Mini Shai-Hulud: Compromised @antv npm Packages Steal Developer and CI/CD Credentials (TeamPCP)

Mini Shai-Hulud (TL-2026-2806), also tracked as Mini Shai-Hulud, is a high-severity supply-chain compromise, first published 2026-09-30. It is attributed to TeamPCP with medium confidence, affects AntV / npm ecosystem @antv/* npm packages (g2, g6, x6, l7, s2, f2, g, maps to 14 MITRE ATT&CK techniques (T1003.007, T1027, T1059.004), and is covered by 9 detection rules and 23 indicators of compromise.

Key facts for TL-2026-2806

Threat ID
TL-2026-2806
Also known as
Mini Shai-Hulud, Shai-Hulud wave 5, AntV npm compromise
Severity
HIGH
Status
ACTIVE
Category
SUPPLY_CHAIN
First published
2026-09-30
Last reviewed
2026-09-30
Attribution
TeamPCP
Attribution confidence
MEDIUM
Motivation
FINANCIAL
Target sectors
technology, software-development, cloud, finance
Target regions
Global
Detection rules
9
Indicators of compromise
23

Malware and tooling in Mini Shai-Hulud

Malware and tooling: Backdoor:Python/ShaiWorm, Shai-Hulud, Bun

On 2026-05-19 a compromised maintainer account ('atool') published 637-639 malicious versions across ~323 npm packages in the @antv ecosystem, including echarts-for-react, size-sensor and timeago.js. A preinstall hook runs an obfuscated Bun payload that harvests cloud, GitHub, npm, Vault, Kubernetes and 1Password credentials from workstations and GitHub Actions runners, then self-propagates. Qualys and GBHackers (2026-09-28/30) frame it as attackers moving beyond source-code theft to developer credentials for cloud account takeover.

How Mini Shai-Hulud works

Mini Shai-Hulud is a fifth-wave continuation of the Shai-Hulud npm worm lineage (Sep 2025 original, Nov 2025 'SHA1-Hulud', Apr 2026 SAP CAP-JS wave with Claude Code hook injection, 2026-05-11 TanStack wave with valid SLSA provenance via OIDC hijack). On 2026-05-19 UTC, in two waves (about 01:39-01:56 with ~317 versions and 02:05-02:06 with ~314 versions), the npm account 'atool', which maintains the @antv scope and roughly 547 packages, was used to publish malicious versions. Snyk counts 637 versions across 323 packages and about 16 million weekly downloads; Microsoft and SecurityWeek count 639 versions. Downstream packages such as echarts-for-react (over 1M weekly downloads), size-sensor and timeago.js were affected. The method of maintainer-account compromise was still under investigation.

Execution chain: the package's preinstall hook runs node, then a shell, then Bun (installed if absent), then a ~499 KB obfuscated index.js that replaces the legitimate file. Obfuscation has two layers: 1,732 Base64 strings in a rotated array (shuffle key 0xa31de), and PBKDF2/SHA-256-encrypted critical strings (C2 domain, env var names) decrypted at runtime. The payload gates on GitHub Actions on Linux and skips main, master, dependabot/, renovate/ and gh-pages branches. It reads secrets from the Runner.Worker process memory (/proc/<pid>/mem), which bypasses GitHub secret masking. It also probes AWS IMDS (169.254.169.254) and ECS (169.254.170.2) metadata, and scans 80+ environment variables and 100-130+ file paths (~/.aws/credentials, ~/.kube/config, .npmrc, .netrc, Vault token paths, SSH keys, database strings, SaaS tokens). Targeted credential stores include GitHub, AWS, GCP, Azure, HashiCorp Vault, Kubernetes, npm (including OIDC-to-npm token exchange) and 1Password.

Exfiltration: data is JSON-serialized, gzip-compressed and AES-256-GCM encrypted with the key wrapped by an attacker RSA-OAEP public key. It goes to t.m-kosche[.]com:443 at /api/public/otel/v1/traces, disguised as OpenTelemetry traces. The fallback is public GitHub 'dead-drop' repositories created under victim accounts (2,200+ observed) with the reversed description 'niagA oG eW ereH :duluH-iahS' and Dune-themed names, plus commits through the Git Data API. Persistence and escalation: an injected passwordless sudoers rule, a .claude/settings.json SessionStart hook, a .vscode/tasks.json folderOpen task, a Python C2 daemon (~/.local/share/kitty/cat.py) run through a systemd user unit or macOS LaunchAgent, and a GitHub token monitor. The payload also forges Sigstore (Fulcio/Rekor) SLSA provenance and injects a malicious GitHub workflow. Attribution to TeamPCP (DeadCatx3, PCPcat) comes from Snyk and SecurityWeek citing researchers. Microsoft did not name an actor.

