Open Source · · 1 day

guardrails-ai PyPI package carried Shai-Hulud

JFrog listed 1 guardrails-ai PyPI package in the May 2026 Shai-Hulud wave. This record scopes those artifacts to their own official distribution surface.

Part of Shai-Hulud hits npm and PyPI campaign

guardrails-ai is the PyPI outlier in a campaign dominated by npm. JFrog listed guardrails-ai version 0.10.1 as part of the May 2026 Shai-Hulud wave, showing that TeamPCP's package-publisher focus was not limited to JavaScript.

The risk profile was still familiar. A Python package install can run in notebooks, CI jobs, build containers, and developer shells that hold cloud credentials, repository tokens, and package-registry secrets. Shai-Hulud's campaign logic treated those environments as credential sources first and application runtimes second.

This record keeps the PyPI package separate from the npm aggregate so Python dependency inventories have a precise indicator. The campaign page explains the shared actor, infrastructure, and propagation behavior; this page pins the package name, version, registry location, and May 11-12 exposure window.

For response, the useful question is whether any trusted environment installed guardrails-ai==0.10.1 during the window. A match should lead to credential rotation and review from a clean machine, especially for systems that also had package-publishing or CI authority.

Notes

  • The network and payload indicators are the campaign-level set JFrog published for this wave, not observations of this package's own bytes. They identify the wave's infrastructure and persistence, and are recorded here so each affected distribution surface carries them. Where a record also lists indicators read from an acquired sample, those are marked as such.
  • Minimal campaign-linked record created to keep Shai-Hulud package evidence scoped by vendor, organization, maintainer account, or package distribution surface.

Appendix · Affected releases

  • Hash order is the complete malicious guardrails_ai-0.10.1-py3-none-any.whl and guardrails_ai-0.10.1.tar.gz PyPI distributions. The audit script's archive-specific detector names both files and SHA-256 values; these are not the extracted loader or transformers.pyz component hashes.

Indicators

  • file_sha256__init__.py 2a314ea8be337e1ca9ec833ed13ed854d9fd38bce0a519cf288f3bec8d9e6f30
  • file_sha256transformers.pyz 5245eb032e336b85cff0dbb3450d591826bf2ef214fd30d7eba1a763664e151b
  • ipv483.142.209.194
  • urlhttp://83.142.209.194/transformers.pyz
  • urlhttp://83.142.209.194/v1/models
  • urlhttp://83.142.209.194/v1/weights
  • urlhttp://83.142.209.194/audio.mp3
  • file/tmp/transformers.pyz
  • file~/.local/bin/pgmonitor.py
  • file/etc/systemd/system/pgsql-monitor.service
  • stringShai-Hulud: Here We Go Again
  • stringFIRESCALE

References

  1. Shai-Hulud: Here We Go Again - Worm by TeamPCP Hits NPM and PyPIresearch.jfrog.com
  2. Over 100 npm, PyPI Packages Hit in New Shai-Hulud Supply Chain Attacks - SecurityWeeksecurityweek.com
  3. Mini Shai-Hulud Is Back: npm Worm Hits over 160 Packages, including Mistral and Tanstack - Aikidoaikido.dev
  4. Malicious code in guardrails-ai 0.10.1 - Guardrails AI security advisorygithub.com
  5. Mini Shai-Hulud archive and payload audit scriptgist.github.com

Source record: oss/attacks/shai-hulud-guardrails-ai-pypi/meta.yaml