Mini Shai-Hulud

discovered 2026-04-29

Self-propagating npm supply chain worm. Wave 4 (2026-08-04): mass credential compromise across 8+ npm organizations, ~404 packages, ~1,070 poisoned versions in a 2-hour window. setup.mjs + Bun v1.3.13 dropper, IDE hook cross-wiring (Claude Code + VS Code), commit spoofing upgraded to GitHub API-verified commits. Deep payload analysis confirmed EtherHiding (Ethereum smart contract 0xE1f2395...3103 storing C2 domains), DomainSender exfiltration channel, and CI runner /proc/mem secret scraping. Stage-two is a confirmed production build of the Miasma codebase with DomainSender activated and Ethereum contract bootstrapping. 536 exfiltration repos created on Aug 4 across compromised GitHub accounts (nishantosc, juukan), 873+ total across all waves. GitHub commit search keywords: DontRevokeOrItGoesBoom (PAT discovery), TheBeautifulSandsOfTime (JS C2 commands), firedalazer (Python persistent monitor), thebeautifulmarchoftime (backup C2 domain discovery).

Objective

Steal developer, cloud, registry, and application credentials through malicious package execution and self-propagate via stolen tokens and trusted-publishing abuse.

Related campaigns

Packages

Indicators

Techniques

Read the full analysis →