Open Source · · 1 day

git-git-git npm package carried Shai-Hulud

JFrog listed 1 git-git-git npm package in the May 2026 Shai-Hulud wave. This record scopes those artifacts to their own official distribution surface.

Part of Shai-Hulud hits npm and PyPI campaign

git-git-git was another small but relevant developer-tooling package in the May 2026 Shai-Hulud wave. JFrog listed five affected npm releases under the git-git-git name, all tied to the same TeamPCP campaign window.

The package name points at the risk. Tools that wrap or assist Git activity often run on workstations and CI hosts with repository access, SSH keys, GitHub credentials, npm tokens, and cloud configuration nearby. Shai-Hulud's install-time payload was designed to harvest that environment and use any publishing authority it found.

This record keeps git-git-git separate from the larger campaign count because defenders need package-granular evidence. The campaign page carries the common malware behavior and propagation model; this page preserves the artifact names, versions, dates, and npm locations.

A matching install should trigger a host-centered investigation. The important question is not whether the package was part of a production runtime, but whether the affected release executed where credentials were present and where additional packages could be published.

Notes

  • The network and payload indicators are the campaign-level set JFrog published for this wave, not observations of this package's own bytes. They identify the wave's infrastructure and persistence, and are recorded here so each affected distribution surface carries them. Where a record also lists indicators read from an acquired sample, those are marked as such.
  • Minimal campaign-linked record created to keep Shai-Hulud package evidence scoped by vendor, organization, maintainer account, or package distribution surface.

Appendix · Affected releases

1.0.12 sha256 96826fe3…fa4245cc download unavailable
1.0.11 sha256 386d4e81…8e0c5721 download unavailable
1.0.10 sha256 264f78b7…b30ad4b7 download unavailable
1.0.9 sha256 de7bc08f…7adc8d8a download unavailable
1.0.8 sha256 ddd54229…699eeddb download unavailable

Indicators

  • file_sha256npm payload 29c729852fce5a53e30a1541d9fec79c915b2e13f1eda94a5978cf0aae0d88d9
  • file_sha256npm payload 2ec78d556d696e208927cc503d48e4b5eb56b31abc2870c2ed2e98d6be27fc96
  • file_sha256npm payload ab4fcadaec49c03278063dd269ea5eef82d24f2124a8e15d7b90f2fa8601266c
  • file_sha256npm payload d4a2086ea18f5e39cd867b8b06918a524eabb21d45ea98aad07357b98173458a
  • urlhttps://filev2.getsession.org/file/
  • domainseed1.getsession.org
  • domainseed2.getsession.org
  • domainseed3.getsession.org
  • domainapi.masscan.cloud
  • file~/.local/bin/gh-token-monitor.sh
  • file~/.config/systemd/user/gh-token-monitor.service
  • file~/Library/LaunchAgents/com.user.gh-token-monitor.plist
  • file~/.config/gh-token-monitor/
  • stringShai-Hulud: Here We Go Again
  • stringPUSH UR T3MPRR
  • stringFIRESCALE
  • commit_authorclaude@users.noreply.github.com

References

  1. Shai-Hulud: Here We Go Again - Worm by TeamPCP Hits NPM and PyPIresearch.jfrog.com
  2. TanStack npm Packages Compromised in Ongoing Mini Shai-Hulud Supply Chain Attack - Socketsocket.dev
  3. Mini Shai-Hulud Is Back: npm Worm Hits over 160 Packages, including Mistral and Tanstack - Aikidoaikido.dev
  4. Retained jsDelivr flat member manifest for git-git-git 1.0.8data.jsdelivr.com
  5. Retained jsDelivr flat member manifest for git-git-git 1.0.9data.jsdelivr.com
  6. Retained jsDelivr flat member manifest for git-git-git 1.0.10data.jsdelivr.com
  7. Retained jsDelivr flat member manifest for git-git-git 1.0.11data.jsdelivr.com
  8. Retained jsDelivr flat member manifest for git-git-git 1.0.12data.jsdelivr.com

Source record: oss/attacks/shai-hulud-git-git-git-npm/meta.yaml