MITRE ATT&CK techniques used in TL-2026-2806

Credential Access

T1003.007 Proc Filesystem; T1528 Steal Application Access Token; T1552.001 Credentials In Files; T1552.005 Cloud Instance Metadata API

Defense Evasion

T1027 Obfuscated Files or Information

Execution

T1059.004 Unix Shell; T1059.007 JavaScript

Command and Control

T1071.001 Web Protocols

Initial Access

T1078.004 Cloud Accounts; T1195.001 Compromise Software Dependencies and Development Tools

Persistence

T1543.001 Launch Agent; T1543.002 Systemd Service

Privilege Escalation

T1548.003 Sudo and Sudo Caching

Exfiltration

T1567.001 Exfiltration to Code Repository

Affected products and versions in Mini Shai-Hulud

  • AntV / npm ecosystem — @antv/* npm packages (g2, g6, x6, l7, s2, f2, g, g2plot, graphin, data-set, scale)
    Vulnerable versions: Versions published 2026-05-19 UTC (637-639 versions across ~323 packages)
    Fixed in: Removed by GitHub; use pre-2026-05-19 releases
  • npm ecosystem — echarts-for-react, size-sensor, timeago.js, canvas-nest.js
    Vulnerable versions: Malicious versions published 2026-05-19
    Fixed in: Pre-compromise releases

Remediation for Mini Shai-Hulud

Patches

  • Pin to known-good versions published before 2026-05-19; GitHub removed ~640 malicious packages and invalidated 61,274 npm tokens

Immediate actions

  • Search lockfiles and package.json for @antv/*, echarts-for-react, size-sensor, timeago.js, canvas-nest.js and other packages published 2026-05-19
  • Rotate all exposed GitHub tokens/PATs, AWS keys, npm publish tokens, Vault tokens, kubeconfig credentials and CI/CD secrets
  • Audit GitHub accounts for repos with description 'niagA oG eW ereH :duluH-iahS' and the branch chore/add-codeql-static-analysis
  • Block and alert on t.m-kosche.com; review CI/CD egress logs
  • Remove persistence: .claude/settings.json SessionStart hook, .vscode/tasks.json folderOpen task, kitty-monitor systemd/LaunchAgent units, gh-token-monitor.sh

Workarounds

  • Set ignore-scripts=true in .npmrc / npm install --ignore-scripts with explicit allowlisting
  • Enforce lockfile integrity (npm ci)

Longer-term hardening

  • Replace long-lived cloud keys with short-lived OIDC-federated workload credentials
  • Enforce IMDSv2 and egress filtering for 169.254.169.254
  • Use a private registry/proxy with cooldown and behavioral scanning
  • Least-privilege CI/CD secrets and immutable audit logging

Weaknesses (CWE) in Mini Shai-Hulud

CWE-506, CWE-522

Timeline of Mini Shai-Hulud

  • First Shai-Hulud self-propagating npm worm wave (~4 packages, e.g. @ctrl/tinycolor)
  • SHA1-Hulud second wave: 600+ packages (Zapier, PostHog, Postman) with backdoor and destructive capabilities
  • Mini Shai-Hulud SAP CAP-JS/MBT wave (4 packages) introduces Claude Code hook injection
  • TanStack wave: 84 versions across 42 packages published with valid SLSA provenance via OIDC hijack
  • Public detection around 02:18 UTC; researchers file reports; malicious packages spread to downstream echarts-for-react, size-sensor, timeago.js
  • Compromised 'atool' maintainer account publishes ~317 malicious @antv versions between 01:39 and 01:56 UTC; a second wave of ~314 follows at 02:05-02:06 UTC
  • Microsoft, Snyk and SecurityWeek publish analyses; GitHub removes ~640 malicious packages and invalidates 61,274 npm tokens
  • Qualys publishes 'Developer New Perimeter' analysis tying Shai-Hulud to developer-credential-driven cloud breaches
  • GBHackers reports attackers targeting developer credentials to expand supply chain intrusions beyond source code

Sources cited for Mini Shai-Hulud

More in supply chain

Detection coverage for TL-2026-2806

As of 2026-09-30, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2806 across Splunk SPL, Microsoft KQL and Sigma, covering 23 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Community OSINT corroboration for TL-2026-2806

2 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.

Further reading

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat weather, live.

Every square is one real report, mapped to MITRE ATT&CK and shipped with Splunk SPL, Microsoft KQL and Sigma detections you can copy.

Every threat in the corpus, newest first.

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats