Mini Shai-Hulud is a self-replicating software supply-chain worm associated with the financially motivated threat cluster TeamPCP. It is designed to compromise developer environments and CI/CD pipelines, steal credentials and tokens, and use the stolen access to publish trojanized packages and spread across software ecosystems, particularly npm and PyPI. The malware has been described as an adapted descendant of earlier Shai-Hulud supply-chain worm activity and has spawned related campaigns and variants including Miasma and Hades.
Its core behavior centers on harvesting developer and build-system secrets, including CI/CD credentials, cloud access keys, personal access tokens, API keys, SSH keys, Kubernetes secrets, and other authentication material present in developer workstations and automated build environments. Stolen credentials are then weaponized to compromise additional repositories, package registries, and trusted release workflows, enabling automated propagation through downstream software dependencies. Multiple incidents linked to the malware involved abuse of legitimate publishing pipelines and trusted identities, including cases where malicious packages were released with valid provenance attestations after CI/CD compromise.
Mini Shai-Hulud has targeted both package-install and repository-centric execution paths. Reported delivery and execution mechanisms include malicious npm preinstall hooks, trojanized packages in npm and PyPI, and compromised trusted developer tooling such as Visual Studio Code extensions. Related activity also shows the malware or its variants abusing install-time execution paths that avoid obvious lifecycle-script indicators, as well as execution through imported package code or poisoned project configuration in developer workflows.
A notable feature of the malware family is persistence in developer tooling, especially AI-assisted coding environments. Mini Shai-Hulud has been observed scanning for configuration files associated with AI coding assistants and modifying them to inject hooks or instructions that silently execute malware whenever a developer starts an AI coding session. It has also been linked to persistence through developer workspace and automation files, allowing continued execution and further credential theft from trusted local environments.
The malware primarily targets developer workstations, source-code repositories, package maintainers, CI/CD runners, and cloud-connected build systems. Victim sectors are defined more by software supply-chain position than by industry, with compromises affecting open-source maintainers, security tooling, AI middleware, cloud-native projects, and widely used JavaScript and Python package ecosystems. Some reporting also describes destructive or sabotage-oriented behavior in certain waves, but the dominant and consistently corroborated role of Mini Shai-Hulud is as a credential-stealing, self-propagating supply-chain worm used to expand access and compromise additional software distribution channels.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The tracking identifier is CVE-2026-45321 (CVSS 9.6 per The Hacker News; advisory GHSA-g7cv-rxg3-hmpx per Snyk). | a new self-spreading Mini Shai-Hulud worm across npm and PyPI... poisoned roughly 170 npm and PyPI packages... plus a 1-in-6 disk-wipe payload on Israeli and Iranian locale hosts.
The four CVEs associated with this campaign are CVE-2026-33634, CVE-2026-48027, CVE-2026-45321, and CVE-2025-55182. | Mini Shai-Hulud was a self-replicating worm designed to spread across both npm and PyPI registries.
The four CVEs associated with this campaign are CVE-2026-33634, CVE-2026-48027, CVE-2026-45321, and CVE-2025-55182. | Mini Shai-Hulud was a self-replicating worm designed to spread across both npm and PyPI registries.
The four CVEs associated with this campaign are CVE-2026-33634, CVE-2026-48027, CVE-2026-45321, and CVE-2025-55182. | Mini Shai-Hulud was a self-replicating worm designed to spread across both npm and PyPI registries.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The financially motivated group TeamPCP was linked to some of the most significant activity, including the self-propagating “Mini Shai-Hulud” worm, which continued to spawn derivative campaigns, dubbed Miasma and Hades, after its source code was published to GitHub in May.
TanStack npm packages compromised: inside the Mini Shai-Hulud supply chain attack ... The TanStack attack is not an isolated incident. It is the latest wave in a series of npm supply chain attacks using the Shai-Hulud worm toolchain.
30 distinct techniques documented for this family, organized by ATT&CK tactic.
the attacker never stole maintainer npm credentials... the malicious versions were published by TanStack's legitimate release pipeline using its own trusted OIDC identity
The maintainer of a large number of packages was compromised, injecting malicious dependencies into the supply chain of multiple packages each of which exceeds 1 million weekly downloads...
The maintainer of a large number of packages was compromised, injecting malicious dependencies into the supply chain of multiple packages...
the worm injects persistence hooks into developer tooling, specifically .vscode/tasks.json and ~/.claude/settings.json , so it survives reboots on developer endpoints
For each one it finds, it injects a hook command which helps the malware stay persistent... every time the developer starts an AI coding session, the malware runs silently and automatically.
the worm injects persistence hooks into developer tooling, specifically .vscode/tasks.json and ~/.claude/settings.json , so it survives reboots on developer endpoints
the worm injects persistence hooks into developer tooling, specifically .vscode/tasks.json and ~/.claude/settings.json , so it survives reboots on developer endpoints
For AI tools that use markdown-based instruction files... the worm injects text designed to be interpreted by the LLM itself, not just executed by the shell.
a pull_request_target workflow ran fork-controlled code on a privileged GitHub Actions runner
The command and control (C2) infrastructure in this campaign masquerades as api.anthropic.com.
For AI tools that use markdown-based instruction files... the worm injects text designed to be interpreted by the LLM itself, not just executed by the shell.
the attacker never stole maintainer npm credentials... the malicious versions were published by TanStack's legitimate release pipeline using its own trusted OIDC identity
...a 1-in-6 chance of running a recursive wipe on systems matching Israeli or Iranian locales... The original TeamPCP campaign report documented a conditional wiper... checked whether the infected system's timezone was set to Iran or its default language was Farsi...
the pipeline's OIDC token was extracted from runner process memory
harvesting credentials and spreading to every GitHub repository that the developer’s token can reach... The propagation mechanism depends on stolen GitHub tokens
Also notable is the use of the FIRESCALE mechanism to identify a backup command-and-control (C2) address in the event the primary domain is unreachable.
The payload wasn’t just stealing tokens and exfiltrating credentials.
198 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
96 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as a more recent supply-chain worm related by comparison to Sandworm_Mode.
A self-propagating worm used in software supply-chain attacks, notable for spawning derivative campaigns after its source code was published.
A supply-chain worm targeting npm, PyPI, and other third-party registries. It steals tokens and credentials, rewrites AI coding assistant configuration and rules files for persistence, injects SessionStart hooks or prompt instructions, executes a staged payload such as ~/.config/index.js, and propagates through repositories reachable with stolen GitHub tokens.
Malware/campaign activity associated with software package compromise, theft of developer credentials, package-publishing access, cloud identities, and CI/CD targeting. Mentioned as sharing tactics and tooling concepts with Miasma, but not conclusively tied to this specific AsyncAPI attack.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.