Open Source · · 1 day
git-branch-selector npm package carried Shai-Hulud
JFrog listed 1 git-branch-selector npm package in the May 2026 Shai-Hulud wave. This record scopes those artifacts to their own official distribution surface.
Part of Shai-Hulud hits npm and PyPI campaign
git-branch-selector sat directly in the developer-tooling lane Shai-Hulud liked to abuse. JFrog listed five affected npm releases, all under the git-branch-selector package name, during the May 11-12 TeamPCP wave.
The package's purpose made the compromise more than a random registry hit. A tool used around Git workflows is likely to run on machines with repository access, SSH keys, GitHub tokens, npm credentials, and local configuration files. Those are the same assets the Shai-Hulud payload family was built to collect and turn into new publishing opportunities.
This record scopes that risk to the official npm distribution surface. The campaign page explains the shared loader, infrastructure, and propagation behavior; this page keeps the exact package name, version list, and registry URLs available for concrete exposure checks.
The response question is whether git-branch-selector appeared in a lockfile, build cache, CI job, or developer install during the affected window. Any hit should be handled as a possible credential-theft event, even if no production service imported the package.
Notes
- The network and payload indicators are the campaign-level set JFrog published for this wave, not observations of this package's own bytes. They identify the wave's infrastructure and persistence, and are recorded here so each affected distribution surface carries them. Where a record also lists indicators read from an acquired sample, those are marked as such.
- Minimal campaign-linked record created to keep Shai-Hulud package evidence scoped by vendor, organization, maintainer account, or package distribution surface.
Appendix · Affected releases
Indicators
- file_sha256npm payload 29c729852fce5a53e30a1541d9fec79c915b2e13f1eda94a5978cf0aae0d88d9
- file_sha256npm payload 2ec78d556d696e208927cc503d48e4b5eb56b31abc2870c2ed2e98d6be27fc96
- file_sha256npm payload ab4fcadaec49c03278063dd269ea5eef82d24f2124a8e15d7b90f2fa8601266c
- file_sha256npm payload d4a2086ea18f5e39cd867b8b06918a524eabb21d45ea98aad07357b98173458a
- urlhttps://filev2.getsession.org/file/
- domainseed1.getsession.org
- domainseed2.getsession.org
- domainseed3.getsession.org
- domainapi.masscan.cloud
- file~/.local/bin/gh-token-monitor.sh
- file~/.config/systemd/user/gh-token-monitor.service
- file~/Library/LaunchAgents/com.user.gh-token-monitor.plist
- file~/.config/gh-token-monitor/
- stringShai-Hulud: Here We Go Again
- stringPUSH UR T3MPRR
- stringFIRESCALE
- commit_authorclaude@users.noreply.github.com
References
- Shai-Hulud: Here We Go Again - Worm by TeamPCP Hits NPM and PyPIresearch.jfrog.com
- TanStack npm Packages Compromised in Ongoing Mini Shai-Hulud Supply Chain Attack - Socketsocket.dev
- Mini Shai-Hulud Is Back: npm Worm Hits over 160 Packages, including Mistral and Tanstack - Aikidoaikido.dev
- Retained jsDelivr flat member manifest for git-branch-selector 1.3.3data.jsdelivr.com
- Retained jsDelivr flat member manifest for git-branch-selector 1.3.4data.jsdelivr.com
- Retained jsDelivr flat member manifest for git-branch-selector 1.3.5data.jsdelivr.com
- Retained jsDelivr flat member manifest for git-branch-selector 1.3.6data.jsdelivr.com
- Retained jsDelivr flat member manifest for git-branch-selector 1.3.7data.jsdelivr.com
- Upstream git-branch-selector tree used for the exact screenshot overlaygithub.com
Source record: oss/attacks/shai-hulud-git-branch-selector-npm/meta.yaml