EarlyTerms

Mini Shai-Hulud

Validating · Emerged · 46 days old · Last reviewed

Mini Shai-Hulud is the fourth-generation variant of the Shai-Hulud supply-chain worm family, built by threat group TeamPCP to self-propagate across npm, PyPI, and Packagist by stealing CI/CD credentials and republishing infected packages through compromised maintainer accounts.

First detected in April 2026 targeting SAP packages, Mini Shai-Hulud reached critical mass on May 11, 2026, when it compromised 42 TanStack packages with valid SLSA Build Level 3 provenance attestations — the first documented case of a worm defeating cryptographic supply-chain integrity controls. On May 12, 2026, TeamPCP open-sourced the complete attack toolkit on GitHub, making the worm-as-a-service available to any threat actor.

Think of it as a skeleton key that clones itself into every lock it opens.

Search Interest

peak ~1.3K/mo
updated 2026-06-14
~1.3K/mo ~645/mo 0
2026-05-15 2026-05-30 2026-06-13
Term Lifecycle
  1. Nascent
    0–7 days
  2. Emergent
    8–30 days
  3. Validating ← now
    31–90 days
  4. Rising
    91–180 days
  5. Established
    180 days +

Why is it emerging now?

TL;DR

Mini Shai-Hulud broke two npm supply-chain defenses: it forged valid SLSA Build Level 3 provenance and survived remediation via AI coding agent session hooks. TeamPCP open-sourced the full toolkit May 12, 2026 — derivatives Miasma and Hades are already active.

6 forces driving coverage — scroll →

Outlook

6-month signal projection and commercial timeline.

Signal high
Revenue strong

Open-sourced worm toolkit accelerates derivative campaigns; AI coding agent config files are now a confirmed propagation surface every security team must address.

Risk · Microsoft and Red Hat credential revocation could collapse active Miasma/Hades wave spread before broader adoption.

Analogs · XZ Utils backdoor · event-stream malware · SolarWinds SUNBURST

Monetization timeline
  1. now
    Incident response in demand

    Security teams auditing CI/CD pipelines and AI agent config files; paid advisory, scanning tooling in immediate demand.

  2. 3-6mo
    Supply chain hardening products

    Vendors build OIDC policy analyzers, CI cache validators, and AI agent config scanners targeting the specific Mini Shai-Hulud attack surface.

  3. 6-12mo
    Compliance and SLSA reform

    SLSA specification update to address provenance forgery via pipeline hijack; compliance auditors add AI agent session hooks to review checklists.

Competition & Opportunity for term “Mini Shai-Hulud”

Three heuristic signals derived from the tracked queries, the term's monetization cards, and its cluster neighbors. Directional, not audited.

Content Gap
2 queries tracked
Led by General (2)
2 Suggest-only tails — long-tail opening
Revenue Potential
0% commercial-intent queries
2 monetization angles mapped
Mostly informational — pre-commercial
Build Difficulty
Medium
Stage: validating — incumbents warming up
0 / 13 default TLDs taken
9 related terms already published
Heuristic · signals: tracked queries, term monetization cards, cluster neighbors

Ideas for term “Mini Shai-Hulud”

Buildable pitches — turn this term into an article, site, product, post, newsletter, video, or course. Steal any card and run with it.

Article
What is Mini Shai-Hulud? The npm worm that broke SLSA provenance explained

High-intent explainer for the 'mini shai-hulud' query; zero competition from pre-existing pages targeting this exact term. Hooks the SLSA-defeat angle for security-literate readers.

Article
Mini Shai-Hulud vs Miasma vs Hades: mapping the Shai-Hulud worm family in 2026

Comparison article for security professionals needing a reference on the three active campaign branches; satisfies the 'what is the difference between Miasma and Mini Shai-Hulud' query.

Article
How to detect Mini Shai-Hulud indicators in your npm, PyPI, and Packagist dependencies

Practical audit checklist: suspicious preinstall hooks, Bun runtime downloads, binding.gyp patterns, forked optionalDependencies, AI agent config file changes.

Article
How Mini Shai-Hulud defeated SLSA Build Level 3 — and what comes next for supply chain attestations

Deep analysis piece targeting platform engineers; the SLSA-forgery-via-pipeline-hijack angle has no prior coverage and is a strong SEO gap in the SLSA specification community.

