hulud was a self-replicating worm designed to spread across both npm and PyPI registries.
The four CVEs associated with this campaign are CVE-2026-33634, CVE-2026-48027, CVE-2026-45321, and CVE-2025-55182. | Mini Shai-Hulud was a self-replicating worm designed to spread across both npm and PyPI registries.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
In May, a related worm called Mini Shai-Hulud poisoned more than 400 package versions associated with 172 npm and PyPI packages in about five hours.
TanStack npm packages compromised: inside the Mini Shai-Hulud supply chain attack ... The TanStack attack is not an isolated incident. It is the latest wave in a series of npm supply chain attacks using the Shai-Hulud worm toolchain.
50 distinct techniques documented for this family, organized by ATT&CK tactic.
231 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
127 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Shai-Hulud variant mentioned as background to earlier ChainDrop compromises affecting hundreds of npm packages, including Keyv and Cacheable. It steals credentials and self-propagates through an obfuscated JavaScript payload executed using Bun.
A malware family described as continuing to use malicious workflow injection to steal credentials from CI/CD pipelines. It is mentioned for background, not identified as the payload responsible for the current GhostAction wave.
An open-source, TeamPCP-linked variant of Shai-Hulud used in supply-chain attacks. It propagates through stolen publishing credentials and can exfiltrate data to an HTTPS endpoint or, if unavailable, to public GitHub repositories.
Malware de chaîne d’approvisionnement distribué via des GitHub Actions compromises. Son payload obfusqué s’exécute dans les workflows qui référencent les actions affectées par des tags de version mutables et vise à dérober les jetons, identifiants et secrets CI/CD des développeurs.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.