Open Source · · 1 day

OpenSearch prereleases carried Shai-Hulud

Four @opensearch-project/opensearch prereleases were published with Mini Shai-Hulud malware. OpenSearch removed them and blocked repository writes during credential rotation.

Part of Shai-Hulud hits npm and PyPI campaign

The OpenSearch project disclosed on the evening of May 11, 2026 that four prerelease versions of its official @opensearch-project/opensearch npm client had been published with malicious code as part of the wider Mini Shai-Hulud npm worm. The packages were pulled from npm by 11 p.m. EDT.

In an advisory posted to the seclists oss-sec mailing list, OpenSearch said the affected versions were 3.5.3, 3.6.2, 3.7.0, and 3.8.0. Any machine that installed or executed those packages between 0000 and 0300 UTC on May 12 should be treated as potentially fully compromised, the project said, with all local secrets and keys rotated from another system.

The advisory tied the activity to the broader Mini Shai-Hulud campaign against npm and CI/CD publishing infrastructure. Researchers at JFrog described the campaign's npm payload as a preinstall-script loader of obfuscated JavaScript that harvests credentials, exfiltrates through multiple redundant channels, and uses stolen access to publish more compromised packages.

OpenSearch said it removed the packages, blocked write permissions on project repositories, and began rotating credentials. This record carries the OpenSearch-specific package versions; the campaign record at [[shai-hulud-here-we-go-again]] carries the cross-package TeamPCP machinery.

Notes

  • The network and payload indicators are the campaign-level set JFrog published for this wave, not observations of this package's own bytes. They identify the wave's infrastructure and persistence, and are recorded here so each affected distribution surface carries them. Where a record also lists indicators read from an acquired sample, those are marked as such.

Appendix · Affected releases

3.5.3 no sample yet
3.6.2 no sample yet
3.7.0 no sample yet
3.8.0 sha256 47f04fbf…1c7dfae4 download unavailable

Indicators

  • file_sha256npm payload 29c729852fce5a53e30a1541d9fec79c915b2e13f1eda94a5978cf0aae0d88d9
  • file_sha256npm payload 2ec78d556d696e208927cc503d48e4b5eb56b31abc2870c2ed2e98d6be27fc96
  • file_sha256npm payload ab4fcadaec49c03278063dd269ea5eef82d24f2124a8e15d7b90f2fa8601266c
  • file_sha256npm payload d4a2086ea18f5e39cd867b8b06918a524eabb21d45ea98aad07357b98173458a
  • urlhttps://filev2.getsession.org/file/
  • domainseed1.getsession.org
  • domainseed2.getsession.org
  • domainseed3.getsession.org
  • domainapi.masscan.cloud
  • file~/.local/bin/gh-token-monitor.sh
  • file~/.config/systemd/user/gh-token-monitor.service
  • file~/Library/LaunchAgents/com.user.gh-token-monitor.plist
  • file~/.config/gh-token-monitor/
  • stringShai-Hulud: Here We Go Again
  • stringPUSH UR T3MPRR
  • stringFIRESCALE
  • commit_authorclaude@users.noreply.github.com

References

  1. Shai-Hulud: Here We Go Again - Worm by TeamPCP Hits NPM and PyPIresearch.jfrog.com
  2. TanStack NPM Packages Compromised in Mini Shai-Hulud Supply Chain Attacksocket.dev
  3. @opensearch-project/opensearch 3.8.0 file listing - Socketsocket.dev

Source record: oss/attacks/opensearch-js/meta.yaml