1
Groups Using This
6
Platforms
578
Prevalence Rank
0
Known Aliases
Description

Mini Shai-Hulud is a credential stealer and self-replicating supply chain worm, derived from Shai-Hulud, that has been used by TeamPCP to target Continuous Integration and Continuous Delivery/Deployment (CI/CD) workflows since at least 2026. Mini Shai-Hulud can compromise credentials across multiple cloud, container, and AI configuration file paths and can use stolen npm and GitHub OIDC tokens to spread to other packages maintained by the compromised user. Mini Shai-Hulud also has a targeted wiper component and has used multiple C2 and data exfiltration mechanisms.

View MITRE record ↗

Platforms
ContainersIaaSLinuxmacOSSaaSWindows
Groups Deploying Mini Shai-Hulud (1)
↑