TeamPCP Mini Shai-Hulud npm supply-chain campaign
Campaign
Summary
Hide ▲
Show ▼
The TeamPCP-linked Mini Shai-Hulud campaign is an active npm supply-chain operation that steals developer credentials and abuses trusted publishing paths to spread trojanized packages. A new Miasma wave compromised more than 30 npm packages in Red Hat's @redhat-cloud-services namespace and used preinstall hooks to steal GitHub Actions secrets, cloud credentials, SSH keys, npm tokens, and other sensitive files. Red Hat said it removed the affected packages and has not identified impact to customer, partner, or production environments, while the wider campaign has already compromised 309 GitHub repositories.
Related Happenings
AsyncAPI malicious npm package supply-chain malware
Malware Activity
H score21
First: 15.07.2026 18:37
Last: 15.07.2026 18:37
Sources 1
About this happening:
Malicious AsyncAPI npm releases pushed a remote access trojan and info-stealing payload into packages with more than 2.25 million weekly downloads, putting downstr...
AsyncAPI malicious npm package supply-chain malware
Malware ActivityAbout this happening: Malicious AsyncAPI npm releases pushed a remote access trojan and info-stealing payload into packages with more than 2.25 million weekly downloads, putting downstr...
AsyncAPI repositories and npm publishing workflow hit by network compromise
Incident
H score27
First: 15.07.2026 12:16
Last: 15.07.2026 12:16
Sources 1
About this happening:
The AsyncAPI npm publishing pipeline was compromised in a July 14 supply-chain attack that used the project’s normal GitHub Actions release path to publish trojani...
AsyncAPI repositories and npm publishing workflow hit by network compromise
IncidentAbout this happening: The AsyncAPI npm publishing pipeline was compromised in a July 14 supply-chain attack that used the project’s normal GitHub Actions release path to publish trojani...
GitHub fake-repository infostealer campaign
Campaign
H score41
First: 14.07.2026 22:15
Last: 14.07.2026 22:15
Sources 1
About this happening:
A GitHub impersonation campaign is distributing infostealer malware through 292 fake repositories, expanding the risk to users searching for trusted software downloads...
GitHub fake-repository infostealer campaign
CampaignAbout this happening: A GitHub impersonation campaign is distributing infostealer malware through 292 fake repositories, expanding the risk to users searching for trusted software downloads...
Jscrambler hit by network compromise
Incident
H score15
First: 13.07.2026 22:44
Last: 13.07.2026 22:44
Sources 1
About this happening:
The Jscrambler npm package suffered an unauthorized publication of a malicious version that exposed developers to infostealer theft risk. The bad release stayed li...
Jscrambler hit by network compromise
IncidentAbout this happening: The Jscrambler npm package suffered an unauthorized publication of a malicious version that exposed developers to infostealer theft risk. The bad release stayed li...
OpenMandriva Linux project hit by cyberattack
Incident
H score32
First: 10.07.2026 01:14
Last: 10.07.2026 01:14
Sources 1
About this happening:
The OpenMandriva Linux project is recovering from an attempted internal sabotage that deleted repositories and published an empty package that could have damaged user...
OpenMandriva Linux project hit by cyberattack
IncidentAbout this happening: The OpenMandriva Linux project is recovering from an attempted internal sabotage that deleted repositories and published an empty package that could have damaged user...
Timeline
-
12.05.2026 14:07 2 articles · 2mo ago
Mini Shai-Hulud fresh wave compromises TanStack npm packages
Initial DisclosureResearchers disclosed a fresh wave of TeamPCP-linked Mini Shai-Hulud infections across compromised npm packages in the TanStack developer ecosystem, including 373 malicious package-version entries across 169 npm package names and 84 compromised TanStack npm package artifacts. The malware steals credentials from developer machines and CI/CD runners, then abuses trusted publishing paths, GitHub Actions/OIDC, and maintainers’ publishing credentials to push trojanized package updates.
Show sources
- Worm Redux: Fresh Mini Shai-Hulud Infections Bite Supply Chain — www.darkreading.com — 12.05.2026 14:07
- Leaked Shai-Hulud malware fuels new npm infostealer campaign — www.bleepingcomputer.com — 18.05.2026 20:28
-
26.11.2025 20:08 4 articles · 7mo ago
Shai-Hulud v2 expands from npm into Maven packages
Campaign Scope UpdateShai-Hulud v2 expanded from npm into Maven through org.mvnpm:posthog-node:4.18.1, which contained setup_bun.js and bun_environment.js. The campaign also abused GitHub Actions CI misconfigurations in projects associated with PostHog, AsyncAPI, and Postman, and the broader operation was linked to more than 28,000 affected repositories and widespread secret theft.
Show sources
- Shai-Hulud v2 Campaign Spreads From npm to Maven, Exposing Thousands of Secrets — thehackernews.com — 26.11.2025 20:08
- GitHub links repo breach to TanStack npm supply-chain attack — www.bleepingcomputer.com — 21.05.2026 09:54
- Miasma Supply Chain Attack Compromises Red Hat npm Packages with Credential-Stealing Worm — thehackernews.com — 01.06.2026 20:40
- Red Hat npm packages compromised to steal developer credentials — www.bleepingcomputer.com — 02.06.2026 00:38