Campaign · Open Source · · 8 days
Shai-Hulud hits npm and PyPI
Shai-Hulud: Here We Go Again was a May 2026 TeamPCP campaign affecting roughly 169 to 170+ npm package names, plus 2 PyPI packages, with combined reported download volume above 200 million per week.
Draws together 29 incidents across 459 packages
A self-spreading npm worm researchers dubbed "Mini Shai-Hulud" tore through more than 170 JavaScript packages and at least two Python packages over eight days in May 2026, in what JFrog, Aikido, Socket, and StepSecurity described as a second major outing for a TeamPCP-linked operation that first surfaced under the Shai-Hulud name in late 2025.
Researchers said the campaign was aimed at package publishers themselves rather than at any single project. JFrog reported more than 170 npm packages and two PyPI packages, while Aikido counted 373 malicious package-version entries across 169 npm names as the list was refined over several days. The npm payload imported @tanstack/setup as a GitHub-sourced dependency, rewrote package metadata, bumped versions, and republished infected tarballs using stolen npm tokens. Inside GitHub Actions runners, researchers said it could also abuse OIDC trusted publishing to mint a fresh npm publish token under a legitimate workflow identity, a step earlier worms had not reached.
The malware daemonized after install so the package manager could return a successful exit while harvesting continued in the background. Its value was in recursion: any package install in a privileged developer or CI environment could leak tokens, enumerate more publishable packages, and seed the next wave.
High-value scopes, including TanStack, Mistral, UiPath, OpenSearch prereleases, and Guardrails, are recorded separately where the package evidence is precise. This campaign record holds the moving aggregate and the common mechanics.
Notes
- Aikido reported 373 malicious package-version entries across 169 npm package names on May 12, 2026; JFrog separately reported 170+ npm packages plus 2 PyPI packages. The count shifted as researchers removed false positives and added newly discovered package versions.
- Legacy artifact note: 170+ npm unique packages in JFrog Appendix A, excluding separately tracked @tanstack/* packages
- Legacy artifact note: @uipath/* packages
- Legacy artifact note: @squawk/* packages
- Legacy artifact note: @tallyui/* packages
- Legacy artifact note: @beproduct/nestjs-auth
- Legacy artifact note: @draftlab/* and @draftauth/* packages
- Legacy artifact note: @taskflow-corp/cli and @tolka/cli
- Legacy artifact note: @ml-toolkit-ts/*, @mesadev/*, @dirigible-ai/sdk, and @supersurkhet/* packages
- Legacy artifact note: @mistralai/mistralai@2.2.2, 2.2.3, 2.2.4
- Legacy artifact note: @mistralai/mistralai-azure@1.7.1, 1.7.2, 1.7.3
- Legacy artifact note: @mistralai/mistralai-gcp@1.7.1, 1.7.2, 1.7.3
- Legacy artifact note: @opensearch-project/opensearch prereleases tracked separately
- Legacy artifact note: guardrails-ai@0.10.1
Incidents in this campaign
- BeProduct npm package carried Shai-Hulud
- Dirigible AI npm package carried Shai-Hulud
- DraftAuth npm packages carried Shai-Hulud
- DraftLab npm packages carried Shai-Hulud
- ML Toolkit TS npm packages carried Shai-Hulud
- MesaDev npm packages carried Shai-Hulud
- Squawk npm packages carried Shai-Hulud
- SuperSurkhet npm packages carried Shai-Hulud
- Tally UI npm packages carried Shai-Hulud
- Taskflow Corp npm package carried Shai-Hulud
- Tolka npm package carried Shai-Hulud
- UiPath npm packages carried Shai-Hulud
- agentwork-cli npm package carried Shai-Hulud
- cmux-agent-mcp npm package carried Shai-Hulud
- cross-stitch npm package carried Shai-Hulud
- git-branch-selector npm package carried Shai-Hulud
- git-git-git npm package carried Shai-Hulud
- guardrails-ai PyPI package carried Shai-Hulud
- nextmove-mcp npm package carried Shai-Hulud
- OpenSearch prereleases carried Shai-Hulud
- safe-action npm package carried Shai-Hulud
- TanStack packages hit by Mini Shai-Hulud
- ts-dna npm package carried Shai-Hulud
- wot-api npm package carried Shai-Hulud
- Mistral SDK packages imported Shai-Hulud loader
- actions-cool GitHub Actions tags rewritten by TeamPCP
- Nx Console VS Code extension shipped credential stealer
- AntV ecosystem npm packages hit by TeamPCP
- Microsoft durabletask PyPI hit by Mini Shai-Hulud
Appendix · Affected packages
447 more packages
Samples and hashes sit on each incident page, linked above
References
Source record: oss/campaigns/shai-hulud-here-we-go-again/meta.yaml