Mini Shai-Hulud
11
3
29.04.2026
26.06.2026
Profil laut MITRE ATT&CK
Mini Shai-Hulud is a credential stealer and self-replicating supply chain worm, derived from Shai-Hulud, that has been used by TeamPCP to target Continuous Integration and Continuous Delivery/Deployment (CI/CD) workflows since at least 2026. Mini Shai-Hulud can compromise credentials across multiple cloud, container, and AI configuration file paths and can use stolen npm and GitHub OIDC tokens to spread to other packages maintained by the compromised user. Mini Shai-Hulud also has a targeted wiper component and has used multiple C2 and data exfiltration mechanisms.
Vollständiges MITRE-ProfilBeschreibung und Alias-Namen stammen aus MITRE ATT&CK®.
Nennungen im Zeitverlauf
Meldungen je Monat, letzte 12 Monate.
Beobachtete Techniken
ATT&CK-Techniken, die in denselben Meldungen benannt sind — nicht das vollständige MITRE-Repertoire.
Gemeinsam genannt
Betroffene Branchen
Meldungen
Miasma Malware Targets npm Packages and GitHub Actions in Supply Chain Attack
Hades PyPI Attack: 19 Packages Poisoned to Auto-Run Bun Credential Stealer
Miasma Supply Chain Attack Compromises Red Hat npm Packages with Credential-Stealing Worm
Over 320 NPM Packages Hit by Fresh Mini Shai-Hulud Supply Chain Attack
Mini Shai-Hulud Pushes Malicious AntV npm Packages via Compromised Maintainer Account
TanStack Supply Chain Attack Hits Two OpenAI Employee Devices, Forces macOS Updates
Mini Shai-Hulud Worm Compromises TanStack, Mistral AI, Guardrails AI & More Packages
Worm Redux: Fresh Mini Shai-Hulud Infections Bite Supply Chain
1,800 Hit in Mini Shai-Hulud Attack on SAP, Lightning, Intercom
TeamPCP Hits SAP Packages With 'Mini Shai-Hulud' Attack
SAP-Related npm Packages Compromised in Credential-Stealing Supply Chain Attack
Quellen: The Hacker News (7), SecurityWeek (2), Dark Reading (2)
Alle Angaben auf dieser Seite stammen aus dem Alias-Abgleich der Meldungstexte gegen den MITRE-ATT&CK-Katalog. Beziehungen entstehen rein statistisch: Zwei Einträge gelten als verbunden, wenn sie in derselben Meldung benannt sind. Das ist keine eigenständige Attribution durch SecBoard, und eine Nennung ist kein Nachweis einer Täterschaft.