Mini Shai-Hulud: Compromised @antv npm Packages Steal Developer and CI/CD Credentials (TeamPCP)
Mini Shai-Hulud (TL-2026-2806), also tracked as Mini Shai-Hulud, is a high-severity supply-chain compromise, first published 2026-09-30. It is attributed to TeamPCP with medium confidence, affects AntV / npm ecosystem @antv/* npm packages (g2, g6, x6, l7, s2, f2, g, maps to 14 MITRE ATT&CK techniques (T1003.007, T1027, T1059.004), and is covered by 9 detection rules and 23 indicators of compromise.
Key facts for TL-2026-2806
- Threat ID
- TL-2026-2806
- Also known as
- Mini Shai-Hulud, Shai-Hulud wave 5, AntV npm compromise
- Severity
- HIGH
- Status
- ACTIVE
- Category
- SUPPLY_CHAIN
- First published
- 2026-09-30
- Last reviewed
- 2026-09-30
- Attribution
- TeamPCP
- Attribution confidence
- MEDIUM
- Motivation
- FINANCIAL
- Target sectors
- technology, software-development, cloud, finance
- Target regions
- Global
- Detection rules
- 9
- Indicators of compromise
- 23
Malware and tooling in Mini Shai-Hulud
Malware and tooling: Backdoor:Python/ShaiWorm, Shai-Hulud, Bun
On 2026-05-19 a compromised maintainer account ('atool') published 637-639 malicious versions across ~323 npm packages in the @antv ecosystem, including echarts-for-react, size-sensor and timeago.js. A preinstall hook runs an obfuscated Bun payload that harvests cloud, GitHub, npm, Vault, Kubernetes and 1Password credentials from workstations and GitHub Actions runners, then self-propagates. Qualys and GBHackers (2026-09-28/30) frame it as attackers moving beyond source-code theft to developer credentials for cloud account takeover.
How Mini Shai-Hulud works
Mini Shai-Hulud is a fifth-wave continuation of the Shai-Hulud npm worm lineage (Sep 2025 original, Nov 2025 'SHA1-Hulud', Apr 2026 SAP CAP-JS wave with Claude Code hook injection, 2026-05-11 TanStack wave with valid SLSA provenance via OIDC hijack). On 2026-05-19 UTC, in two waves (about 01:39-01:56 with ~317 versions and 02:05-02:06 with ~314 versions), the npm account 'atool', which maintains the @antv scope and roughly 547 packages, was used to publish malicious versions. Snyk counts 637 versions across 323 packages and about 16 million weekly downloads; Microsoft and SecurityWeek count 639 versions. Downstream packages such as echarts-for-react (over 1M weekly downloads), size-sensor and timeago.js were affected. The method of maintainer-account compromise was still under investigation.
Execution chain: the package's preinstall hook runs node, then a shell, then Bun (installed if absent), then a ~499 KB obfuscated index.js that replaces the legitimate file. Obfuscation has two layers: 1,732 Base64 strings in a rotated array (shuffle key 0xa31de), and PBKDF2/SHA-256-encrypted critical strings (C2 domain, env var names) decrypted at runtime. The payload gates on GitHub Actions on Linux and skips main, master, dependabot/, renovate/ and gh-pages branches. It reads secrets from the Runner.Worker process memory (/proc/<pid>/mem), which bypasses GitHub secret masking. It also probes AWS IMDS (169.254.169.254) and ECS (169.254.170.2) metadata, and scans 80+ environment variables and 100-130+ file paths (~/.aws/credentials, ~/.kube/config, .npmrc, .netrc, Vault token paths, SSH keys, database strings, SaaS tokens). Targeted credential stores include GitHub, AWS, GCP, Azure, HashiCorp Vault, Kubernetes, npm (including OIDC-to-npm token exchange) and 1Password.
Exfiltration: data is JSON-serialized, gzip-compressed and AES-256-GCM encrypted with the key wrapped by an attacker RSA-OAEP public key. It goes to t.m-kosche[.]com:443 at /api/public/otel/v1/traces, disguised as OpenTelemetry traces. The fallback is public GitHub 'dead-drop' repositories created under victim accounts (2,200+ observed) with the reversed description 'niagA oG eW ereH :duluH-iahS' and Dune-themed names, plus commits through the Git Data API. Persistence and escalation: an injected passwordless sudoers rule, a .claude/settings.json SessionStart hook, a .vscode/tasks.json folderOpen task, a Python C2 daemon (~/.local/share/kitty/cat.py) run through a systemd user unit or macOS LaunchAgent, and a GitHub token monitor. The payload also forges Sigstore (Fulcio/Rekor) SLSA provenance and injects a malicious GitHub workflow. Attribution to TeamPCP (DeadCatx3, PCPcat) comes from Snyk and SecurityWeek citing researchers. Microsoft did not name an actor.
