ctipilot.ch

Mini Shai-Hulud

campaign · campaign:mini-shai-hulud single-source

TeamPCP npm supply-chain worm family (initial wave: SAP CAP packages); the framework was later open-sourced, spawning derivatives including Phantom Gyp.

Aliases: Phantom Gyp

Coverage timeline
25
first 2026-05-04 → last 2026-06-29
Peak priority
high
11 high · 14 notable
Sources cited
70
41 hosts
Sections touched
8
active-threats, deep-dive, trending-vulnerabilities
Co-occurring entities
7
see Related entities below
ATT&CK techniques
21
pinned v19.1 · see below
2026-05-0425 appearances2026-06-29

ATT&CK techniques

21 techniques observed across 9 entries — derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.1 · compare on the matrix · Navigator layer (JSON)

Reconnaissance TA0043

T1593Search Open Websites/Domains×1

Adversaries may search freely available websites and/or domains for information about victims that can be used during targeting. Information about victims may be available in various online sites, such as social media, new sites, or those hosting information about business operations such as hiring or requested/rewarded contracts.

Evidence: 2026-05-13/mini-shai-hulud-s-github-actions-pwn-request-oidc-token-thef · ATT&CK page ↗

Resource Development TA0042

T1583.001Acquire Infrastructure: Domains×1

Adversaries may acquire domains that can be used during targeting. Domain names are the human readable names used to represent one or more IP addresses. They can be purchased or, in some cases, acquired for free.

Evidence: 2026-05-13/mini-shai-hulud-s-github-actions-pwn-request-oidc-token-thef · ATT&CK page ↗

T1650Acquire Access×1

Adversaries may purchase or otherwise acquire an existing access to a target system or network. A variety of online services and initial access broker networks are available to sell access to previously compromised systems. In some cases, adversary groups may form partnerships to share compromised systems with each other.

Evidence: 2026-05-22/teampcp-mini-shai-hulud-unit-42-and-stepsecurity-confirm-sls · ATT&CK page ↗

Initial Access TA0001

T1078Valid Accounts×1

Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.

Evidence: 2026-05-21/verizon-2026-dbir-vulnerability-exploitation-overtakes-crede · ATT&CK page ↗

T1078.004Valid Accounts: Cloud Accounts×3

Valid accounts in cloud environments may allow adversaries to perform actions to achieve Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Cloud accounts are those created and configured by an organization for use by users, remote support, services, or for administration of resources within a cloud service provider or SaaS application. Cloud Accounts can exist solely in the cloud; alternatively, they may be hybrid-joined between on-premises systems and the cloud through syncing or federation with other identity sources such as Windows Active Directory.

Evidence: 2026-05-21/teampcp-mini-shai-hulud-campaign-github-itself-breached-3-80 · 2026-05-13/mini-shai-hulud-teampcp-worm-hits-tanstack-uipath-mistral-ai · 2026-05-13/mini-shai-hulud-s-github-actions-pwn-request-oidc-token-thef · ATT&CK page ↗

T1190Exploit Public-Facing Application×2

Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.

Evidence: 2026-05-21/verizon-2026-dbir-vulnerability-exploitation-overtakes-crede · 2026-05-13/cve-2026-34263-cve-2026-34260-sap-commerce-cloud-pre-auth-rc · ATT&CK page ↗

T1195Supply Chain Compromise×1

Adversaries may manipulate products or product delivery mechanisms prior to receipt by a final consumer for the purpose of data or system compromise.

Evidence: 2026-05-21/verizon-2026-dbir-vulnerability-exploitation-overtakes-crede · ATT&CK page ↗

T1195.002Supply Chain Compromise: Compromise Software Supply Chain×4

Adversaries may manipulate application software prior to receipt by a final consumer for the purpose of data or system compromise. Supply chain compromise of software can take place in a number of ways, including manipulation of the application source code, manipulation of the update/distribution mechanism for that software, or replacing compiled releases with a modified version.

Evidence: 2026-06-01/two-concurrent-npm-dependency-confusion-campaigns-target-int · 2026-05-20/actions-cool-issues-helper-github-action-compromised-53-tags · 2026-05-13/mini-shai-hulud-teampcp-worm-hits-tanstack-uipath-mistral-ai · 2026-05-13/mini-shai-hulud-s-github-actions-pwn-request-oidc-token-thef · ATT&CK page ↗

T1199Trusted Relationship×1

Adversaries may breach or otherwise leverage organizations who have access to intended victims. Access through trusted third party relationship abuses an existing connection that may not be protected or receives less scrutiny than standard mechanisms of gaining access to a network.

