logo

Shai-Hulud Campaign Evolution: Miasma, Hades, and AI Scanner Evasion

ID: 8b1cf505-8954-5fa2-80b1-14f489abfa0d

STIX ID: report--8b1cf505-8954-5fa2-80b1-14f489abfa0d

Feed Name: Security Boulevard

Threat Score
90/100

Date Published: 2026-06-12

Date Updated: 2026-06-13

Author: Atinderpal Singh (Senior Manager, Threat Research)

...
...

Zscaler ThreatLabz describes the Shai-Hulud supply-chain campaign that progressed from maintainer-focused npm compromises into CI/CD and PyPI abuse, leveraging .pth persistence, OIDC token scraping in GitHub Actions to produce valid SLSA-attested malicious packages, IDE-configuration execution vectors, and prompt-injection to bypass LLM-based scanners; the actor (linked to TeamPCP/UNC6780 for early waves) publicly released the worm source on May 12, 2026, amplifying the threat and encouraging copycats, and the report includes detailed mitigation guidance and IOCs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.