Open‑source software supply chains rely heavily on trust: trusted maintainers, trusted CI pipelines, and trusted cryptographic signatures. The Mini Shai‑Hulud campaign showed how quickly that trust can be weaponized.
In May 2026, a threat group known as TeamPCP launched a coordinated attack that compromised widely used npm and PyPI packages, published hundreds of malicious versions, and used legitimate build infrastructure to make those packages appear authentic. In one burst on May 19, 2026, attackers reportedly published 637 malicious versions across 323 packages in roughly 22 minutes after compromising a maintainer account tied to the @antv ecosystem.
The incident is now considered one of the most technically significant open‑source supply‑chain attacks because the malicious artifacts carried valid build provenance and signing attestations, undermining a key security mechanism developers rely on.
Mini Shai‑Hulud was not a single event but a multi‑stage campaign targeting widely used developer ecosystems.
Security research reports that the operation compromised more than 170 npm and PyPI packages across 19 namespaces, publishing over 400 malicious package versions between May 10 and May 12, 2026.
The affected packages included libraries tied to projects such as TanStack, Mistral AI, UiPath, OpenSearch, and Guardrails AI—software components with large downstream usage across web applications and developer tools.
Because these packages collectively accumulated hundreds of millions of historical downloads, even a brief compromise created widespread risk across the developer ecosystem.
A later wave targeted the AntV data‑visualization ecosystem, where hundreds of malicious versions were published across related npm packages with roughly 16 million weekly downloads.
The astonishing speed of the attack came from abusing trusted automation and maintainership privileges.
In the May 19 wave, the attackers reportedly compromised the npm maintainer account associated with the atool package and used it to push hundreds of new versions across a large group of related packages.
Because maintainers can publish new versions automatically through scripts and CI pipelines, a single compromised account allowed attackers to:
This automation allowed the attackers to publish hundreds of malicious artifacts within minutes, rather than manually compromising packages one by one.
One of the most technically notable aspects of Mini Shai‑Hulud was how it subverted modern “secure” publishing workflows.
Many projects now use GitHub Actions trusted publishing, where CI workflows obtain temporary identity tokens through OpenID Connect (OIDC) and use them to publish packages without storing long‑lived credentials.
In several compromised projects, the attackers were able to:
Because the release pipeline itself performed the publish, the packages appeared to come from the project’s legitimate build system.
This technique bypassed a common security assumption: that removing long‑lived credentials automatically prevents supply‑chain compromise.
The attack went further by exploiting the software‑supply‑chain integrity systems meant to prevent tampering.
Modern build pipelines increasingly generate SLSA provenance attestations and sign artifacts using Sigstore certificates. These signatures allow users to verify that a package was built by a trusted workflow.
Mini Shai‑Hulud undermined that guarantee.
Researchers found that the attackers were able to obtain legitimate signing certificates by using compromised CI identities and OIDC tokens. As a result, malicious packages were released with valid SLSA Build Level 3 provenance and cryptographic signatures.
From a verification perspective, the packages looked authentic: they were signed, traceable to real workflows, and published through trusted pipelines.
The weakness was not the signing system itself—it was that the trusted build environment had already been compromised.
The malicious packages contained code designed to harvest sensitive developer and infrastructure credentials.
Reports indicate the malware targeted items such as:
By stealing these secrets, the malware could compromise additional repositories and publishing pipelines, allowing the worm to propagate through the ecosystem.
This credential‑theft capability is what allowed Mini Shai‑Hulud to behave like a self‑spreading supply‑chain worm, moving from one compromised project to another.
Mini Shai‑Hulud demonstrated several dangerous realities about modern software supply chains.
1. Trusted infrastructure can be turned against itself.
Even advanced security features—OIDC trusted publishing, SLSA provenance, and signed artifacts—cannot prevent malicious releases if attackers gain control of the build pipeline that generates them.
2. One compromised maintainer can affect hundreds of packages.
The AntV wave showed how a single account compromise could result in hundreds of malicious versions across hundreds of packages in minutes.
3. Popular packages amplify the blast radius.
Many compromised libraries are dependencies of other packages, meaning malicious updates can spread through transitive dependencies to thousands of projects.
4. The campaign evolved over time.
Security researchers linked Mini Shai‑Hulud to a broader TeamPCP campaign that also involved compromising tools such as the Checkmarx Jenkins AST plugin and targeting multiple open‑source ecosystems.
Because the techniques rely on automation and common CI/CD patterns, analysts warn that copycat attacks or variants are likely.
Mini Shai‑Hulud exposed a critical truth about modern software supply chains: cryptographic verification alone cannot guarantee safety if attackers control the trusted pipeline producing the software.
The attack shows why organizations increasingly focus on:
As the ecosystem shifts toward automated builds and signed artifacts, the security of CI infrastructure and developer identities has become just as important as the integrity of the code itself.
Mini Shai‑Hulud demonstrated how quickly that trust can be exploited—and how widely the consequences can spread when it is.
Studio Global AI
Use this topic as a starting point for a fresh source-backed answer, then compare citations before you share it.
Mini Shai‑Hulud was a self‑propagating supply‑chain worm that abused GitHub Actions OIDC tokens, CI/CD secrets, and trusted build provenance to publish malicious npm packages that appeared legitimate—at one point push...
Mini Shai‑Hulud was a self‑propagating supply‑chain worm that abused GitHub Actions OIDC tokens, CI/CD secrets, and trusted build provenance to publish malicious npm packages that appeared legitimate—at one point push... The attackers exploited trusted automation: compromised maintainer accounts and CI pipelines allowed malicious packages to be signed with valid SLSA provenance and Sigstore certificates, making them appear authentic.[...
Because the malware stole developer and CI/CD credentials and targeted widely used packages with millions of weekly downloads, the campaign demonstrated how a single compromise can cascade through the entire open‑sour...