Evidence: 2026-05-13/mini-shai-hulud-s-github-actions-pwn-request-oidc-token-thef · ATT&CK page ↗

Persistence TA0003

T1078Valid Accounts×1

Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.

Evidence: 2026-05-21/verizon-2026-dbir-vulnerability-exploitation-overtakes-crede · ATT&CK page ↗

T1078.004Valid Accounts: Cloud Accounts×3

Valid accounts in cloud environments may allow adversaries to perform actions to achieve Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Cloud accounts are those created and configured by an organization for use by users, remote support, services, or for administration of resources within a cloud service provider or SaaS application. Cloud Accounts can exist solely in the cloud; alternatively, they may be hybrid-joined between on-premises systems and the cloud through syncing or federation with other identity sources such as Windows Active Directory.

Evidence: 2026-05-21/teampcp-mini-shai-hulud-campaign-github-itself-breached-3-80 · 2026-05-13/mini-shai-hulud-teampcp-worm-hits-tanstack-uipath-mistral-ai · 2026-05-13/mini-shai-hulud-s-github-actions-pwn-request-oidc-token-thef · ATT&CK page ↗

T1505.003Server Software Component: Web Shell×1

Adversaries may backdoor web servers with web shells to establish persistent access to systems. A Web shell is a Web script that is placed on an openly accessible Web server to allow an adversary to access the Web server as a gateway into a network. A Web shell may provide a set of functions to execute or a command-line interface on the system that hosts the Web server.

Evidence: 2026-05-13/mini-shai-hulud-s-github-actions-pwn-request-oidc-token-thef · ATT&CK page ↗

Privilege Escalation TA0004

T1078Valid Accounts×1

Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.

Evidence: 2026-05-21/verizon-2026-dbir-vulnerability-exploitation-overtakes-crede · ATT&CK page ↗

T1078.004Valid Accounts: Cloud Accounts×3

Valid accounts in cloud environments may allow adversaries to perform actions to achieve Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Cloud accounts are those created and configured by an organization for use by users, remote support, services, or for administration of resources within a cloud service provider or SaaS application. Cloud Accounts can exist solely in the cloud; alternatively, they may be hybrid-joined between on-premises systems and the cloud through syncing or federation with other identity sources such as Windows Active Directory.

Evidence: 2026-05-21/teampcp-mini-shai-hulud-campaign-github-itself-breached-3-80 · 2026-05-13/mini-shai-hulud-teampcp-worm-hits-tanstack-uipath-mistral-ai · 2026-05-13/mini-shai-hulud-s-github-actions-pwn-request-oidc-token-thef · ATT&CK page ↗

Stealth TA0005

T1078Valid Accounts×1

Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.

Evidence: 2026-05-21/verizon-2026-dbir-vulnerability-exploitation-overtakes-crede · ATT&CK page ↗

T1078.004Valid Accounts: Cloud Accounts×3

Valid accounts in cloud environments may allow adversaries to perform actions to achieve Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Cloud accounts are those created and configured by an organization for use by users, remote support, services, or for administration of resources within a cloud service provider or SaaS application. Cloud Accounts can exist solely in the cloud; alternatively, they may be hybrid-joined between on-premises systems and the cloud through syncing or federation with other identity sources such as Windows Active Directory.

Evidence: 2026-05-21/teampcp-mini-shai-hulud-campaign-github-itself-breached-3-80 · 2026-05-13/mini-shai-hulud-teampcp-worm-hits-tanstack-uipath-mistral-ai · 2026-05-13/mini-shai-hulud-s-github-actions-pwn-request-oidc-token-thef · ATT&CK page ↗

Defense Impairment TA0112

T1553.002Subvert Trust Controls: Code Signing×1

Adversaries may create, acquire, or steal code signing materials to sign their malware or tools. Code signing provides a level of authenticity on a binary from the developer and a guarantee that the binary has not been tampered with. The certificates used during an operation may be created, acquired, or stolen by the adversary. Unlike Invalid Code Signature, this activity will result in a valid signature.

