logo

Mini Shai-Hulud Attack Prompts npm to Revoke 2FA-Bypass Tokens

ID: 6a5bbf2e-5da6-59b0-b451-6040188543da

STIX ID: report--6a5bbf2e-5da6-59b0-b451-6040188543da

Feed Name: GBHackers

Threat Score
88/100

Date Published: 2026-05-22

Date Updated: 2026-06-18

Author: Mayura Kathir

...
...

npm invalidated all write-enabled tokens that bypass 2FA and released a staged-publishing preview after the 'Mini Shai-Hulud' supply-chain campaign (attributed to TeamPCP) compromised hundreds of packages across npm, PyPI, and Composer. Attackers republished malicious versions by hijacking maintainer accounts, abusing CI/CD pipelines (including GitHub Actions cache poisoning and extracting OIDC tokens), and even spreading via a malicious VS Code extension that exfiltrated data from thousands of repositories; the report emphasizes rotating credentials, restricting CI token exposure, and adopting staged publishing to mitigate further supply-chain risk.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.