logo

Shai-Hulud Worm Steals Developer Secrets Across npm, GitHub, AWS, and Kubernetes

ID: 785e5d09-bfad-54ee-9059-44da3707835f

STIX ID: report--785e5d09-bfad-54ee-9059-44da3707835f

Feed Name: Cyber Press

Threat Score
85/100

Date Published: 2026-05-15

Date Updated: 2026-05-22

Author: Varshini

...
...

Shai-Hulud is a self-propagating, credential-stealing npm worm publicly released by threat actor TeamPCP that targets GitHub Actions, CI/CD pipelines, and developer environments to harvest GitHub, npm, AWS and Kubernetes credentials, exfiltrate them to a C2 (git-tanstack.com), and propagate via compromised GitHub accounts and malicious npm package publishes; the report provides technical details, targeted files, TTPs, and IOCs and warns of rapid code forking and expanded attack surface after the public release.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.