Evidence: 2026-05-13/mini-shai-hulud-s-github-actions-pwn-request-oidc-token-thef · ATT&CK page ↗

Credential Access TA0006

T1003.007OS Credential Dumping: Proc Filesystem×1

Adversaries may gather credentials from the proc filesystem or `/proc`. The proc filesystem is a pseudo-filesystem used as an interface to kernel data structures for Linux based systems managing virtual memory. For each process, the `/proc/<PID>/maps` file shows how memory is mapped within the process’s virtual address space. And `/proc/<PID>/mem`, exposed for debugging purposes, provides access to the process’s virtual address space.

Evidence: 2026-05-13/mini-shai-hulud-s-github-actions-pwn-request-oidc-token-thef · ATT&CK page ↗

T1110Brute Force×1

Adversaries may use brute force techniques to gain access to accounts when passwords are unknown or when password hashes are obtained. Without knowledge of the password for an account or set of accounts, an adversary may systematically guess the password using a repetitive or iterative mechanism. Brute forcing passwords can take place via interaction with a service that will check the validity of those credentials or offline against previously acquired credential data, such as password hashes.

Evidence: 2026-05-21/verizon-2026-dbir-vulnerability-exploitation-overtakes-crede · ATT&CK page ↗

T1552.001Unsecured Credentials: Credentials In Files×3

Adversaries may search local file systems and remote file shares for files containing insecurely stored credentials. These can be files created by users to store their own credentials, shared credential stores for a group of individuals, configuration files containing passwords for a system or service, or source code/binary files containing embedded passwords.

Evidence: 2026-05-22/teampcp-mini-shai-hulud-unit-42-and-stepsecurity-confirm-sls · 2026-05-20/actions-cool-issues-helper-github-action-compromised-53-tags · 2026-05-13/mini-shai-hulud-teampcp-worm-hits-tanstack-uipath-mistral-ai · ATT&CK page ↗

T1606.002Forge Web Credentials: SAML Tokens×1

An adversary may forge SAML tokens with any permissions claims and lifetimes if they possess a valid SAML token-signing certificate. The default lifetime of a SAML token is one hour, but the validity period can be specified in the <code>NotOnOrAfter</code> value of the <code>conditions ...</code> element in a token. This value can be changed using the <code>AccessTokenLifetime</code> in a <code>LifetimeTokenPolicy</code>. Forged SAML tokens enable adversaries to authenticate across services that use SAML 2.0 as an SSO (single sign-on) mechanism.

Evidence: 2026-05-13/mini-shai-hulud-s-github-actions-pwn-request-oidc-token-thef · ATT&CK page ↗

Discovery TA0007

T1082System Information Discovery×1

An adversary may attempt to get detailed information about the operating system and hardware, including version, patches, hotfixes, service packs, and architecture. Adversaries may use this information to shape follow-on behaviors, including whether or not the adversary fully infects the target and/or attempts specific actions. This behavior is distinct from Local Storage Discovery which is an adversary's discovery of local drive, disks and/or volumes.

Evidence: 2026-06-01/two-concurrent-npm-dependency-confusion-campaigns-target-int · ATT&CK page ↗

T1083File and Directory Discovery×1

Adversaries may enumerate files and directories or may search in specific locations of a host or network share for certain information within a file system. Adversaries may use the information from File and Directory Discovery during automated discovery to shape follow-on behaviors, including whether or not the adversary fully infects the target and/or attempts specific actions.

Evidence: 2026-06-01/two-concurrent-npm-dependency-confusion-campaigns-target-int · ATT&CK page ↗

T1614System Location Discovery×1

Adversaries may gather information in an attempt to calculate the geographical location of a victim host. Adversaries may use the information from System Location Discovery during automated discovery to shape follow-on behaviors, including whether or not the adversary fully infects the target and/or attempts specific actions.

Evidence: 2026-06-01/two-concurrent-npm-dependency-confusion-campaigns-target-int · ATT&CK page ↗

Lateral Movement TA0008

T1570Lateral Tool Transfer×1

Adversaries may transfer tools or other files between systems in a compromised environment. Once brought into the victim environment (i.e., Ingress Tool Transfer) files may then be copied from one system to another to stage adversary tools or other files over the course of an operation.

