logo

Mini Shai-Hulud: Supply Chain Malware Attack

ID: 6c648135-7de4-5c77-a08a-4484df058362

STIX ID: report--6c648135-7de4-5c77-a08a-4484df058362

Feed Name: Arctic Wolf Blog

Threat Score
90/100

Date Published: 2026-05-12

Date Updated: 2026-06-11

...
...

**Mini Shai‑Hulud** is a coordinated supply‑chain campaign (attributed to TeamPCP) that poisoned npm and PyPI packages using GitHub Actions cache poisoning and mutable CI workflow triggers to exfiltrate CI/CD, cloud, and developer credentials; attackers deployed persistence daemons and have the capability to run destructive wiper payloads under certain conditions. The report provides immediate remediation guidance (package removal, credential rotation, hunting for persistence artifacts), short‑ and long‑term mitigations for CI/CD and dependency hygiene, and lists artifacts/IOCs and vendor upgrade recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.