Shai-Hulud Campaign Evolution: Miasma, Hades, and AI Scanner Evasion
ID: 8b1cf505-8954-5fa2-80b1-14f489abfa0d
STIX ID: report--8b1cf505-8954-5fa2-80b1-14f489abfa0d
Feed Name: Security Boulevard
Date Published: 2026-06-12
Date Updated: 2026-06-13
Author: Atinderpal Singh (Senior Manager, Threat Research)
Zscaler ThreatLabz describes the Shai-Hulud supply-chain campaign that progressed from maintainer-focused npm compromises into CI/CD and PyPI abuse, leveraging .pth persistence, OIDC token scraping in GitHub Actions to produce valid SLSA-attested malicious packages, IDE-configuration execution vectors, and prompt-injection to bypass LLM-based scanners; the actor (linked to TeamPCP/UNC6780 for early waves) publicly released the worm source on May 12, 2026, amplifying the threat and encouraging copycats, and the report includes detailed mitigation guidance and IOCs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