Evidence: 2026-05-21/teampcp-mini-shai-hulud-campaign-github-itself-breached-3-80 · ATT&CK page ↗

Collection TA0009

T1213Data from Information Repositories×1

Adversaries may leverage information repositories to mine valuable information. Information repositories are tools that allow for storage of information, typically to facilitate collaboration or information sharing between users, and can store a wide variety of data that may aid adversaries in further objectives, such as Credential Access, Lateral Movement, or Defense Evasion, or direct access to the target information. Adversaries may also abuse external sharing features to share sensitive documents with recipients outside of the organization (i.e., Transfer Data to Cloud Account).

Evidence: 2026-05-13/cve-2026-34263-cve-2026-34260-sap-commerce-cloud-pre-auth-rc · ATT&CK page ↗

Impact TA0040

T1485Data Destruction×1

Adversaries may destroy data and files on specific systems or in large numbers on a network to interrupt availability to systems, services, and network resources. Data destruction is likely to render stored data irrecoverable by forensic techniques through overwriting files or data on local and remote drives. Common operating system file deletion commands such as <code>del</code> and <code>rm</code> often only remove pointers to files without wiping the contents of the files themselves, making the files recoverable by proper forensic methodology. This behavior is distinct from Disk Content Wipe and Disk Structure Wipe because individual files are destroyed rather than sections of a storage disk or the disk's logical structure.

Evidence: 2026-05-26/teampcp-mini-shai-hulud-framework-open-sourced-microsoft-pyp · ATT&CK page ↗

Story timeline

  1. 2026-06-29npm supply-chain worms — a sustained wave across the week
    weekly-multi-day
  2. 2026-06-27Miasma / "Mini Shai-Hulud" npm worm runs a new wave across LeoPlatform/RStreams packages
    updates
  3. 2026-06-14Shai-Hulud / Miasma supply-chain worm lineage — open-sourced, ported to PyPI, and a 1,500-package AUR wave
    weekly-multi-day
  4. 2026-06-09TeamPCP open-sources its Mini Shai-Hulud framework, spawning a new "Phantom Gyp" derivative
    active-threats
  5. 2026-06-06Miasma supply-chain worm reaches 73 Microsoft GitHub repositories, adds Azure credential collectors
    updates
  6. 2026-06-02"Miasma" worm backdoors 32 Red Hat Cloud Services npm packages via OIDC trusted-publishing abuse
    active-threats
  7. 2026-06-01Two concurrent npm dependency-confusion campaigns target internal corporate namespaces
    active-threats
  8. 2026-05-26TeamPCP / Mini Shai-Hulud — framework open-sourced, Microsoft PyPI SDK trojanised with a wiper stage, forged Sigstore badges
    updates
  9. 2026-05-25Mini Shai-Hulud / TrapDoor — the supply-chain worm goes cross-ecosystem, open-source and destructive
    weekly-multi-day
  10. 2026-05-25Mini Shai-Hulud / TeamPCP — @antv npm wave and confirmed Maven Central poisoning; Cargo still un-hit
    weekly-long-running
  11. 2026-05-22TeamPCP Mini Shai-Hulud — Unit 42 and StepSecurity confirm SLSA Build Level 3 attestation invalidated as integrity gate
    updates
  12. 2026-05-21Verizon 2026 DBIR: vulnerability exploitation overtakes credentials as primary breach vector for the first time in 19 years
    deep-dive
  13. 2026-05-21TeamPCP / Mini Shai-Hulud campaign — GitHub itself breached (~3,800 internal repos via poisoned VS Code extension), Microsoft durabletask PyPI worm propagates via AWS SSM and kubectl exec, Grafana confirms missed-token-rotation root cause
    updatesTeamPCP / Mini Shai-Hulud campaign — GitHub itself breached (~3,800 internal repos via poisoned VS Code extension), Microsoft durabletask PyPI worm propagates
  14. 2026-05-20actions-cool/issues-helper GitHub Action compromised — 53 tags moved to imposter commit reading Runner.Worker /proc/PID/mem; linked to Mini Shai-Hulud
    active-threats
  15. 2026-05-18TeamPCP / Mini Shai-Hulud / Megalodon — the open-sourced supply-chain worm became commodity infrastructure this week
    weekly-multi-day
  16. 2026-05-15TeamPCP / Mini Shai-Hulud — OpenAI named as victim; code-signing certificate rotation enforced for all macOS apps
    updates
  17. 2026-05-15CVE-2026-45793 — PHP Composer: GitHub Actions CI token disclosure in error messages
    active-threats
  18. 2026-05-13Mini Shai-Hulud — TeamPCP worm hits TanStack, UiPath, Mistral AI, OpenSearch (160+ package versions)
    updates
  19. 2026-05-13Mini Shai-Hulud's GitHub Actions Pwn-Request → OIDC Token Theft Chain
    deep-dive
  20. 2026-05-13CVE-2026-34263 / CVE-2026-34260 — SAP Commerce Cloud pre-auth RCE, S/4HANA Enterprise Search SQL injection
    trending-vulnerabilities
  21. 2026-05-11TeamPCP / Mini Shai-Hulud (ShinyHunters / WorldLeaks adjacent) — wave 4 + framework leak + IDE persistence
    weekly-long-running
  22. 2026-05-11TeamPCP / Mini Shai-Hulud npm supply-chain worm — wave 4 + framework source leak
    weekly-multi-day
  23. 2026-05-11Looking ahead — 2026-W20
    weekly-looking-ahead
  24. 2026-05-11AI tooling SaaS and developer toolchain
    weekly-sector-patterns
  25. 2026-05-04TeamPCP → PCPJack — cloud-worm successor evicting prior operator artefacts
    weekly-long-running

