Mini Shai-Hulud is a self-replicating software supply-chain worm associated with the financially motivated threat cluster TeamPCP, also tracked as UNC6780. It is designed to compromise developer ecosystems and propagate across open-source package registries, especially npm and PyPI, by stealing credentials from developer workstations, CI/CD pipelines, and cloud-connected build environments, then using those credentials or trusted publishing workflows to release additional trojanized packages. Public reporting describes it as one of the defining malware families in TeamPCP’s 2026 campaign against developer tooling, security utilities, AI middleware, and widely used open-source libraries.
The malware’s core function is credential theft and automated propagation. Reported targets include CI/CD tokens, GitHub and package-registry publishing credentials, cloud access keys, personal access tokens, SSH material, Kubernetes secrets, and other developer-environment secrets. In compromised build environments, Mini Shai-Hulud has been observed abusing GitHub Actions and OpenID Connect trusted publishing flows, including theft of runner-resident tokens from process memory, allowing malicious packages to be published under legitimate identities with valid provenance attestations. This made some malicious releases appear trustworthy despite being attacker-controlled.
Mini Shai-Hulud has been linked to large multi-package poisoning events spanning both npm and PyPI, including compromises affecting major package ecosystems and downstream developer workflows. It has been described as cross-ecosystem and self-spreading, with infected packages serving as new distribution points for further credential theft and package compromise. Reporting also indicates persistence mechanisms on developer endpoints through modifications to developer-tool configuration and tasking files, enabling continued execution and follow-on theft after initial infection.
Beyond credential theft and propagation, some 2026 variants introduced destructive behavior. Reported samples included a probabilistic disk-wiping routine triggered on systems matching specific regional or language settings, marking an escalation from pure credential theft to sabotage. The broader TeamPCP ecosystem also used Mini Shai-Hulud alongside related malware families such as Miasma and Hades, and public release of the framework reportedly enabled derivative and copycat campaigns.
Mini Shai-Hulud primarily targets developer and CI/CD environments rather than consumer endpoints. Its operational objective is to weaponize trust relationships in software publishing pipelines, source repositories, and package-management workflows to achieve ecosystem-scale compromise, credential harvesting, persistence, and downstream supply-chain spread.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The tracking identifier is CVE-2026-45321 (CVSS 9.6 per The Hacker News; advisory GHSA-g7cv-rxg3-hmpx per Snyk). | a new self-spreading Mini Shai-Hulud worm across npm and PyPI... poisoned roughly 170 npm and PyPI packages... plus a 1-in-6 disk-wipe payload on Israeli and Iranian locale hosts.
The four CVEs associated with this campaign are CVE-2026-33634, CVE-2026-48027, CVE-2026-45321, and CVE-2025-55182. | Mini Shai-Hulud was a self-replicating worm designed to spread across both npm and PyPI registries.
The four CVEs associated with this campaign are CVE-2026-33634, CVE-2026-48027, CVE-2026-45321, and CVE-2025-55182. | Mini Shai-Hulud was a self-replicating worm designed to spread across both npm and PyPI registries.
The four CVEs associated with this campaign are CVE-2026-33634, CVE-2026-48027, CVE-2026-45321, and CVE-2025-55182. | Mini Shai-Hulud was a self-replicating worm designed to spread across both npm and PyPI registries.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
a new self-spreading Mini Shai-Hulud worm across npm and PyPI... poisoned roughly 170 npm and PyPI packages... plus a 1-in-6 disk-wipe payload on Israeli and Iranian locale hosts.
TanStack npm packages compromised: inside the Mini Shai-Hulud supply chain attack ... The TanStack attack is not an isolated incident. It is the latest wave in a series of npm supply chain attacks using the Shai-Hulud worm toolchain.
28 distinct techniques documented for this family, organized by ATT&CK tactic.
the attacker never stole maintainer npm credentials... the malicious versions were published by TanStack's legitimate release pipeline using its own trusted OIDC identity
Shai-Hulud spreads by republishing malicious versions of any packages the stolen npm and GitHub accounts can reach.
The first wave compromised dozens of packages in September 2025... Another variant, Mini Shai-Hulud, hit npm, PyPI, and Packagist in April and May 2026.
the worm injects persistence hooks into developer tooling, specifically .vscode/tasks.json and ~/.claude/settings.json , so it survives reboots on developer endpoints
a 1-in-6 chance of running a recursive wipe on systems matching Israeli or Iranian locales
TeamPCP modified tools including, but not limited to, Trivy, KICS, LiteLLM, and the Telnyx Python SDK. These tools are commonly integrated into enterprise development continuous integration (CI)/continuous delivery (CD) pipelines, cloud infrastructure, and security workflows.
the worm injects persistence hooks into developer tooling, specifically .vscode/tasks.json and ~/.claude/settings.json , so it survives reboots on developer endpoints
the attacker never stole maintainer npm credentials... the malicious versions were published by TanStack's legitimate release pipeline using its own trusted OIDC identity
TeamPCP modified tools including, but not limited to, Trivy, KICS, LiteLLM, and the Telnyx Python SDK. These tools are commonly integrated into enterprise development continuous integration (CI)/continuous delivery (CD) pipelines, cloud infrastructure, and security workflows.
the pipeline's OIDC token was extracted from runner process memory
If the machine is running inside AWS, it propagates itself to other EC2 instances using SSM.
Also notable is the use of the FIRESCALE mechanism to identify a backup command-and-control (C2) address in the event the primary domain is unreachable.
GitHub said... the activity involved exfiltration of GitHub-internal repositories only... the stealer is capable of harvesting credentials... and exfiltrating the data to the attacker-controlled domain.
198 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
90 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Cross-registry worm campaign affecting npm and PyPI packages in a coordinated supply-chain operation.
Self-propagating malware used by TeamPCP in software supply chain attacks to steal secrets and maintain access in compromised environments.
A self-replicating supply-chain worm that spreads autonomously across npm and PyPI registries, harvesting credentials and poisoning downstream packages and configuration files.
Self-replicating worm that spreads across npm and PyPI registries, harvesting credentials and poisoning the software supply chain.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.