Skip to main content
QUIETLYTIC
Malware

Mini Shai-Hulud

Self-replicating supply-chain worm and credential stealer, per MITRE ATT&CK, derived from Shai-Hulud and used by TeamPCP to target CI/CD workflows since at least 2026 via stolen npm and GitHub OIDC tokens.

Threat Level
CRITICAL
Family
Shai-Hulud
Type
WORM

Overview

Mini Shai-Hulud (MITRE ATT&CK ID S9043) is a credential stealer and self-replicating supply-chain worm, derived from a related family MITRE tracks as Shai-Hulud, that has been used by the group TeamPCP to target Continuous Integration and Continuous Delivery/Deployment (CI/CD) workflows since at least 2026, per MITRE’s software profile. MITRE documents the worm as capable of compromising credentials across multiple cloud, container, and AI configuration file paths, and using stolen npm and GitHub OIDC tokens to spread to other packages maintained by a compromised user’s account. MITRE’s data also notes a targeted wiper component and multiple documented command-and-control and data-exfiltration mechanisms. MITRE’s citations for this entry are notably recent — Wiz, Trend Micro, Hunt.io, Phoenix, Flashpoint, and an FBI advisory, all dated 2026 — reflecting how current this threat is relative to most entries in MITRE’s knowledge base.

Actors documented using this tool (per MITRE ATT&CK relationship data)

Our ingested data links Mini Shai-Hulud to one group: TeamPCP, its documented operator per MITRE’s description.

Notable techniques (per MITRE ATT&CK relationship data)

Techniques MITRE links to Mini Shai-Hulud in our data include Application Access Token abuse (T1550.001), Archive Collected Data (T1560) and its Archive via Utility (T1560.001) variant, Automated Collection (T1119), Cloud Account (T1087.004) and Cloud Accounts (T1078.004), Cloud Instance Metadata API abuse (T1552.005), and Cloud Secrets Management Stores (T1555.006) — a distinctly cloud/CI-CD-native technique profile compared to the more traditional Windows-endpoint-focused tooling elsewhere in this batch.

What we don’t have

MITRE’s data doesn’t give a precise discovery date beyond “since at least 2026.” We have no independent telemetry or IOC data beyond MITRE’s STIX bundle, and given how recently this entry was added, no long-term data on the worm’s spread or containment.

Frequently Asked Questions

What is Mini Shai-Hulud? A self-replicating supply-chain worm and credential stealer, per MITRE ATT&CK, targeting CI/CD workflows via stolen npm and GitHub OIDC tokens since at least 2026, used by the group TeamPCP.

How does Mini Shai-Hulud spread? Per MITRE ATT&CK’s documentation, it uses stolen npm and GitHub OIDC tokens to propagate to other packages maintained by a compromised user’s account — a self-replicating, package-ecosystem-native spreading mechanism.

Does Mini Shai-Hulud have a destructive component? Yes — MITRE’s description notes a targeted wiper component in addition to its credential-theft and self-propagation capabilities.


Data sourced from MITRE ATT&CK® (https://attack.mitre.org), software ID S9043, aggregated August 31, 2026. This product uses MITRE ATT&CK data but is not endorsed or certified by MITRE. See more malware profiles.

Report an error

Found a factual error, an outdated figure, or a broken source link? Let us know and our editorial desk will review it.


Related intelligence


Analyst tools