socket-dev · Crawled Sep 19, 2026

Happy Birthday, Shai-Hulud

6 IoCs 1 Actors 1 Malware
Read original article ↗

AI Summary

Shai-Hulud is a self-propagating worm that first appeared on npm in September 2025 by compromising the @ctrl/tinycolor package, which had over two million weekly downloads. The worm harvested credentials using TruffleHog, exfiltrated data to a public GitHub repository named Shai-Hulud, and used stolen npm tokens to propagate to other packages maintained by the victim. It established persistence via GitHub Actions workflows and evolved through multiple waves in late 2025 and 2026, with increasing sophistication and destructive capabilities. In May 2026, the source code was released publicly by TeamPCP, leading to widespread replication and new campaigns, including one leveraging short-lived OIDC tokens in CI environments. The original authors remain unattributed, though two alleged members of TeamPCP were arrested in August 2026.

AI-extracted · verify before operational use

Extracted Entities 2 found

Indicators of Compromise 6 extracted

Type Value Detail
Package @ctrl/tinycolor Details →
Filename bundle.js Details →
Filename setup_bun.js Details →
Filename bun_environment.js Details →
GitHub Repo Shai-Hulud Details →
GitHub User TeamPCP Details →

MITRE ATT&CK TTPs 28 techniques