Malware.View on attack.mitre.org
Mini Shai-Hulud is a credential stealer and self-replicating supply chain worm, derived from Shai-Hulud, that has been used by TeamPCP to target Continuous Integration and Continuous Delivery/Deployment (CI/CD) workflows since at least 2026. Mini Shai-Hulud can compromise credentials across multiple cloud, container, and AI configuration file paths and can use stolen npm and GitHub OIDC tokens to spread to other packages maintained by the compromised user. Mini Shai-Hulud also has a targeted wiper component and has used multiple C2 and data exfiltration mechanisms.
| Technique | Procedure example |
|---|---|
| T1003.007 Proc Filesystem |
Mini Shai-Hulud has scraped runner process memory to extract short-lived identity tokens, which it then exchanged for per-package npm trusted-publisher tokens. |
| T1008 Fallback Channels |
Mini Shai-Hulud has established Fallback Channels to exfiltrate data to Github when other configured infrastructure is found to be unreachable. |
| T1016 System Network Configuration Discovery |
Mini Shai-Hulud has discovered network configuration through the use of system commands to include `ip addr`, and `ip route`. |
| T1021.007 Cloud Services |
Mini Shai-Hulud has accessed and propagated to AWS EC2 instances via SSM Send-Command. |
| T1027.013 Encrypted/Encoded File |
Mini Shai-Hulud has used a hybrid AES-256-GCM and RSA OAEP-SHA256 encryption to archive gathered data. Mini Shai-Hulud has also utilized custom MD5-keystream XOR cipher to encrypt data. Mini Shai-Hulud has also been deployed via an obfuscated script using Bun JavaScript runtime. |
| T1033 System Owner/User Discovery |
Mini Shai-Hulud has leveraged commands such as `whoami` to identify the system owner. |
| T1036.005 Match Legitimate Resource Name or Location |
Mini Shai-Hulud has leveraged a user-agent string that mimics a standard git client to avoid detection within network logs. |
| T1041 Exfiltration Over C2 Channel |
Mini Shai-Hulud has exfiltrated encrypted archives over C2 domains. |
| T1053.006 Systemd Timers |
Mini Shai-Hulud has obtained persistence on Linux devices by writing the `gh-token-monitor` daemon within `~/.config/systemd/user/gh-token-monitor.service` that polls GitHub every 60 seconds. Mini Shai-Hulud has also leveraged a daemon called “kitty-monitor.service” to maintain persistence within Linux hosts. |
| T1059.006 Python |
Mini Shai-Hulud has utilized Python scripts to execute payloads. |
| T1059.007 JavaScript |
Mini Shai-Hulud has leveraged JavaScript runtime to execute malicious scripts. |
| T1059.013 Container CLI/API |
Mini Shai-Hulud has utilized the Docker command-line tool to gather details of the victim environment and collect credentials. |
| T1070.004 File Deletion |
Mini Shai-Hulud has deleted all artifacts to include gathered credential archives to reduce disk persistence and detection. |
| T1071.001 Web Protocols |
Mini Shai-Hulud has has exfiltrated data through the use of HTTPS POST requests to C2 domains. |
| T1078.004 Cloud Accounts |
Mini Shai-Hulud has used compromised accounts for Docker Hub and GitHub to publish malicious software packages. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.