Open Source · · 1 day

ML Toolkit TS npm packages carried Shai-Hulud

JFrog listed 3 ML Toolkit TS npm packages in the May 2026 Shai-Hulud wave. This record scopes those artifacts to their own official distribution surface.

Part of Shai-Hulud hits npm and PyPI campaign

ML Toolkit TS was a three-package Shai-Hulud cluster. JFrog listed affected releases for @ml-toolkit-ts/preprocessing, @ml-toolkit-ts/xgboost, and ml-toolkit-ts, giving TeamPCP a foothold in machine-learning utility packages rather than only web application dependencies.

The technical risk still came from install-time execution. Development and training environments often carry cloud credentials, data-platform tokens, GitHub access, and package-registry credentials. In the Shai-Hulud wave, a compromised package install could harvest those secrets and use any available publish authority to continue the spread.

This record scopes the ML Toolkit TS artifacts as one trust boundary because the package names and versions are what defenders can search. The campaign page carries the common TeamPCP tooling, infrastructure, and self-propagation mechanics.

The cleanup question is whether the affected ML Toolkit TS versions reached a workstation, CI runner, notebook environment, or container build during May 11-12. A positive match should trigger credential rotation from a clean system and review of any package releases made from that environment.

Notes

  • The network and payload indicators are the campaign-level set JFrog published for this wave, not observations of this package's own bytes. They identify the wave's infrastructure and persistence, and are recorded here so each affected distribution surface carries them. Where a record also lists indicators read from an acquired sample, those are marked as such.
  • Minimal campaign-linked record created to keep Shai-Hulud package evidence scoped by vendor, organization, maintainer account, or package distribution surface.

Appendix · Affected releases

Indicators

  • file_sha256npm payload 29c729852fce5a53e30a1541d9fec79c915b2e13f1eda94a5978cf0aae0d88d9
  • file_sha256npm payload 2ec78d556d696e208927cc503d48e4b5eb56b31abc2870c2ed2e98d6be27fc96
  • file_sha256npm payload ab4fcadaec49c03278063dd269ea5eef82d24f2124a8e15d7b90f2fa8601266c
  • file_sha256npm payload d4a2086ea18f5e39cd867b8b06918a524eabb21d45ea98aad07357b98173458a
  • urlhttps://filev2.getsession.org/file/
  • domainseed1.getsession.org
  • domainseed2.getsession.org
  • domainseed3.getsession.org
  • domainapi.masscan.cloud
  • file~/.local/bin/gh-token-monitor.sh
  • file~/.config/systemd/user/gh-token-monitor.service
  • file~/Library/LaunchAgents/com.user.gh-token-monitor.plist
  • file~/.config/gh-token-monitor/
  • stringShai-Hulud: Here We Go Again
  • stringPUSH UR T3MPRR
  • stringFIRESCALE
  • commit_authorclaude@users.noreply.github.com

References

  1. Shai-Hulud: Here We Go Again - Worm by TeamPCP Hits NPM and PyPIresearch.jfrog.com
  2. TanStack npm Packages Compromised in Ongoing Mini Shai-Hulud Supply Chain Attack - Socketsocket.dev
  3. Mini Shai-Hulud Is Back: npm Worm Hits over 160 Packages, including Mistral and Tanstack - Aikidoaikido.dev
  4. Socket retained file listing for ml-toolkit-ts 1.0.4socket.dev
  5. Socket retained file listing for ml-toolkit-ts 1.0.5socket.dev
  6. Socket retained file listing for @ml-toolkit-ts/preprocessing 1.0.2socket.dev
  7. Socket retained file listing for @ml-toolkit-ts/preprocessing 1.0.3socket.dev
  8. Socket retained file listing for @ml-toolkit-ts/xgboost 1.0.3socket.dev
  9. Socket retained file listing for @ml-toolkit-ts/xgboost 1.0.4socket.dev

Source record: oss/attacks/shai-hulud-ml-toolkit-ts-npm/meta.yaml