Open Source · · 1 day

ts-dna npm package carried Shai-Hulud

JFrog listed 1 ts-dna npm package in the May 2026 Shai-Hulud wave. This record scopes those artifacts to their own official distribution surface.

Part of Shai-Hulud hits npm and PyPI campaign

ts-dna was a single-package entry in the May 2026 Shai-Hulud wave. JFrog listed five affected npm releases under the ts-dna name, all tied to the campaign's May 11-12 publishing window.

The package's importance is not measured by its size. Shai-Hulud used registry trust and install-time execution to reach developer machines and CI runners, then searched those environments for npm tokens, GitHub credentials, cloud material, and other secrets that could help it propagate.

This record separates ts-dna from the campaign aggregate so responders have a precise dependency indicator. The campaign page explains the common loader, infrastructure, and TeamPCP behavior; this page keeps the package name, versions, dates, and registry URLs attached to one distribution surface.

Any matching install should be treated as credential exposure until proven otherwise. The relevant evidence may live in lockfiles, npm caches, build logs, private mirrors, or CI images rather than in deployed production code.

Notes

  • The network and payload indicators are the campaign-level set JFrog published for this wave, not observations of this package's own bytes. They identify the wave's infrastructure and persistence, and are recorded here so each affected distribution surface carries them. Where a record also lists indicators read from an acquired sample, those are marked as such.
  • Minimal campaign-linked record created to keep Shai-Hulud package evidence scoped by vendor, organization, maintainer account, or package distribution surface.

Appendix · Affected releases

ts-dna npm
3.0.5 sha256 18b40969…c49898c8 download unavailable
3.0.4 sha256 e97bb9be…4ac29fe9 download unavailable
3.0.3 sha256 0c480c4c…c4dd233d download unavailable
3.0.2 sha256 8aec02d6…d1d6e920 download unavailable
3.0.1 sha256 d0a44c98…4f37c8ab download unavailable

Indicators

  • file_sha256npm payload 29c729852fce5a53e30a1541d9fec79c915b2e13f1eda94a5978cf0aae0d88d9
  • file_sha256npm payload 2ec78d556d696e208927cc503d48e4b5eb56b31abc2870c2ed2e98d6be27fc96
  • file_sha256npm payload ab4fcadaec49c03278063dd269ea5eef82d24f2124a8e15d7b90f2fa8601266c
  • file_sha256npm payload d4a2086ea18f5e39cd867b8b06918a524eabb21d45ea98aad07357b98173458a
  • urlhttps://filev2.getsession.org/file/
  • domainseed1.getsession.org
  • domainseed2.getsession.org
  • domainseed3.getsession.org
  • domainapi.masscan.cloud
  • file~/.local/bin/gh-token-monitor.sh
  • file~/.config/systemd/user/gh-token-monitor.service
  • file~/Library/LaunchAgents/com.user.gh-token-monitor.plist
  • file~/.config/gh-token-monitor/
  • stringShai-Hulud: Here We Go Again
  • stringPUSH UR T3MPRR
  • stringFIRESCALE
  • commit_authorclaude@users.noreply.github.com

References

  1. Shai-Hulud: Here We Go Again - Worm by TeamPCP Hits NPM and PyPIresearch.jfrog.com
  2. TanStack npm Packages Compromised in Ongoing Mini Shai-Hulud Supply Chain Attack - Socketsocket.dev
  3. Mini Shai-Hulud Is Back: npm Worm Hits over 160 Packages, including Mistral and Tanstack - Aikidoaikido.dev
  4. Socket retained file tree for ts-dna 3.0.1socket.dev
  5. Retained jsDelivr flat member manifest for ts-dna 3.0.2data.jsdelivr.com
  6. Retained jsDelivr flat member manifest for ts-dna 3.0.3data.jsdelivr.com
  7. Retained jsDelivr flat member manifest for ts-dna 3.0.4data.jsdelivr.com
  8. Socket retained file tree for ts-dna 3.0.5socket.dev

Source record: oss/attacks/shai-hulud-ts-dna-npm/meta.yaml