logo

Shai-Hulud code drop: It’s open season

ID: a76a63c0-c826-5b15-a60c-15b000fea620

STIX ID: report--a76a63c0-c826-5b15-a60c-15b000fea620

Feed Name: ReversingLabs Blog

Threat Score
90/100

Date Published: 2026-05-15

Date Updated: 2026-05-15

Author: Jaikumar Vijayan

...
...

TeamPCP publicly released the Shai-Hulud malware source code and researchers observed an active supply-chain campaign (the “Mini Shai-Hulud” attacks) that has compromised 150+ npm and PyPI packages; Shai-Hulud is a comprehensive offensive framework that harvests secrets (GitHub tokens, cloud credentials, npm tokens), poisons CI/CD pipelines and packages, persists via background services and a deadman switch, and exfiltrates data to attacker-controlled endpoints, substantially raising the risk of widespread, reusable supply-chain compromises and copycat variants.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.