logo

Worm Redux: Fresh Mini Shai-Hulud Infections Bite Supply Chain

ID: 782545cb-fba1-549f-b908-048811fd06aa

STIX ID: report--782545cb-fba1-549f-b908-048811fd06aa

Feed Name: Dark Reading

Threat Score
78/100

Date Published: 2026-05-12

Date Updated: 2026-05-12

Author: Elizabeth Montalbano

...
...

Mini Shai-Hulud is an active, worm-like malware campaign compromising npm packages—primarily in the TanStack ecosystem—to steal credentials from developer machines and CI/CD runners and then abuse maintainer publishing credentials and trusted release workflows to push trojanized updates; researchers have identified hundreds of malicious package versions and warn the campaign leverages obfuscation, Bun-based execution, IDE persistence, and CI/OIDC abuse to increase propagation and impact.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.