McCarthy, R., Cohen, A., and Read, B. (2026, May 12). Mini Shai-Hulud Strikes Again: TanStack + more npm Packages Compromised. Retrieved July 16, 2026.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1008 Fallback Channels |
MalwareMini Shai-Hulud | Mini Shai-Hulud has established Fallback Channels to exfiltrate data to Github when other configured infrastructure is found to be unreachable. |
| T1053.006 Systemd Timers |
MalwareMini Shai-Hulud | Mini Shai-Hulud has obtained persistence on Linux devices by writing the `gh-token-monitor` daemon within `~/.config/systemd/user/gh-token-monitor.service` that polls GitHub every 60 seconds. Mini Shai-Hulud has also leveraged a daemon called “kitty-monitor.service” to maintain persistence within Linux hosts. |
| T1059.006 Python |
MalwareMini Shai-Hulud | Mini Shai-Hulud has utilized Python scripts to execute payloads. |
| T1078.004 Cloud Accounts |
GroupTeamPCP | TeamPCP has used compromised credentials for GitHub and software package repositories, including privileged service accounts, to inject malicious code into CI/CD pipelines. |
| T1090.003 Multi-hop Proxy |
MalwareMini Shai-Hulud | Mini Shai-Hulud has the ability to exfiltrate stolen credentials via the Session messenger network. |
| T1102.001 Dead Drop Resolver |
MalwareMini Shai-Hulud | Mini Shai-Hulud has leveraged GitHub commit-search API to recover fallback C2 domains stored in auto-created public Github repositories. |
| T1105 Ingress Tool Transfer |
MalwareMini Shai-Hulud | Mini Shai-Hulud has the ability to download additional payloads from adversary controlled or compromised infrastructure. |
| T1190 Exploit Public-Facing Application |
GroupTeamPCP | TeamPCP has exploited misconfigurations in GitHub Actions and vulnerabilities such as CVE-2026-33634 in the Aqua Security Trivy scanner and CVE-2025-55182 (React2Shell) against vulnerable cloud endpoints. |
| T1195.001 Compromise Software Dependencies and Development Tools |
GroupTeamPCP | TeamPCP has conducted coordinated supply chain attacks targeting open-source developer infrastructure including the NPM, VS Code, Docker, and PyPi ecosystems to compromise multiple software packages. Aikido TeamPCP Telnyx MAR 2026Aqua Security Trivy Compromise MAR 2026FBI TeamPCP JUL 2026Flashpoint Mini Shai-Hulud MAY 2026Google AI Threat Tracker MAY 2026Hunt.io TeamPCP Toolkit MAY 2026Palo Alto TeamPCP MAR 2026Phoenix TeamPCP 20 MAY 2026Trend Micro TeamPCP MAY 2026Wiz Mini Shai-Hulud MAY 2026Wiz TeamPCP KICS MAR 2026Wiz Trivy Compromise MAR 2026 |
| T1480 Execution Guardrails |
MalwareMini Shai-Hulud | Mini Shai-Hulud has utilized execution guardrails in order to prevent operating in restricted geolocations to include Russia by checking the devices language and terminating when a forbidden value is detected. Mini Shai-Hulud has also utilized designated instructions that execute when victim hosts match geolocations to include wiping victim devices when the device is determined to be located within Iran or Israel. |
| T1497.001 System Checks |
MalwareMini Shai-Hulud | Mini Shai-Hulud has evaded execution in virtual environments and sandboxes through checking system information to include the number of CPUs and exiting at times when there were less than four and other times when there were less than two CPUs. |
| T1528 Steal Application Access Token |
MalwareMini Shai-Hulud | Mini Shai-Hulud has stolen application access tokens and other tokens to include those associated with CI/CD. |
| T1543.001 Launch Agent |
MalwareMini Shai-Hulud | Mini Shai-Hulud has established persistence on macOS hosts by installing a gh-token-monitor daemon through LaunchAgent that polls GitHub every 60 seconds. |
| T1543.002 Systemd Service |
MalwareMini Shai-Hulud | Mini Shai-Hulud has created .service files using Systemd on victim Linux hosts to establish persistence. |
| T1546.016 Installer Packages |
GroupTeamPCP | TeamPCP has modified software packages with preinstall scripts to download and execute malicious payloads. |
| T1550.001 Application Access Token |
MalwareMini Shai-Hulud | Mini Shai-Hulud has the ability to authenticate using stolen application access tokens. |
| T1555.005 Password Managers |
MalwareMini Shai-Hulud | Mini Shai-Hulud has gathered credentials stored in password managers to include password vaults. |
| T1555.006 Cloud Secrets Management Stores |
MalwareMini Shai-Hulud | Mini Shai-Hulud has captured credentials stored in cloud secret stores. |
| T1583.001 Domains |
GroupTeamPCP | TeamPCP has registered domains resembling legitimate victim sites such as scan.aquasecurtiy[.]org, checkmarx[.]zone, and git-tanstack[.]com to mask C2 and exfiltration endpoints. TeamPCP has also set up a dark web leak site to post stolen data. |
| T1583.006 Web Services |
GroupTeamPCP | TeamPCP has set up Clouflare Tunnels for malware C2. TeamPCP has also used the session messenger network for decentralized, encrypted exfiltration via *.getsession[.]org to recipient ID `05f9e609d79eed391015e11380dee4b5c9ead0b6e2e7f0134e6e51767a87323026`. |
| T1614.001 System Language Discovery |
MalwareMini Shai-Hulud | Mini Shai-Hulud has the ability to check system details for its language configuration and terminates actions when the system is configured for the Russian language. |
| T1677 Poisoned Pipeline Execution |
GroupTeamPCP | TeamPCP has compromised trusted CI/CD pipelines by injecting credential-stealing payloads into legitimate workflows and software packages including open-source security tools Trivy and KICS, and AI gateway LiteLLM. Aikido TeamPCP Telnyx MAR 2026Aqua Security Blog Trivy Compromise APR 2026Aqua Security Trivy Compromise MAR 2026FBI TeamPCP JUL 2026Flashpoint Mini Shai-Hulud MAY 2026Google AI Threat Tracker MAY 2026Hunt.io TeamPCP Toolkit MAY 2026Palo Alto TeamPCP MAR 2026Phoenix TeamPCP 20 MAY 2026Sysdig TeamPCP MAR 2026Trend Micro TeamPCP MAY 2026Wiz Mini Shai-Hulud MAY 2026Wiz TeamPCP KICS MAR 2026Wiz Trivy Compromise MAR 2026 |
| T1677 Poisoned Pipeline Execution |
MalwareMini Shai-Hulud | Mini Shai-Hulud has utilized Github Actions to propagate through the use of triggered workflows. |
| T1683.001 Written Content |
GroupTeamPCP | TeamPCP has created Dune-themed GitHub repositories using stolen tokens. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.