Corpus graph previewActor to Incident
Supply Chain GraphPan, zoom, and select actor, campaign, and incident tiers.

Supply Chain graph is loading. Keyboard controls become available after graph initialization.

Supply Chain Incident

Focused Graph View

The persistent graph is framed to this incident while the canonical page heading and details continue below.

270 nodes467 edgesCold links hydrate here

Supply Chain Incident

Shai-Hulud npm self-propagating package compromise

The Shai-Hulud campaign compromised npm packages with credential-harvesting malware that used stolen npm tokens to publish malicious versions of additional packages.

ConfidenceHigh
Evidence LevelResearcher
Attack StagePackage Publish
Source Artifact DivergenceNo
Attribution ConfidenceSuspected

Evidence-Gated Propagation

Propagation Timeline

  1. Release@ctrl/tinycolor@4.1.1pkg:npm/%40ctrl/tinycolor@4.1.1
    Release@ctrl/tinycolor@4.1.2pkg:npm/%40ctrl/tinycolor@4.1.2

    The npm registry metadata records adjacent malicious @ctrl/tinycolor releases on the same date; this edge preserves ordered wave structure without asserting causation.

  2. Release@ctrl/tinycolor@4.1.1pkg:npm/%40ctrl/tinycolor@4.1.1

    Public reporting places rxnt-authentication activity before the @ctrl/tinycolor wave and describes token reuse, but this edge is temporal precedence rather than asserted package-to-package causation.

Affected Packages

Affected Releases

  • @ctrl/tinycolor@4.1.1pkg:npm/%40ctrl/tinycolor@4.1.1 · published 2025-09-15Release
  • @ctrl/tinycolor@4.1.2pkg:npm/%40ctrl/tinycolor@4.1.2 · published 2025-09-15Release

Repositories

No structured records.

Organizations

Maintainers

No structured records.

Threat Actors

  • Shai-Hulud operator

Campaigns

No structured records.

Build Systems

  • GitHub Actions

Distribution Channels

  • GitHub Actions workflow
  • npm registry

Compromised Accounts

  • compromised npm maintainer tokens
  • victim GitHub tokens

Connected Entities

  • @ctrl/tinycolorPackage
  • @ctrl/tinycolor@4.1.1Release
  • @ctrl/tinycolor@4.1.2Release
  • compromised npm maintainer tokensCompromised Account
  • ctrlOrganization
  • GitHub ActionsBuild System
  • GitHub Actions workflowDistribution Channel
  • npm registryDistribution Channel
  • rxntOrganization
  • rxnt-authenticationPackage
  • Shai-Hulud operatorThreat Actor
  • victim GitHub tokensCompromised Account

Attribution Evidence

References