Home / Companies / GitGuardian / Blog / Post Details
Content Deep Dive

Mini Shai-Hulud's Latest Wave: 280 New Places It Hunts for Your Secrets

Blog post from GitGuardian

Post Details
Company
Date Published
Author
Gaetan Ferry
Word Count
901
Company Posts That Month
4
Language
English
Hacker News Points
-
Post removed?
No
Summary

A new “Mini Shai-Hulud” npm supply-chain campaign reportedly began with the compromise of [email protected] on August 4, 2026, spreading to more than 800 packages and thousands of versions, including packages associated with several prominent companies. The malware uses an npm preinstall script to download the Bun runtime and execute an obfuscated second-stage payload, then targets developer endpoints and CI/CD runners for credentials, exfiltrates secrets through GitHub, and attempts persistence by modifying Claude and VS Code configuration files. Although its core collection providers remain unchanged, the updated variant substantially expands its filesystem search scope from 189 to 469 secret locations across Linux, Windows, and macOS, with particular emphasis on AI tools, CI/CD platforms, cloud services, cryptocurrency wallets, and files belonging to multiple users when elevated privileges are available. It also introduces the ability to retrieve command-and-control information from the Ethereum blockchain, illustrating continued adaptation by npm supply-chain attackers as they refine credential harvesting and respond to ecosystem security measures.

Trends Found in this Post
Trend Post Mentions Total Month Mentions Posts Companies MoM
Secrets Management 13 584 99 52 -76%
AI Agents 2 1,180 266 113 -80%
Kubernetes 1 634 79 44 -75%
OpenClaw 1 6 4 3 -98%
Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.