Open Source · · 1 day

cmux-agent-mcp npm package carried Shai-Hulud

JFrog listed 1 cmux-agent-mcp npm package in the May 2026 Shai-Hulud wave. This record scopes those artifacts to their own official distribution surface.

Part of Shai-Hulud hits npm and PyPI campaign

The cmux-agent-mcp compromise was one of the narrower package records in the May 2026 Shai-Hulud wave. JFrog listed six affected cmux-agent-mcp npm versions, all published inside the same May 11-12 window that drove the broader TeamPCP campaign.

The package name matters because MCP tooling often sits in developer automation paths rather than end-user runtime paths. That is exactly where Shai-Hulud wanted to run. A package install in an agent, local development shell, or CI job could expose npm tokens, GitHub credentials, cloud metadata, SSH material, and other secrets before the user saw anything obviously wrong.

This record therefore treats cmux-agent-mcp as its own distribution surface. The campaign page explains the common loader and self-propagation mechanics; this page anchors the affected package name, version set, dates, and npm URLs for inventory and incident-response work.

Defenders do not need to prove the package was imported by a production service before acting. The risk begins when a privileged environment resolved and executed one of the affected releases. That makes package caches, build logs, and lockfiles as important as deployed application manifests.

Notes

  • The network and payload indicators are the campaign-level set JFrog published for this wave, not observations of this package's own bytes. They identify the wave's infrastructure and persistence, and are recorded here so each affected distribution surface carries them. Where a record also lists indicators read from an acquired sample, those are marked as such.
  • Minimal campaign-linked record created to keep Shai-Hulud package evidence scoped by vendor, organization, maintainer account, or package distribution surface.

Appendix · Affected releases

0.1.8 sha256 9578177f…7ca1787b download unavailable
0.1.7 sha256 b15c1408…15a7cbb8 download unavailable
0.1.6 sha256 c893f66f…e5a1c405 download unavailable
0.1.5 sha256 52bd37ce…9fbc6dd6 download unavailable
0.1.4 sha256 efdadfcf…92ade454 download unavailable
0.1.3 sha256 78a2e180…5d2cab99 download unavailable

Indicators

  • file_sha256npm payload 29c729852fce5a53e30a1541d9fec79c915b2e13f1eda94a5978cf0aae0d88d9
  • file_sha256npm payload 2ec78d556d696e208927cc503d48e4b5eb56b31abc2870c2ed2e98d6be27fc96
  • file_sha256npm payload ab4fcadaec49c03278063dd269ea5eef82d24f2124a8e15d7b90f2fa8601266c
  • file_sha256npm payload d4a2086ea18f5e39cd867b8b06918a524eabb21d45ea98aad07357b98173458a
  • urlhttps://filev2.getsession.org/file/
  • domainseed1.getsession.org
  • domainseed2.getsession.org
  • domainseed3.getsession.org
  • domainapi.masscan.cloud
  • file~/.local/bin/gh-token-monitor.sh
  • file~/.config/systemd/user/gh-token-monitor.service
  • file~/Library/LaunchAgents/com.user.gh-token-monitor.plist
  • file~/.config/gh-token-monitor/
  • stringShai-Hulud: Here We Go Again
  • stringPUSH UR T3MPRR
  • stringFIRESCALE
  • commit_authorclaude@users.noreply.github.com

References

  1. Shai-Hulud: Here We Go Again - Worm by TeamPCP Hits NPM and PyPIresearch.jfrog.com
  2. TanStack npm Packages Compromised in Ongoing Mini Shai-Hulud Supply Chain Attack - Socketsocket.dev
  3. Mini Shai-Hulud Is Back: npm Worm Hits over 160 Packages, including Mistral and Tanstack - Aikidoaikido.dev
  4. Socket retained file tree for cmux-agent-mcp 0.1.3socket.dev
  5. Socket retained file tree for cmux-agent-mcp 0.1.4socket.dev
  6. Socket retained file tree for cmux-agent-mcp 0.1.5socket.dev
  7. Socket retained file tree for cmux-agent-mcp 0.1.6socket.dev
  8. Socket retained file tree for cmux-agent-mcp 0.1.7socket.dev
  9. Socket retained file tree for cmux-agent-mcp 0.1.8socket.dev
  10. Retained jsDelivr flat member manifest for cmux-agent-mcp 0.1.6data.jsdelivr.com
  11. Retained jsDelivr flat member manifest for cmux-agent-mcp 0.1.7data.jsdelivr.com
  12. Retained jsDelivr flat member manifest for cmux-agent-mcp 0.1.8data.jsdelivr.com
  13. Upstream cmux-agent-mcp source tree used for reproducible build overlaysgithub.com

Source record: oss/attacks/shai-hulud-cmux-agent-mcp-npm/meta.yaml