Open Source · · 1 day

MesaDev npm packages carried Shai-Hulud

JFrog listed 3 MesaDev npm packages in the May 2026 Shai-Hulud wave. This record scopes those artifacts to their own official distribution surface.

Part of Shai-Hulud hits npm and PyPI campaign

MesaDev entered the May 2026 Shai-Hulud wave through three related npm packages: @mesadev/rest, @mesadev/saguaro, and @mesadev/sdk. JFrog listed one affected release for each package, putting the compromise across an API, SDK, and service-integration surface at the same time.

That pattern fits TeamPCP's goal. Packages used for service access and SDK integration tend to be installed in projects and CI jobs with tokens, cloud configuration, GitHub credentials, and package-publishing access nearby. Shai-Hulud used install-time execution to collect that material and look for the next package it could republish.

This page keeps the MesaDev namespace separate from the campaign aggregate. The broader [[shai-hulud-here-we-go-again]] record carries the shared loader and propagation behavior; this record preserves the exact package names, releases, registry paths, and May 11-12 exposure window.

For defenders, the package list is the starting point. A hit in a lockfile, package cache, build log, or local npm cache should be handled as a potential credential-exposure event, even if the application using MesaDev never shipped.

Notes

  • The network and payload indicators are the campaign-level set JFrog published for this wave, not observations of this package's own bytes. They identify the wave's infrastructure and persistence, and are recorded here so each affected distribution surface carries them. Where a record also lists indicators read from an acquired sample, those are marked as such.
  • Minimal campaign-linked record created to keep Shai-Hulud package evidence scoped by vendor, organization, maintainer account, or package distribution surface.

Appendix · Affected releases

Indicators

  • file_sha256npm payload 29c729852fce5a53e30a1541d9fec79c915b2e13f1eda94a5978cf0aae0d88d9
  • file_sha256npm payload 2ec78d556d696e208927cc503d48e4b5eb56b31abc2870c2ed2e98d6be27fc96
  • file_sha256npm payload ab4fcadaec49c03278063dd269ea5eef82d24f2124a8e15d7b90f2fa8601266c
  • file_sha256npm payload d4a2086ea18f5e39cd867b8b06918a524eabb21d45ea98aad07357b98173458a
  • urlhttps://filev2.getsession.org/file/
  • domainseed1.getsession.org
  • domainseed2.getsession.org
  • domainseed3.getsession.org
  • domainapi.masscan.cloud
  • file~/.local/bin/gh-token-monitor.sh
  • file~/.config/systemd/user/gh-token-monitor.service
  • file~/Library/LaunchAgents/com.user.gh-token-monitor.plist
  • file~/.config/gh-token-monitor/
  • stringShai-Hulud: Here We Go Again
  • stringPUSH UR T3MPRR
  • stringFIRESCALE
  • commit_authorclaude@users.noreply.github.com

References

  1. Shai-Hulud: Here We Go Again - Worm by TeamPCP Hits NPM and PyPIresearch.jfrog.com
  2. TanStack npm Packages Compromised in Ongoing Mini Shai-Hulud Supply Chain Attack - Socketsocket.dev
  3. Mini Shai-Hulud Is Back: npm Worm Hits over 160 Packages, including Mistral and Tanstack - Aikidoaikido.dev
  4. Retained jsDelivr member manifest for @mesadev/rest 0.28.3data.jsdelivr.com
  5. Retained jsDelivr member manifest for @mesadev/saguaro 0.4.22data.jsdelivr.com
  6. Retained jsDelivr member manifest for @mesadev/sdk 0.28.3data.jsdelivr.com
  7. Triage report for the exact shared router_init.js payloadtria.ge
  8. Socket retained file tree for @mesadev/rest 0.28.3socket.dev
  9. Socket retained file tree for @mesadev/saguaro 0.4.22socket.dev
  10. Socket retained file tree for @mesadev/sdk 0.28.3socket.dev

Source record: oss/attacks/shai-hulud-mesadev-npm/meta.yaml