MITRE ATT&CK techniques used in TL-2026-2806
Credential Access
T1003.007 Proc Filesystem; T1528 Steal Application Access Token; T1552.001 Credentials In Files; T1552.005 Cloud Instance Metadata API
Defense Evasion
T1027 Obfuscated Files or Information
Execution
T1059.004 Unix Shell; T1059.007 JavaScript
Command and Control
Initial Access
T1078.004 Cloud Accounts; T1195.001 Compromise Software Dependencies and Development Tools
Persistence
T1543.001 Launch Agent; T1543.002 Systemd Service
Privilege Escalation
T1548.003 Sudo and Sudo Caching
Exfiltration
Affected products and versions in Mini Shai-Hulud
- AntV / npm ecosystem — @antv/* npm packages (g2, g6, x6, l7, s2, f2, g, g2plot, graphin, data-set, scale)
Vulnerable versions: Versions published 2026-05-19 UTC (637-639 versions across ~323 packages)
Fixed in: Removed by GitHub; use pre-2026-05-19 releases - npm ecosystem — echarts-for-react, size-sensor, timeago.js, canvas-nest.js
Vulnerable versions: Malicious versions published 2026-05-19
Fixed in: Pre-compromise releases
Remediation for Mini Shai-Hulud
Patches
- Pin to known-good versions published before 2026-05-19; GitHub removed ~640 malicious packages and invalidated 61,274 npm tokens
Immediate actions
- Search lockfiles and package.json for @antv/*, echarts-for-react, size-sensor, timeago.js, canvas-nest.js and other packages published 2026-05-19
- Rotate all exposed GitHub tokens/PATs, AWS keys, npm publish tokens, Vault tokens, kubeconfig credentials and CI/CD secrets
- Audit GitHub accounts for repos with description 'niagA oG eW ereH :duluH-iahS' and the branch chore/add-codeql-static-analysis
- Block and alert on t.m-kosche.com; review CI/CD egress logs
- Remove persistence: .claude/settings.json SessionStart hook, .vscode/tasks.json folderOpen task, kitty-monitor systemd/LaunchAgent units, gh-token-monitor.sh
Workarounds
- Set ignore-scripts=true in .npmrc / npm install --ignore-scripts with explicit allowlisting
- Enforce lockfile integrity (npm ci)
Longer-term hardening
- Replace long-lived cloud keys with short-lived OIDC-federated workload credentials
- Enforce IMDSv2 and egress filtering for 169.254.169.254
- Use a private registry/proxy with cooldown and behavioral scanning
- Least-privilege CI/CD secrets and immutable audit logging
Weaknesses (CWE) in Mini Shai-Hulud
CWE-506, CWE-522
Timeline of Mini Shai-Hulud
- First Shai-Hulud self-propagating npm worm wave (~4 packages, e.g. @ctrl/tinycolor)
- SHA1-Hulud second wave: 600+ packages (Zapier, PostHog, Postman) with backdoor and destructive capabilities
- Mini Shai-Hulud SAP CAP-JS/MBT wave (4 packages) introduces Claude Code hook injection
- TanStack wave: 84 versions across 42 packages published with valid SLSA provenance via OIDC hijack
- Public detection around 02:18 UTC; researchers file reports; malicious packages spread to downstream echarts-for-react, size-sensor, timeago.js
- Compromised 'atool' maintainer account publishes ~317 malicious @antv versions between 01:39 and 01:56 UTC; a second wave of ~314 follows at 02:05-02:06 UTC
- Microsoft, Snyk and SecurityWeek publish analyses; GitHub removes ~640 malicious packages and invalidates 61,274 npm tokens
- Qualys publishes 'Developer New Perimeter' analysis tying Shai-Hulud to developer-credential-driven cloud breaches
- GBHackers reports attackers targeting developer credentials to expand supply chain intrusions beyond source code
Sources cited for Mini Shai-Hulud
- Attackers Target Developer Credentials to Expand Supply Chain Intrusions Beyond Source Code
- Qualys: Developer New Perimeter Supply Chain Cloud Breaches
- Mini Shai Hulud: Compromised @antv npm packages enable CI/CD credential theft (Microsoft Security Blog)
- Mini Shai-Hulud Hits AntV: 300+ Malicious npm Packages Published via Compromised Maintainer Account (Snyk)
- Over 320 NPM Packages Hit by Fresh Mini Shai-Hulud Supply Chain Attack (SecurityWeek)
- Mini Shai-Hulud Hits @antv npm Packages, Targets CI/CD Secrets (GBHackers)
- Shai-Hulud 2.0: Guidance for detecting, investigating, and defending against the supply chain attack (Microsoft)
- Mini Shai-Hulud Compromises @antv npm Packages to Steal CI/CD Credentials (Cybersecuritynews)
More in supply chain
- Bitget $387.5M Cryptocurrency Theft via Third-Party Security Product Zero-Day (Suspected DPRK / TraderTraitor)
- MALFEX: Malicious npm postinstall supply-chain campaign delivering Overlord RAT and movinlike stealer
- PhantomSub: 101 Malicious npm Baileys Forks Force Developers' WhatsApp Accounts into Attacker-Controlled Groups/Channels
- Re-Enabled actions-cool GitHub Actions (issues-helper, maintain-one-comment) Resume Executing Mini Shai-Hulud CI/CD Credential-Theft Payload
- Google Cloud Threat Intelligence: Supply Chain Compromise Campaigns and Mitigation Guidance (2025-2026)
Detection coverage for TL-2026-2806
As of 2026-09-30, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2806 across Splunk SPL, Microsoft KQL and Sigma, covering 23 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.
Community OSINT corroboration for TL-2026-2806
2 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.