Relationships explore in graph

Typed, source-stated connections from the entity registry — each edge cites the entry whose reporting establishes it.

attributed to

related to

Where this entity is cited

  • updates7
  • weekly-multi-day5
  • active-threats5
  • weekly-long-running3
  • deep-dive2
  • weekly-sector-patterns1
  • weekly-looking-ahead1
  • trending-vulnerabilities1

Source distribution

  • thehackernews.com9 (13%)
  • nvd.nist.gov5 (7%)
  • wiz.io4 (6%)
  • bleepingcomputer.com3 (4%)
  • helpnetsecurity.com3 (4%)
  • socket.dev3 (4%)
  • isc.sans.edu2 (3%)
  • microsoft.com2 (3%)
  • other39 (56%)

Co-occurring entities

Derived — referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.

All cited sources (70)

Entries about Mini Shai-Hulud (25)

2026-06-29 · view entry permalink →

NOTABLE

npm supply-chain worms — a sustained wave across the week

Three separate npm-ecosystem supply-chain events were in play across the window, and the pattern is the story. Microsoft attributed the Mastra scope compromise (140+ @mastra packages, postinstall dropper) to North Korea's Sapphire Sleet (covered in the daily on 06-21). JFrog documented PostCSS typosquats from the abdrizak account delivering a Nuitka-compiled Python RAT with Chrome DPAPI credential theft. And on 2026-06-25 Socket reported a fresh Miasma / "Mini Shai-Hulud" worm wave across LeoPlatform/RStreams packages (carried in the daily 06-27), the self-propagating supply-chain worm last seen backdooring @redhat-cloud-services.

The synthesis: the npm registry is under continuous, parallel pressure from a state actor (DPRK), commodity typosquat crews and a self-replicating worm — three different operators, one ecosystem. The common control is the same one npm v12 is about to enforce by default: disable install scripts (--ignore-scripts), pin and review dependencies, and treat CI build-time package resolution as an attack surface. (daily 06-21, daily 06-24, daily 06-27)

synthesis29 Jun 00:20Zmulti-sourceOpen finding ↗

2026-06-27 · view entry permalink →

HIGHupdate

Miasma / "Mini Shai-Hulud" npm worm runs a new wave across LeoPlatform/RStreams packages

UPDATE · originally covered TeamPCP open-sources its Mini Shai-Hulud framework, spawning a new "Phantom Gyp" derivative (2026-06-09)

The Miasma / Mini Shai-Hulud / Hades supply-chain worm — last seen backdooring @redhat-cloud-services packages and the TeamPCP "Phantom Gyp" framework — ran a fresh wave on 2026-06-24: 23+ malicious versions across the LeoPlatform and RStreams serverless-data-pipeline npm ecosystems (leo-sdk, leo-auth, leo-aws, leo-cli) after the czirker publisher account was compromised, plus a Go-module compromise of Verana Blockchain (Socket Security, 2026-06-25).

