logo

Shai-Hulud Part 2: When the Worm Forged Its Own Security Certificate by Lucie Cardiet

ID: dc290d89-2e25-5574-9c9c-fc84cc545b9f

STIX ID: report--dc290d89-2e25-5574-9c9c-fc84cc545b9f

Feed Name: Vectra AI Blog

Threat Score
88/100

Date Published: 2026-05-13

Date Updated: 2026-05-13

...
...

The report dissects the Shai-Hulud supply-chain worm (open-sourced by TeamPCP) which extracts GitHub Actions OIDC tokens from runner memory to request Sigstore Fulcio certificates and cosign SLSA Build Level 3 attestations, enabling poisoned packages to appear legitimately signed; a May 2026 campaign affected TanStack and over 170 packages (401 malicious versions). It explains why provenance checks fail (the attestation is accurate about identity but cannot attest to intended code), outlines behavioral detection signals spanning GitHub, Sigstore, and npm logs, and warns that public release of the toolkit will enable rapid, cross-platform proliferation and make signature-based scanning ineffective.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.