Mini Shai-Hulud: Supply Chain Malware Attack
ID: 6c648135-7de4-5c77-a08a-4484df058362
STIX ID: report--6c648135-7de4-5c77-a08a-4484df058362
Feed Name: Arctic Wolf Blog
**Mini Shai‑Hulud** is a coordinated supply‑chain campaign (attributed to TeamPCP) that poisoned npm and PyPI packages using GitHub Actions cache poisoning and mutable CI workflow triggers to exfiltrate CI/CD, cloud, and developer credentials; attackers deployed persistence daemons and have the capability to run destructive wiper payloads under certain conditions. The report provides immediate remediation guidance (package removal, credential rotation, hunting for persistence artifacts), short‑ and long‑term mitigations for CI/CD and dependency hygiene, and lists artifacts/IOCs and vendor upgrade recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
