Mini Shai-Hulud's Latest Wave: 280 New Places It Hunts for Your Secrets
Blog post from GitGuardian
A new “Mini Shai-Hulud” npm supply-chain campaign reportedly began with the compromise of [email protected] on August 4, 2026, spreading to more than 800 packages and thousands of versions, including packages associated with several prominent companies. The malware uses an npm preinstall script to download the Bun runtime and execute an obfuscated second-stage payload, then targets developer endpoints and CI/CD runners for credentials, exfiltrates secrets through GitHub, and attempts persistence by modifying Claude and VS Code configuration files. Although its core collection providers remain unchanged, the updated variant substantially expands its filesystem search scope from 189 to 469 secret locations across Linux, Windows, and macOS, with particular emphasis on AI tools, CI/CD platforms, cloud services, cryptocurrency wallets, and files belonging to multiple users when elevated privileges are available. It also introduces the ability to retrieve command-and-control information from the Ethereum blockchain, illustrating continued adaptation by npm supply-chain attackers as they refine credential harvesting and respond to ecosystem security measures.
| Trend | Post Mentions | Total Month Mentions | Posts | Companies | MoM |
|---|---|---|---|---|---|
| Secrets Management | 13 | 584 | 99 | 52 | -76% |
| AI Agents | 2 | 1,180 | 266 | 113 | -80% |
| Kubernetes | 1 | 634 | 79 | 44 | -75% |
| OpenClaw | 1 | 6 | 4 | 3 | -98% |
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.