Lineage viewActor to Incident
Supply Chain GraphPan, zoom, and select actor, campaign, and incident tiers.

Supply Chain graph is loading. Keyboard controls become available after graph initialization.

Malware Family Lineage

Focused Graph View

Trace malware strain genealogy separately from infection propagation, with confidence and mutation deltas visible on each edge.

270 nodes467 edgesCold links hydrate here

Supply Chain / Malware Family

Shai-Hulud: a worm family, traced

A self-propagating supply-chain worm family spanning npm, PyPI, and RubyGems activity, modeled as genealogy rather than infection propagation.

Actor at root · time left to right · mutation on each edge

Phylogeny

Sep 2025
Dec 2025
May 2026
Jun 1-5
Jun 6+
scale · faster propagation
added PyPI · added trusted publishing · OIDC token theft
binding.gyp install evasion · per-infection encryption · AI coding-agent prompt injection
moved to PyPI · Artifactory reconnaissance · broader propagation
Rust ELF payload · preinstall hook · cosmetic fork
Mini Shai-Hulud source open-sourced2026-05-12
confirmed descent suspected / cosmetic fork source-release fork eventEVOLVED_FROM is genealogy; SEEDED_BY remains infection path.
Hover a strainTargets and incidents live one layer down; this page traces family genealogy.

Analyst consumable

Strain Comparison

GenerationFirst SeenEcosystemsKey Mutation / NoveltyProvenance AbuseAttributedLineage
Shai-Hulud2025-09-16npmOrigin strain: self-replicating npm worm with token theft and auto-republish behavior.Static token theftUnattributedOrigin
Shai-Hulud 2.02025-11-24npmSecond wave with broader package reach and faster propagation.Static token theftTeamPCPConfirmed
Mini Shai-Hulud2026-05-11npm · PyPI · RubyGemsTrusted publishing and OIDC token abuse across multiple package ecosystems.Trusted publishing / OIDCTeamPCPConfirmed
Miasma2026-06-01npmbinding.gyp install-time evasion, per-infection encryption, and prompt-injection targeting AI coding agents.Trusted publishing / OIDCSuspected TeamPCPSuspected
Hades2026-06-06PyPIPyPI move with Artifactory-focused reconnaissance and broader propagation.OIDCSuspectedSuspected
IronWorm2026-06-06npmRust ELF payload delivered through a preinstall hook.Preinstall hookUnclearSuspected

What stayed, what mutated

Family Changelog

Shai-Hulud

2025-09-16 · npm · origin

Mutated: Created the family template: developer token theft, public exfiltration repositories, and automated republishing into other npm packages.

Shai-Hulud 2.0

2025-11-24 · npm · confirmed

Kept: token theft, auto-republish.

Mutated: Expanded the original playbook into a larger wave while retaining token theft and automated republishing.

Mini Shai-Hulud

2026-05-11 · npm + PyPI + RubyGems · confirmed

Kept: self-propagation, credential theft.

Mutated: Shifted the worm from static-token theft toward CI/CD trusted-publishing abuse, OIDC token extraction, and cross-ecosystem package propagation.

Miasma

2026-06-01 · npm · suspected

Kept: trusted-publishing abuse, self-propagation.

Mutated: Added per-infection encryption, binding.gyp execution, and AI-assistant prompt-injection behavior while retaining the released Mini Shai-Hulud playbook.

Hades

2026-06-06 · PyPI · suspected

Kept: Miasma evasion, AI-assistant targeting.

Mutated: Carried Miasma behavior into PyPI and added Artifactory-focused reconnaissance.

IronWorm

2026-06-06 · npm · suspected

Kept: credential-driven self-replication.

Mutated: A suspected cosmetic clone over the released base, with a Rust ELF payload and preinstall execution.

Why the grading matters

Genealogy, Not Infection

Confirmed descent requires code overlap or explicit researcher attestation. Suspected and cosmetic forks stay dashed, and the source-release fork event remains visible because public code makes look-alikes harder to attribute.

This page separates EVOLVED_FROM, meaning strain genealogy, from SEEDED_BY, meaning one compromise enabled another.

Related Incidents

Family Sources