logo

Mini Shai Hulud: Cross-ecosystem supply chain worm targeting npm & PyPI

ID: 88a76dc8-2714-59d7-96bf-776571efab91

STIX ID: report--88a76dc8-2714-59d7-96bf-776571efab91

Feed Name: Expel Blog

Threat Score
90/100

Date Published: 2026-05-12

Date Updated: 2026-07-16

...
...

On May 11, 2026, threat actor TeamPCP executed a large-scale supply-chain attack that compromised over 170 npm and PyPI packages (including TanStack, Mistral AI, OpenSearch). The worm "Mini Shai Hulud" hijacks GitHub Actions via pull_request_target and OIDC extraction to publish malicious updates with forged provenance, deploys an obfuscated credential stealer that exfiltrates AWS, GitHub, Vault, and Kubernetes secrets, and installs persistence into Claude Code and VS Code; the report includes IOCs (domains, file names, a malicious hash, IP, and author alias) and remediation guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.