Product
CI/CD workflow auditor for Mini Shai-Hulud OIDC token exfiltration patterns

GitHub Action that validates pull_request_target permissions, cache integrity, and OIDC scope restrictions — closes the exact three chained vulnerabilities CVE-2026-45321 exploited.

Product
AI coding agent config file integrity scanner

Pre-commit hook or SaaS scanner that detects unexpected changes to .claude/settings.json, .vscode/tasks.json, .gemini/settings.json — the persistence hooks Mini Shai-Hulud survives remediation through.

Video
Live demo: How Mini Shai-Hulud poisons a GitHub Actions cache and publishes malicious npm with valid SLSA provenance

Security YouTube walkthrough in a sandboxed environment; the SLSA-defeat mechanism is highly visual and counterintuitive — strong candidate for a 'wait, this is real?' viral moment.

Post HN / r/netsec / r/programming
Mini Shai-Hulud Proved That Valid SLSA Provenance Means Nothing If the Pipeline Is Compromised

You checked the Sigstore signature. The SLSA Build Level 3 badge was there. The npm package was still malware.

Post LinkedIn / DevSecOps / AppSec community
TeamPCP Open-Sourced Their Worm Toolkit. Here's What the Security Industry Missed.

On May 12, 2026, the group behind 170+ compromised npm packages posted their full attack code to GitHub. Two weeks later, Miasma used it to hit Red Hat. Then Microsoft.

Post Newsletter / YouTube / Tech media
The npm Worm That Lives in Your AI Coding Agent

Mini Shai-Hulud doesn't just steal your AWS keys — it writes itself into .claude/settings.json so it re-executes every time you open your project in Claude Code, even after you've 'fixed' the compromised package.

What People Search

Long-tail queries from Google Suggest + Trends. Volume and competition are heuristics — directional, not audited. Content Type comes from query shape.

Keyword
Competition
Content Type
mini shai-hulud
Low
General
small shai hulud
Low
General
Updated 2026-06-14 · sources: Google Trends, Google Suggest · Competition is heuristic

SERP of term “Mini Shai-Hulud”

What searchers see today — organic results on top, paid ads if anyone's bidding. Ad density is a real-time commercial signal.

FAQ

What is Mini Shai-Hulud?

Mini Shai-Hulud is the fourth-generation variant of the Shai-Hulud supply-chain worm family, built by threat group TeamPCP to self-propagate across npm, PyPI, and Packagist by stealing CI/CD credentials and republishing infected packages….

Why is Mini Shai-Hulud emerging now?

Mini Shai-Hulud broke two npm supply-chain defenses: it forged valid SLSA Build Level 3 provenance and survived remediation via AI coding agent session hooks. TeamPCP open-sourced the full toolkit May 12, 2026 — derivatives Miasma and Hades are already active.

When did Mini Shai-Hulud emerge?

Publicly emerged around 2026-04-29 (about 46 days ago as of 2026-06-14). EarlyTerms first recorded a pipeline signal on 2026-05-12.

Related Terms

Other terms in the same space — aliases, subtypes, competitors, and neighbors to explore next.

Explore next
Also mentioned
  • Part of supply chain attack·Shai-Hulud
  • Related SLSA

Sources

Primary URLs this report cites — open any to verify the claim yourself.

  1. 01 Akamai Security Research: Mini Shai-Hulud Worm Returns and Goes Public (May 12, 2026) akamai.com
  2. 02 Snyk: TanStack npm Packages Hit by Mini Shai-Hulud — SLSA BL3 provenance defeated (May 12, 2026) snyk.io
  3. 03 SafeDep: Mini Shai-Hulud Strikes Again — 314 npm Packages Compromised (May 19, 2026) safedep.io
  4. 04 StepSecurity: TeamPCP's Mini Shai-Hulud Is Back — TanStack Self-Spreading Supply Chain Attack (May 12, 2026) stepsecurity.io
  5. 05 Tenable: Mini Shai-Hulud FAQ — CVE-2026-45321, CVSS 9.6, four campaign waves (May 2026) tenable.com
  6. 06 Semgrep: Mini Shai-Hulud Spreads to Packagist via Malicious Intercom PHP Composer Plugin (May 2026) semgrep.dev
  7. 07 Socket: Mini Shai-Hulud, Miasma, and Hades Target Bioinformatics and MCP Developers (Jun 13, 2026) socket.dev
  8. 08 Cloud Security Alliance: Mini Shai-Hulud Multi-Ecosystem Supply Chain Attack Research Note labs.cloudsecurityalliance.org