Also known as: tracked as, Mini Shai-Hulud, a worm
Shai‑Hulud is operated by the TeamPCP group and has evolved into a self‑replicating worm that leverages modern supply‑chain attack vectors across multiple ecosystems. It injects malicious post‑install lifecycle hooks—such as "setup_bun.js"—into popular npm packages to install the Bun JavaScript runtime, which then runs a multi‑stage credential stealer targeting local configuration files, environment variables, and cloud secret stores including AWS Secrets Manager, GCP Secret Manager, and Azure Key Vault. Beyond credential theft, Shai‑Hulud abuses GitHub Actions by injecting workflow files (e.g., "discussion.yaml") that run during CI/CD pipelines to exfiltrate secrets over HTTP/HTTPS, enumerate OIDC tokens from runner memory, and deploy self‑hosted runners under the attacker’s control. The malicious code also tamperes with system services—modifying systemd-resolved, flushing iptables, and in worst cases destroying writable home directories via overwrite or shred commands to hide activity. The actor demonstrates cross‑ecosystem propagation by targeting both npm/PyPI packages and IDE configuration files. It exploits compromised vulnerability scanners, misconfigured GitHub Actions, and malicious tarball distributions while using AI prompt injection to evade LLM‑based code scanners. By publishing malicious packages with valid SLSA provenance, Shai‑Hulud breaks trust chains at the highest assurance level, creating a highly resilient supply‑chain attack capable of widespread contamination.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
Shai‑Hulud is a supply‑chain worm that propagates through npm/PyPI packages and malicious GitHub Actions workflows, harvesting credentials from cloud secret stores and exfiltrating them via encoded payloads. It creates public repositories on victims’ accounts to leak stolen secrets and can manipulate system services for persistence or destructive impact. The actor demonstrates advanced evasion techniques such as AI‑prompt injection and SLSA provenance spoofing, making detection challenging.
Goals & Targeting
Shai‑Hulud primarily seeks financial gain by harvesting credential material that can be sold or leveraged for further compromise. The actor targets a broad spectrum of sectors—including government, defense, critical infrastructure, financial services, information technology, oil & gas, telecommunications, and non‑profits—across the United States, Saudi Arabia, and North Korea. These victims are chosen for their reliance on open‑source ecosystems and cloud environments, maximizing the likelihood of finding exposed secrets in npm/PyPI packages, GitHub Actions pipelines, and cloud secret stores.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Since its emergence, Shai‑Hulud has infected more than 25,000 GitHub repositories and distributed malicious npm packages on a daily basis. Campaigns exhibit high operational tempo with rapid seed and spread cycles; the actor leverages public supply‑chain channels to reach new victims quickly. While primarily focused on credential theft for financial exploitation, Shai‑Hulud’s destructive capabilities—such as overwriting user home directories—indicate potential pivoting toward broader impact attacks. Early iterations of the worm were limited to npm packages, but later versions expanded into PyPI and IDE configuration files, demonstrating adaptability.
IOC Patterns
Recommended Actions
No campaigns linked yet.
No observed data linked yet.
43
Techniques
53
Tools
0
Campaigns
40
IOCs
0
Observed Data
15
Tactics