Mini Shai-Hulud Hits 323 npm Packages, Steals 20+ creds

Get the Tech newsletter
Daily tech — startups, AI labs, chips, the launches that shape the next decade. Free.
- Mini Shai-Hulud campaign compromised npm packages tied to the maintainer account atool, including echarts-for-react, which sees roughly 1.1 million weekly downloads.
- TeamPCP is identified as the financially motivated threat actor behind the campaign and released the source code for a supply‑chain attack contest on BreachForums.
- Attacker published 639 malicious versions across 323 unique packages, with 558 versions across 279 @antv packages, embedding credential‑stealing code.
- Payload harvests more than 20 credential types—including AWS, Google Cloud, Azure, GitHub, npm, SSH, Kubernetes, Vault, Stripe and database strings—and exfiltrates data to t.m‑kosche.com and filev2.getsession.org via a Session P2P network.
- GitHub tokens stolen from CI/CD environments were used to create over 2,500 repositories bearing the reversed marker "Shai‑Hulud: Here We Go Again".
- Sigstore attestation pipeline was added, letting the attacker sign artifacts with legitimate Sigstore certificates using minted OIDC tokens, thereby forging SLSA provenance.
- Copycat actors have uploaded four malicious npm packages, one replicating the Shai‑Hulud worm with its own command‑and‑control infrastructure, showing the framework is being reused.
Why it matters: Enterprises that automatically pull npm updates now face exposure to credential theft across AWS, Google Cloud, Azure, GitHub, and other services, while the attacker gains access to thousands of CI/CD environments and can exfiltrate data to its own servers. The rapid, automated publishing and forged Sigstore attestations make detection harder, amplifying the risk to any organization using the compromised packages.




