Shai-Hulud is a self-propagating software supply-chain worm that emerged in the npm ecosystem in 2025 and became a defining example of malicious package republication through compromised maintainer trust. It spreads by stealing developer publishing credentials and secrets from developer workstations and CI/CD environments, then using those credentials to inject malicious versions into additional packages controlled by the victim. Later waves expanded the scale of compromise to hundreds of packages and adapted to ecosystem defenses by shifting execution techniques and abusing trusted publishing workflows and release automation.
The malware is associated with open-source package ecosystem attacks centered on npm, with later reporting also linking related variants and derivative campaigns to PyPI and Packagist. Shai-Hulud is designed for automated propagation through dependency graphs, developer machines, and build pipelines. Reported capabilities include theft of npm tokens, GitHub personal access tokens, cloud credentials, and other secrets, followed by exfiltration and reuse of those credentials to continue spreading. Some reporting also describes destructive fallback behavior in later variants when usable credentials were not available.
Shai-Hulud and its variants have been linked in multiple reports to TeamPCP, a threat group active in software supply-chain compromise and credential theft campaigns. The malware family has been cited in compromises affecting prominent open-source packages and in downstream intrusions where stolen developer or cloud credentials enabled access to corporate environments. The campaign illustrates a shift from opportunistic malicious packages toward targeted compromise of maintainers, CI/CD workflows, and trusted release channels.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
CVE-2025-10894 highlights how a single workflow misconfiguration can cascade into widespread compromise across the JavaScript ecosystem. The attack chain for CVE-2025-10894 began with exploitation of a GitHub Actions workflow in the Nx repository. The workflow used the pull_request_target trigger, which grants elevated permissions (including a writable GITHUB_TOKEN) to workflows running on pull requests from forks. Attackers crafted pull requests with titles containing bash injection payloads. | The campaign escalated with the release of a self-replicating worm (Shai-Hulud) that used harvested npm credentials to infect additional packages, resulting in over 500 compromised npm projects.
Shai-Hulud is a self-propagating, info-stealing malware that infects software components, uses the access to publish poisoned versions, and then harvests the repository accounts of those affected by the malware downstream.
359 GitHub repos created with encrypted stolen credentials — “Shai-Hulud: Here We Go Again.” CVE-2026-45321 published CVSS 9.6 critical. Mitre, CISA, and major registry operators issue coordinated advisories. | Shai-Hulud is, at this point, a very familiar name... The most recent one being the so-called Mini Shai-Hulud... they are back again... compromising the TanStack Router packages, and starting a brand new campaign based on Mini Shai-Hulud.
In the Shai-Hulud incident, the compromised packages (MAL-2025-46974 and CVE-2025-59144) were identified early, providing actionable findings that customers could remediate quickly.
8 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
TeamPCP prostredníctvom kampane Mini Shai-Hulud kompromitovalo viacero prominentných knižníc NPM a PyPI... Kampaň Shai-Hulud je pokračujúci útok na dodávateľské reťazce v npm ekosystéme... Po inštalácii dokáže kradnúť tokeny, prihlasovacie údaje pre GitHub a cloudové kľúče a šíri sa do ďalších balíkov.
In the Shai-Hulud / Miasma family of supply chain worms, the description stamped onto attacker-created GitHub dead-drop repos has functioned as a campaign signature since the original wave hit in September 2025.
In the Shai-Hulud / Miasma family of supply chain worms, the description stamped onto attacker-created GitHub dead-drop repos has functioned as a campaign signature since the original wave hit in September 2025.
The group often uses a purpose-built, self-replicating npm worm it developed called Shai-Hulud to infect GitHub projects.
researchers say are enabling variants of the Shai-Hulud supply-chain worm to infect and compromise hundreds of software packages and developer accounts worldwide.
A new wave of the Shai-Hulud supply chain campaign, adding 23 newly discovered malicious PyPI package-version artifacts to an already alarming operation that previously compromised 37 packages.
26 distinct techniques documented for this family, organized by ATT&CK tactic.
When a developer installed an infected component, the malware not only stole their secrets, but also used their credentials to hijack other packages they maintained automatically, republishing them in infected form to spread further.
we've already seen A LOT of supply chain attacks, most of them tracing back to Shai-Hulud and its variants.
Компрометация publishing identity - кража npm-токена или GitHub PAT (T1195.001, Initial Access)
Many recent npm supply-chain attacks such as Shai-Hulud and Shai-Hulud 2 relied on lifecycle scripts (preinstall, postinstall) to execute malware immediately during installation.
Дроппер определял ОС через os.platform() и запускал платформенно-специфичный payload (T1059.007 - JavaScript, Execution)
When a developer installed an infected component, the malware not only stole their secrets, but also used their credentials to hijack other packages they maintained automatically, republishing them in infected form to spread further.
Persistence - скрипт payload_1.sh устанавливает gh-token-monitor: на macOS через launchctl load
Отдельный модуль на Python читает /proc/<PID>/mem процесса Runner.Worker GitHub Actions, вытаскивая JSON-объекты с {"value":"...","isSecret":true}
When a developer installed an infected component, the malware not only stole their secrets, but also used their credentials to hijack other packages they maintained automatically, republishing them in infected form to spread further.
Defense Evasion (T1027, T1140). Payload обфусцирован в несколько слоёв: hex-кодирование строк, XOR-шифрование, AES-256-GCM, вложенные вызовы Function(atob(...)).
Отдельный модуль на Python читает /proc/<PID>/mem процесса Runner.Worker GitHub Actions, вытаскивая JSON-объекты с {"value":"...","isSecret":true}
After wave one, npm pushed Trusted Publishing... In response TeamPCP changes their malware to add a runtime memory extraction of an OIDC token. Specifically targeting that workflow.
the malware not only stole their secrets... The attack exposed more than 1,500 sensitive secrets, including AWS, Azure, GCP and GitHub tokens
The newly infected packages are the ones that depended on the original compromised package, or whose maintainers' credentials were harvested and used to publish malicious versions.
214 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
200 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Червь, компрометация которым сотрудника Suno, по словам злоумышленника, стала точкой входа для последующего проникновения в инфраструктуру компании.
Referenced as a known series of supply-chain worms used as a comparison point for Sandworm_Mode’s capabilities.
A worm referenced as the initial compromise vector: a Suno employee was reportedly compromised during a Shai-Hulud worm attack, which then enabled access to Suno infrastructure.
Referenced as a similar campaign/tool for comparison only; the article explicitly says the AsyncAPI malware is not attributed to Shai-Hulud.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.