Mini Shai-Hulud Hits 323 npm Packages, Steals 20+ creds — SkimNews

Get the Tech newsletter
Daily tech — startups, AI labs, chips, the launches that shape the next decade. Free.
- Mini Shai-Hulud campaign compromised npm packages tied to the maintainer account atool, including echarts-for-react, which sees roughly 1.1 million weekly downloads.
- TeamPCP is identified as the financially motivated threat actor behind the campaign and released the source code for a supply‑chain attack contest on BreachForums.
- Attacker published 639 malicious versions across 323 unique packages, with 558 versions across 279 @antv packages, embedding credential‑stealing code.
- Payload harvests more than 20 credential types—including AWS, Google Cloud, Azure, GitHub, npm, SSH, Kubernetes, Vault, Stripe and database strings—and exfiltrates data to t.m‑kosche.com and filev2.getsession.org via a Session P2P network.
- GitHub tokens stolen from CI/CD environments were used to create over 2,500 repositories bearing the reversed marker "Shai‑Hulud: Here We Go Again".
- Sigstore attestation pipeline was added, letting the attacker sign artifacts with legitimate Sigstore certificates using minted OIDC tokens, thereby forging SLSA provenance.
- Copycat actors have uploaded four malicious npm packages, one replicating the Shai‑Hulud worm with its own command‑and‑control infrastructure, showing the framework is being reused.
Why it matters: Enterprises that automatically pull npm updates now face exposure to credential theft across AWS, Google Cloud, Azure, GitHub, and other services, while the attacker gains access to thousands of CI/CD environments and can exfiltrate data to its own servers. The rapid, automated publishing and forged Sigstore attestations make detection harder, amplifying the risk to any organization using the compromised packages.
Ask SkimNews




