Open Source · · 1 day

cross-stitch npm package carried Shai-Hulud

JFrog listed 1 cross-stitch npm package in the May 2026 Shai-Hulud wave. This record scopes those artifacts to their own official distribution surface.

Part of Shai-Hulud hits npm and PyPI campaign

The cross-stitch package was not the largest Shai-Hulud victim, but it shows the campaign's basic economics. JFrog listed five affected npm releases under the cross-stitch name, giving TeamPCP another trusted registry object that could execute during a normal install.

Shai-Hulud did not rely on a vulnerable application path. It relied on where package installation happens. If cross-stitch installed on a developer workstation, CI runner, or automation host, the payload could search for credentials and publishing tokens in the same environment that maintains other packages.

This page keeps the package-level evidence out of the campaign aggregate. The broader [[shai-hulud-here-we-go-again]] record carries the shared worm mechanics, including credential theft and republishing. This record preserves the package name, affected versions, npm distribution URLs, and the May 11-12 exposure window.

The response is correspondingly concrete: find every install or cache hit for the affected cross-stitch versions, then rotate credentials associated with those machines from a clean system. A small package can still become a propagation point if it lands in a privileged publishing environment.

Notes

  • The network and payload indicators are the campaign-level set JFrog published for this wave, not observations of this package's own bytes. They identify the wave's infrastructure and persistence, and are recorded here so each affected distribution surface carries them. Where a record also lists indicators read from an acquired sample, those are marked as such.
  • Minimal campaign-linked record created to keep Shai-Hulud package evidence scoped by vendor, organization, maintainer account, or package distribution surface.

Appendix · Affected releases

1.1.7 sha256 9bd2833a…83c4f8c1 download unavailable
1.1.5 sha256 98862d8f…35b8c2be download unavailable
1.1.6 sha256 c6447760…7daa5f61 download unavailable
1.1.4 sha256 24b9b1f7…2f287242 download unavailable
1.1.3 sha256 e0ef0040…fc4ca959 download unavailable

Indicators

  • file_sha256npm payload 29c729852fce5a53e30a1541d9fec79c915b2e13f1eda94a5978cf0aae0d88d9
  • file_sha256npm payload 2ec78d556d696e208927cc503d48e4b5eb56b31abc2870c2ed2e98d6be27fc96
  • file_sha256npm payload ab4fcadaec49c03278063dd269ea5eef82d24f2124a8e15d7b90f2fa8601266c
  • file_sha256npm payload d4a2086ea18f5e39cd867b8b06918a524eabb21d45ea98aad07357b98173458a
  • urlhttps://filev2.getsession.org/file/
  • domainseed1.getsession.org
  • domainseed2.getsession.org
  • domainseed3.getsession.org
  • domainapi.masscan.cloud
  • file~/.local/bin/gh-token-monitor.sh
  • file~/.config/systemd/user/gh-token-monitor.service
  • file~/Library/LaunchAgents/com.user.gh-token-monitor.plist
  • file~/.config/gh-token-monitor/
  • stringShai-Hulud: Here We Go Again
  • stringPUSH UR T3MPRR
  • stringFIRESCALE
  • commit_authorclaude@users.noreply.github.com

References

  1. Shai-Hulud: Here We Go Again - Worm by TeamPCP Hits NPM and PyPIresearch.jfrog.com
  2. TanStack npm Packages Compromised in Ongoing Mini Shai-Hulud Supply Chain Attack - Socketsocket.dev
  3. Mini Shai-Hulud Is Back: npm Worm Hits over 160 Packages, including Mistral and Tanstack - Aikidoaikido.dev
  4. Retained jsDelivr flat member manifest for cross-stitch 1.1.4data.jsdelivr.com
  5. Retained jsDelivr flat member manifest for cross-stitch 1.1.5data.jsdelivr.com
  6. Retained jsDelivr flat member manifest for cross-stitch 1.1.6data.jsdelivr.com
  7. Upstream cross-stitch tree used for 607 exact documentation overlaysgithub.com

Source record: oss/attacks/shai-hulud-cross-stitch-npm/meta.yaml