Open Source 2026-05-11 · 1 day ·Credential Theft, Self Propagation

Taskflow Corp npm package carried Shai-Hulud

Part of the Shai-Hulud hits npm and PyPI campaign

JFrog listed 1 Taskflow Corp npm package in the May 2026 Shai-Hulud wave. This record scopes those artifacts to their own official distribution surface.

Story

Taskflow Corp appeared in the May 2026 Shai-Hulud wave through @taskflow-corp/cli. JFrog listed six affected npm releases, all within the campaign's May 11-12 package-publishing window.

A CLI package is a direct route into developer and automation environments. It can be installed globally, pulled into CI images, or run during build setup, which puts it near npm tokens, GitHub credentials, cloud configuration, and local secrets. That is the environment Shai-Hulud was built to mine.

This record keeps the Taskflow Corp package separate from the aggregate campaign count. The campaign page explains the shared loader and self-propagation machinery; this page preserves the package name, version set, registry URLs, and dates for inventory and cleanup.

A matching install should be handled as an install-time compromise, not merely a vulnerable library import. Any host or runner that resolved the affected @taskflow-corp/cli versions should have its credentials rotated and its subsequent package-publishing activity reviewed.

Affected Artifacts

Incident Context

Motive
Credential Theft
Attribution
Group
Cause
Compromised Account Credentials
Transitive
Yes
Actor
TeamPCP

Notes

  • Minimal campaign-linked record created to keep Shai-Hulud package evidence scoped by vendor, organization, maintainer account, or package distribution surface.

External References

Source record: oss/attacks/shai-hulud-taskflow-corp-npm/meta.yaml