Supply Chain / Malware Family
Shai-Hulud: a worm family, traced
A self-propagating supply-chain worm family spanning npm, PyPI, and RubyGems activity, modeled as genealogy rather than infection propagation.
Actor at root · time left to right · mutation on each edge
Phylogeny
Analyst consumable
Strain Comparison
| Generation | First Seen | Ecosystems | Key Mutation / Novelty | Provenance Abuse | Attributed | Lineage |
|---|---|---|---|---|---|---|
| Shai-Hulud | 2025-09-16 | npm | Origin strain: self-replicating npm worm with token theft and auto-republish behavior. | Static token theft | Unattributed | Origin |
| Shai-Hulud 2.0 | 2025-11-24 | npm | Second wave with broader package reach and faster propagation. | Static token theft | TeamPCP | Confirmed |
| Mini Shai-Hulud | 2026-05-11 | npm · PyPI · RubyGems | Trusted publishing and OIDC token abuse across multiple package ecosystems. | Trusted publishing / OIDC | TeamPCP | Confirmed |
| Miasma | 2026-06-01 | npm | binding.gyp install-time evasion, per-infection encryption, and prompt-injection targeting AI coding agents. | Trusted publishing / OIDC | Suspected TeamPCP | Suspected |
| Hades | 2026-06-06 | PyPI | PyPI move with Artifactory-focused reconnaissance and broader propagation. | OIDC | Suspected | Suspected |
| IronWorm | 2026-06-06 | npm | Rust ELF payload delivered through a preinstall hook. | Preinstall hook | Unclear | Suspected |
What stayed, what mutated
Family Changelog
Shai-Hulud
2025-09-16 · npm · originMutated: Created the family template: developer token theft, public exfiltration repositories, and automated republishing into other npm packages.
Shai-Hulud 2.0
2025-11-24 · npm · confirmedKept: token theft, auto-republish.
Mutated: Expanded the original playbook into a larger wave while retaining token theft and automated republishing.
Mini Shai-Hulud
2026-05-11 · npm + PyPI + RubyGems · confirmedKept: self-propagation, credential theft.
Mutated: Shifted the worm from static-token theft toward CI/CD trusted-publishing abuse, OIDC token extraction, and cross-ecosystem package propagation.
Miasma
2026-06-01 · npm · suspectedKept: trusted-publishing abuse, self-propagation.
Mutated: Added per-infection encryption, binding.gyp execution, and AI-assistant prompt-injection behavior while retaining the released Mini Shai-Hulud playbook.
Hades
2026-06-06 · PyPI · suspectedKept: Miasma evasion, AI-assistant targeting.
Mutated: Carried Miasma behavior into PyPI and added Artifactory-focused reconnaissance.
IronWorm
2026-06-06 · npm · suspectedKept: credential-driven self-replication.
Mutated: A suspected cosmetic clone over the released base, with a Rust ELF payload and preinstall execution.
Why the grading matters
Genealogy, Not Infection
Confirmed descent requires code overlap or explicit researcher attestation. Suspected and cosmetic forks stay dashed, and the source-release fork event remains visible because public code makes look-alikes harder to attribute.
This page separates EVOLVED_FROM, meaning strain genealogy, from SEEDED_BY, meaning one compromise enabled another.
Related Incidents
- Shai-Hulud npm self-propagating package compromise2025-09-16Supply Chain Incident
- Shai-Hulud 2.0 npm supply-chain worm wave2025-12-09Supply Chain Incident
- Mini Shai-Hulud TanStack npm and PyPI supply-chain wave2026-05-13Supply Chain Incident
Family Sources
- Shai-Hulud npm supply-chain attackWiz · 2025-09-16
- Shai-Hulud 2.0 guidanceMicrosoft Security Blog · 2025-12-09
- TanStack npm packages compromised in Mini Shai-Hulud supply-chain attackSocket Research Team · 2026-05-11
- Mini Shai-Hulud is backStepSecurity · 2026-05-11
- The Hades Campaign: Graph ML PyPI Packages Deploy Cross-Platform Memory Scrapers, AI Analyst Misdirection, and a Wiper DeterrentStepSecurity · 2026-06-08