Open Source · · 1 day

Tolka npm package carried Shai-Hulud

JFrog listed 1 Tolka npm package in the May 2026 Shai-Hulud wave. This record scopes those artifacts to their own official distribution surface.

Part of Shai-Hulud hits npm and PyPI campaign

Tolka was represented in the May 2026 Shai-Hulud wave by @tolka/cli. JFrog listed five affected npm releases, making the package another command-line distribution path for TeamPCP's credential-stealing loader.

CLI packages are valuable because they run where developers and CI systems prepare work. The affected Tolka releases could execute in environments holding npm publish tokens, GitHub credentials, cloud secrets, SSH keys, and other material the worm could use to spread.

This record keeps the Tolka package scoped to its own trust boundary. The broader campaign page carries the shared TeamPCP tooling, infrastructure, and propagation behavior; this page preserves the exact package name, affected versions, registry locations, and May 11-12 exposure window.

The cleanup workflow is package-led: search lockfiles, caches, build images, and CI logs for the listed @tolka/cli versions, then rotate credentials for any environment that installed them and review whether that environment published packages afterward.

Notes

  • The network and payload indicators are the campaign-level set JFrog published for this wave, not observations of this package's own bytes. They identify the wave's infrastructure and persistence, and are recorded here so each affected distribution surface carries them. Where a record also lists indicators read from an acquired sample, those are marked as such.
  • Minimal campaign-linked record created to keep Shai-Hulud package evidence scoped by vendor, organization, maintainer account, or package distribution surface.

Appendix · Affected releases

1.0.5 sha256 64022e6f…30621e93 download unavailable
1.0.6 sha256 00f75436…2fa5ab5a download unavailable
1.0.4 sha256 925b6fbf…93c6ad76 download unavailable
1.0.3 sha256 11753aa9…b8fb23bc download unavailable
1.0.2 sha256 71900c58…fcbb94e8 download unavailable

Indicators

  • file_sha256npm payload 29c729852fce5a53e30a1541d9fec79c915b2e13f1eda94a5978cf0aae0d88d9
  • file_sha256npm payload 2ec78d556d696e208927cc503d48e4b5eb56b31abc2870c2ed2e98d6be27fc96
  • file_sha256npm payload ab4fcadaec49c03278063dd269ea5eef82d24f2124a8e15d7b90f2fa8601266c
  • file_sha256npm payload d4a2086ea18f5e39cd867b8b06918a524eabb21d45ea98aad07357b98173458a
  • urlhttps://filev2.getsession.org/file/
  • domainseed1.getsession.org
  • domainseed2.getsession.org
  • domainseed3.getsession.org
  • domainapi.masscan.cloud
  • file~/.local/bin/gh-token-monitor.sh
  • file~/.config/systemd/user/gh-token-monitor.service
  • file~/Library/LaunchAgents/com.user.gh-token-monitor.plist
  • file~/.config/gh-token-monitor/
  • stringShai-Hulud: Here We Go Again
  • stringPUSH UR T3MPRR
  • stringFIRESCALE
  • commit_authorclaude@users.noreply.github.com

References

  1. Shai-Hulud: Here We Go Again - Worm by TeamPCP Hits NPM and PyPIresearch.jfrog.com
  2. TanStack npm Packages Compromised in Ongoing Mini Shai-Hulud Supply Chain Attack - Socketsocket.dev
  3. Mini Shai-Hulud Is Back: npm Worm Hits over 160 Packages, including Mistral and Tanstack - Aikidoaikido.dev
  4. Retained jsDelivr flat member manifest for @tolka/cli 1.0.2data.jsdelivr.com
  5. Retained jsDelivr flat member manifest for @tolka/cli 1.0.3data.jsdelivr.com
  6. Retained jsDelivr flat member manifest for @tolka/cli 1.0.4data.jsdelivr.com
  7. Retained jsDelivr flat member manifest for @tolka/cli 1.0.5data.jsdelivr.com
  8. Retained jsDelivr flat member manifest for @tolka/cli 1.0.6data.jsdelivr.com

Source record: oss/attacks/shai-hulud-tolka-npm/meta.yaml