The wave reuses the previously documented binding.gyp/node-gyp install-time execution to stage a Bun runtime that harvests .env files, npm/GitHub/cloud tokens, SSH keys and IDE/AI-agent configs, scraping GitHub Actions CI secrets (JFrog, 2026-06-26), and again carries the RevokeAndItGoesKaboom campaign marker that Socket ties to the earlier codfish/semantic-release-action compromise (documented by StepSecurity), where the malicious action searched GitHub commit messages bearing that string as an operator dead-drop channel (Socket Security, 2026-06-25). Any CH/EU team consuming these packages in CI should rotate all exposed CI/cloud credentials since 2026-06-20 and alert on node-gyp evaluating JavaScript from binding.gyp.

threat27 Jun 05:17Zmulti-sourceOpen finding ↗

2026-06-14 · view entry permalink →

NOTABLE

Shai-Hulud / Miasma supply-chain worm lineage — open-sourced, ported to PyPI, and a 1,500-package AUR wave

The supply-chain-worm family the W23 weekly consolidated under the Miasma/IronWorm banner spent this week proliferating across ecosystems and operators. On 9 June a SANS ISC handler tracked TeamPCP open-sourcing its Mini Shai-Hulud framework, immediately spawning a "Phantom Gyp" derivative (SANS ISC; daily 06-09). On 10 June the lineage opened a PyPI front dubbed "Hades" — 37 malicious wheels across 19 packages (The Hacker News; daily 06-10).

The week's largest wave hit the Arch User Repository. "Atomic Arch" began with roughly 400 orphaned AUR packages adopted and re-pointed to a Rust credential-stealer plus eBPF rootkit (The Hacker News; Sonatype; daily 06-13); a second wave around 12 June expanded the count further (tracker estimates range from the 400+ in primary reporting to ~1,500) and swapped some PKGBUILD delivery from npm dependency injection to bun install js-digest — active operator iteration against detection. The npm delivery mechanism has been linked by SANS ISC and subsequent reporting to the broader Shai-Hulud supply-chain family. Official Arch core/extra repositories were not affected; only adopted AUR packages. For defenders the through-line is constant: install-time script execution is the kill chain, and npm/bun/AUR build steps need to be treated as untrusted code execution in CI/CD.

synthesis14 Jun 23:57Zmulti-sourceOpen finding ↗

Earlier coverage (22)

