logo

Mini Shai-Hulud returns, compromising hundreds of npm packages

ID: 1f8b9d03-fd6b-5080-92cd-26c5ab1fc313

STIX ID: report--1f8b9d03-fd6b-5080-92cd-26c5ab1fc313

Feed Name: CyberScoop

Threat Score
85/100

Date Published: 2026-05-19

Date Updated: 2026-05-19

Author: Greg Otto

...
...

A self-replicating supply-chain worm named Mini Shai-Hulud, linked to threat actor TeamPCP, has resurfaced across hundreds of npm packages. It executes on install, harvests GitHub/npm tokens, SSH keys and cloud credentials, installs persistent backdoors in editor settings and as OS services, and uses compromised CI publishing tokens to propagate and publish poisoned packages; researchers warn that removing the package alone is insufficient and affected machines or runners should be treated as fully compromised.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.