Open Source · · 1 day
agentwork-cli npm package carried Shai-Hulud
JFrog listed 1 agentwork-cli npm package in the May 2026 Shai-Hulud wave. This record scopes those artifacts to their own official distribution surface.
Part of Shai-Hulud hits npm and PyPI campaign
The agentwork-cli record is a small slice of the May 2026 Shai-Hulud wave, but it is the slice an incident responder would search for in a package inventory. JFrog listed two malicious npm releases, 0.1.4 and 0.1.5, under the official agentwork-cli package name.
The package did not need a bespoke exploit. In this campaign, TeamPCP used compromised publishing access to turn ordinary package installs into credential-harvesting opportunities. A developer workstation or CI runner that installed the affected versions could expose npm tokens, GitHub material, cloud credentials, and other secrets the worm could use for the next publishing step.
That is why this page keeps the package separate from the aggregate campaign. The broader [[shai-hulud-here-we-go-again]] record explains the shared loader, infrastructure, and self-propagation behavior. This record pins the affected package name, versions, dates, and registry URLs to one trust boundary.
The operational question is narrow: did any build, lockfile, cache, or developer machine resolve agentwork-cli to one of those releases on May 11 or May 12? If yes, the cleanup path starts with credential rotation from a known-clean machine and a review of any downstream packages that environment could publish.
Notes
- The network and payload indicators are the campaign-level set JFrog published for this wave, not observations of this package's own bytes. They identify the wave's infrastructure and persistence, and are recorded here so each affected distribution surface carries them. Where a record also lists indicators read from an acquired sample, those are marked as such.
- Minimal campaign-linked record created to keep Shai-Hulud package evidence scoped by vendor, organization, maintainer account, or package distribution surface.
Appendix · Affected releases
Indicators
- file_sha256npm payload 29c729852fce5a53e30a1541d9fec79c915b2e13f1eda94a5978cf0aae0d88d9
- file_sha256npm payload 2ec78d556d696e208927cc503d48e4b5eb56b31abc2870c2ed2e98d6be27fc96
- file_sha256npm payload ab4fcadaec49c03278063dd269ea5eef82d24f2124a8e15d7b90f2fa8601266c
- file_sha256npm payload d4a2086ea18f5e39cd867b8b06918a524eabb21d45ea98aad07357b98173458a
- urlhttps://filev2.getsession.org/file/
- domainseed1.getsession.org
- domainseed2.getsession.org
- domainseed3.getsession.org
- domainapi.masscan.cloud
- file~/.local/bin/gh-token-monitor.sh
- file~/.config/systemd/user/gh-token-monitor.service
- file~/Library/LaunchAgents/com.user.gh-token-monitor.plist
- file~/.config/gh-token-monitor/
- stringShai-Hulud: Here We Go Again
- stringPUSH UR T3MPRR
- stringFIRESCALE
- commit_authorclaude@users.noreply.github.com
References
Source record: oss/attacks/shai-hulud-agentwork-cli-npm/meta.yaml