2026-06-09HIGHTeamPCP open-sources its Mini Shai-Hulud framework, spawning a new "Phantom Gyp" derivativeTeamPCP open-sources its Mini Shai-Hulud supply-chain framework on GitHub, spawning a new "Phantom Gyp" derivative and underscoring that valid SLSA provenance does not survive a subverted build environment (SANS ISC, 2026-06-08).2026-06-06NOTABLEupdateMiasma supply-chain worm reaches 73 Microsoft GitHub repositories, adds Azure credential collectorsUPDATE (originally covered 2026-06-02): The Miasma worm — the TeamPCP-spawned descendant of the Mini Shai-Hulud lineage first covered against the Red Hat @redhat-cloud-services npm namespace — recompromised the durabletask package and propagated into the Microsoft GitHub estate.2026-06-02HIGH"Miasma" worm backdoors 32 Red Hat Cloud Services npm packages via OIDC trusted-publishing abuse"Miasma" supply-chain worm compromised 32 @redhat-cloud-services npm packages via a hijacked maintainer GitHub account and OIDC trusted-publishing abuse, adding new GCP and Azure cloud-identity collectors (Wiz, 2026-06-01).2026-06-01HIGHTwo concurrent npm dependency-confusion campaigns target internal corporate namespacesTwo concurrent npm dependency-confusion campaigns target internal corporate package namespaces — Microsoft (45 packages across nine organisational scopes) and Sonatype (176 packages) document recon/staging payloads that win npm's version race against private registries when .npmrc is not scope-locked (Microsoft, 2026-05-30 · Sonatype, 2026-05-28). Distinct from the Mini Shai-Hulud / TrapDoor activity covered last week.2026-05-26NOTABLEupdateTeamPCP / Mini Shai-Hulud — framework open-sourced, Microsoft PyPI SDK trojanised with a wiper stage, forged Sigstore badgesUPDATE (originally covered 2026-05-21, consolidated weekly update): SANS ISC handler Kenneth Hartman documents three material escalations in the TeamPCP / Mini Shai-Hulud supply-chain campaign through 2026-05-24 (SANS Internet Storm Center, 2026-05-25).2026-05-25NOTABLEMini Shai-Hulud / TeamPCP — @antv npm wave and confirmed Maven Central poisoning; Cargo still un-hitBeyond the in-window TrapDoor and framework-open-sourcing covered in § 2, horizon research surfaced a development the dailies missed.2026-05-25HIGHMini Shai-Hulud / TrapDoor — the supply-chain worm goes cross-ecosystem, open-source and destructiveSupply-chain worm widens — Mini Shai-Hulud goes cross-ecosystem, open-source and destructive. TrapDoor spans npm/PyPI/crates, the framework was open-sourced with a wiper stage, and Maven Central poisoning via mvnpm is now confirmed — one of last week's two un-hit registries. (daily, Wiz)2026-05-22NOTABLEupdateTeamPCP Mini Shai-Hulud — Unit 42 and StepSecurity confirm SLSA Build Level 3 attestation invalidated as integrity gateUPDATE (originally covered 2026-05-19, updated 2026-05-21): Unit 42 (Palo Alto Networks) and StepSecurity published concurrent technical analyses on 2026-05-21 of the TeamPCP Mini Shai-Hulud npm supply-chain campaign, establishing the defining novelty of this wave: the first documented case of malicious npm …2026-05-21HIGHVerizon 2026 DBIR: vulnerability exploitation overtakes credentials as primary breach vector for the first time in 19 yearsVerizon 2026 DBIR (today's deep dive): vulnerability exploitation overtakes credentials as the leading breach initial-access vector for the first time in the report's 19-year history — 31 % per Verizon's press release (Verizon, 2026-05-19) vs 13 % credentials per Help Net Security's reading of the full DBIR (Help Net Security, 2026-05-20); only 26 % of CISA KEV entries fully remediated (down from 38 %); supply-chain breaches +60 % YoY.2026-05-21HIGHupdateTeamPCP / Mini Shai-Hulud campaign — GitHub itself breached (~3,800 internal repos via poisoned VS Code extension), Microsoft durabletask PyPI worm propagates via AWS SSM and kubectl exec, Grafana confirms missed-token-rotation root causeTeamPCP breaches GitHub itself — ~3,800 internal repositories exfiltrated via a poisoned VS Code extension installed on a GitHub employee device; in parallel, the Mini Shai-Hulud worm compromised the official Microsoft durabletask PyPI package and propagates across AWS via Systems Manager SendCommand and across Kubernetes via kubectl exec (Help Net Security, 2026-05-20; Wiz, 2026-05-20).2026-05-20HIGHactions-cool/issues-helper GitHub Action compromised — 53 tags moved to imposter commit reading Runner.Worker /proc/PID/mem; linked to Mini Shai-HuludTwo more CI/CD supply-chain incidents — actions-cool/issues-helper GitHub Action (exfil infrastructure overlapping with the Mini Shai-Hulud cluster per Socket) and Nx Console VS Code extension (stolen publisher credentials, no cluster attribution). 