logo

‘Mini Shai-Hulud’ malware compromises hundreds of open-source packages in sprawling supply-chain attack

ID: 7c8cc080-a292-5e64-85d3-ffe9ea4bee4d

STIX ID: report--7c8cc080-a292-5e64-85d3-ffe9ea4bee4d

Feed Name: CyberScoop

Threat Score
88/100

Date Published: 2026-05-12

Date Updated: 2026-05-12

Author: Greg Otto

...
...

A widespread software supply‑chain campaign named “mini Shai‑Hulud” compromised hundreds of open‑source packages (including high‑impact libraries such as TanStack’s React Router), embedding an obfuscated credential‑stealing worm that targets AWS, GCP, Kubernetes, Vault, and local developer secrets. Attackers abused CI/GitHub Actions via orphaned commits to publish malicious, provenance‑signed packages, persisted in developer tooling (e.g., .vscode, Anthropic Claude configs), exfiltrated data over the Session anonymous network, and issued extortion threats; researchers observed limited community spread but removed compromised versions from registries.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.