53 issues-helper tags moved to imposter commit 1c9e803 reading /proc/<PID>/mem of Runner.Worker for secrets exfil (StepSecurity, 2026-05-18). Nx Console 18.95.0 (2.2 M installs) compromised via stolen publisher credentials for an 11-minute window 2026-05-18 12:36–12:47 UTC (The Hacker News, 2026-05-19).2026-05-18NOTABLEexploitedTeamPCP / Mini Shai-Hulud / Megalodon — the open-sourced supply-chain worm became commodity infrastructure this weekThis is the week's defining chain. After the worm framework was open-sourced on 2026-05-12, the window saw it move from a single operator's tool to commodity capability, escalating almost daily:2026-05-15NOTABLEupdateTeamPCP / Mini Shai-Hulud — OpenAI named as victim; code-signing certificate rotation enforced for all macOS appsUPDATE (originally covered 2026-05-13): OpenAI disclosed on approximately 2026-05-13 that two employee devices were compromised through the TanStack npm supply-chain attack (Mini Shai-Hulud / TeamPCP, first covered in this brief series on 2026-05-12 and 2026-05-13) and that the compromise affected OpenAI's macOS …2026-05-15NOTABLECVE-2026-45793 — PHP Composer: GitHub Actions CI token disclosure in error messagesCVE-2026-45793 is a token disclosure in PHP Composer (the PHP package manager) patched and disclosed by the Packagist team on 2026-05-13 (Packagist blog, 2026-05-13).2026-05-13NOTABLEMini Shai-Hulud's GitHub Actions Pwn-Request → OIDC Token Theft ChainBackground. Mini Shai-Hulud (the TeamPCP self-propagating npm worm) first surfaced in coverage on 2026-05-10 as a SAP CAP-package compromise.2026-05-13HIGHupdateMini Shai-Hulud — TeamPCP worm hits TanStack, UiPath, Mistral AI, OpenSearch (160+ package versions)Mini Shai-Hulud worm re-detonates. TeamPCP poisoned 160+ npm package versions including @tanstack/ (42 packages, ~12M weekly downloads), @uipath/ (60+), @mistralai/* and @opensearch-project/opensearch via a pull_request_target → pnpm-cache poisoning → /proc/<pid>/mem OIDC-token theft chain that produced valid SLSA Build Level 3 provenance on the trojanised tarballs. UiPath is widely used in EU public-sector RPA; SAP HotNews #3747787 acknowledges CAP-package impact (StepSecurity, 2026-05-11; TanStack post-mortem, 2026-05-12).2026-05-13HIGHCVE-2026-34263 / CVE-2026-34260 — SAP Commerce Cloud pre-auth RCE, S/4HANA Enterprise Search SQL injectionSAP Commerce Cloud pre-auth RCE plus S/4HANA Enterprise Search SQLi. CVE-2026-34263 (CVSS 9.6) is unauthenticated arbitrary code injection via overly permissive Spring Security ordering on the cloud-config endpoint; CVE-2026-34260 (CVSS 9.6) is post-auth SQL injection in the Enterprise Search ABAP component — enabled by default. SAP Commerce and S/4HANA are core to Swiss federal procurement (NOVE/SUPERB programmes) and EU institutional ERP (Onapsis, 2026-05-12; SecurityWeek, 2026-05-12).2026-05-11NOTABLELooking ahead — 2026-W20Microsoft Exchange CVE-2026-42897 — Microsoft permanent patch and out-of-band advisory on DEVCORE Pwn2Own three-bug chain pending.2026-05-11NOTABLETeamPCP / Mini Shai-Hulud (ShinyHunters / WorldLeaks adjacent) — wave 4 + framework leak + IDE persistenceFull coverage in § 2 (multi-day chain).2026-05-11NOTABLEAI tooling SaaS and developer toolchainThe Mini Shai-Hulud / TeamPCP propagation across @tanstack, @uipath, @mistralai, @opensearch-project, @guardrails-ai, and OpenAI consolidates a sector pattern first surfaced in W19: AI-evaluation, AI-observability, AI-agent-orchestration, and AI-tooling SaaS vendors all sit on architectures that …2026-05-11HIGHexploitedTeamPCP / Mini Shai-Hulud npm supply-chain worm — wave 4 + framework source leakTeamPCP Mini Shai-Hulud wave 4 compromised 170+ npm packages / 400+ malicious versions per daily-brief tracking (TanStack, UiPath, Mistral AI, OpenSearch, OpenAI named); Datadog static analysis of the leaked Shai-Hulud framework source (2026-05-12 leak) surfaces previously-undocumented IDE-persistence hooks targeting .claude/settings.json and .vscode/tasks.json, plus OIDC token extraction from /proc/<pid>/mem to forge Sigstore provenance attestations. Provenance-only verification no longer separates malicious from legitimate publications. (Datadog Security Labs · Wiz Blog · daily 2026-05-13 UPDATE · daily 2026-05-15 UPDATE)2026-05-04NOTABLEexploitedTeamPCP → PCPJack — cloud-worm successor evicting prior operator artefactsCurrent state: SentinelLabs documented PCPJack on 2026-05-07 as a worm-class framework that evicts and deletes existing TeamPCP artefacts on compromise (giving the framework its name), then deploys six Python modules harvesting credentials from Docker, Kubernetes, Redis, MongoDB, RayML, and dozens of cloud / SaaS …