Crypto Times Logo Black
Google News Follow Banner
  • News
    • Market
    • Bitcoin
    • Ethereum
    • Altcoins
    • Regulations & Policies
    • Price Analysis
    • DeFi News
    • Blockchain News
    • Industry
  • Exclusive
    ExclusiveShow More
    Elon Musk and SpaceX composite image with the Indian flag and Bitcoin
    India vs Elon Musk: Starlink’s Global Wall of Bans, and the Crypto Thread Running Through It
    Physical gold Bitcoin (BTC) token standing in front of the US Capitol Building and the American flag
    Why Are U.S. Government Wallets Still Routing Seized Crypto to Coinbase?
    Charlie Lee, creator of Litecoin, standing in front of a blue Litecoin corporate logo wall
    Litecoin Turns 15: Original Bitcointalk Records Show How Charlie Lee Launched LTC in 2011
    Elon Musk with folded arms flanked by a giant Bitcoin coin, Tesla electric car, and SpaceX rocket launch
    Elon Musk’s Tesla and SpaceX Still Hold Over 30,000 Bitcoin: Why Is He Not Selling?
    Is ‘Paul Le Roux’ Really Satoshi Nakamoto What the Record Actually Shows
    Is ‘Paul Le Roux’ Really Satoshi Nakamoto? What the Record Actually Shows
  • Opinion
    OpinionShow More
    Donald Trump speaking at a presidential podium with the White House and U.S. Capitol building in the background.
    Trump Just Declared the Super Intelligence Era in the “Unites States.” So Who Controls It?
    Comparison of Bybit 12-hour, Bitget 85-hour, and WazirX 463-day response timers
    Bitget, Bybit Paid in Hours; WazirX Lost Least in Hacks at $235M, Held Users Hostage for 463 Days
    Jackson Hole 2026: Crypto Is No Longer Outside the Fed’s Door
    Jackson Hole 2026: Crypto Is No Longer Outside the Fed’s Door
    The Architecture of Trust Same Routes, New Risks in Global Tokenisation
    The Architecture of Trust: Same Routes, New Risks in Global Tokenisation
    The Architecture of Trust What 4,000 Years of Trade Teach Us About RWA Tokenisation
    The Architecture of Trust: What 4,000 Years of Trade Teach Us About RWA Tokenisation
  • Learn
    • Explained
    • How To
    • Insights
  • IndicesNew
    • India USDT Premium Index
    • India USDC Premium Index
  • Videos
  • More
    • About Us
    • Our Authors
    • Contact Us
    • Editorial Policy
    • Daily Crypto Puzzles
The Crypto TimesThe Crypto Times
  • All News
  • Market
  • Bitcoin
  • Ethereum
  • Altcoins
  • Regulations & Policies
  • Blockchain
  • DeFi
  • Industry
  • Exclusive
  • Opinion
Search
  • News
    • Market
    • Bitcoin
    • Ethereum
    • Altcoins
    • Regulations & Policies
    • Price Analysis
    • Blockchain
    • DeFi
    • Industry
    • Exclusive
    • Opinion
  • Learn
    • Explained
    • How To
    • Insights
  • IndicesNew
    • India USDT Premium Index
    • India USDC Premium Index
  • Quick Links
    • About Us
    • Our Authors
    • Contact Us
    • Editorial Policy
    • AI Policy
    • Sponsored & Advertorial Policy
    • Daily Crypto Puzzles
  • Videos
  • Glossary
Follow US
© 2026 By Crypto Times. All Rights Reserved.
Market News

Mini Shai Hulud Malware Targets Crypto Wallets via npm Packages

The worm specifically targets cryptocurrency wallet files along with cloud credentials, SSH keys, and npm tokens, exfiltrating stolen data through the victim's own GitHub account.

Written By Dhara Chavda
Published 2026-05-12·Updated 5 months ago
Make The Crypto Times preferred on GoogleGoogle
Mini Shai Hulud Malware Targets Crypto Wallets via npm Packages
Show AI Summary
The Mini Shai-Hulud worm’s impact is expected to escalate as it continues to compromise JavaScript packages.
Blockchain security firm SlowMist’s critical threat alert warns of severe consequences for cryptocurrency wallets and cloud credentials.
TeamPCP’s attribution to the attack signals a significant escalation in supply chain operations, potentially leading to more severe breaches.

Blockchain security firm SlowMist has issued a critical threat intelligence alert on “Mini Shai-Hulud,” a self-propagating npm worm that has compromised more than 170 JavaScript packages — including foundational developer tools from TanStack, UiPath, Mistral AI, and DraftLab — to steal cryptocurrency wallets, cloud credentials, and CI/CD secrets at scale.

The alert, classified as severity “Critical” under identifier SM-2026-561840, was published alongside indicators of compromise, including malicious IP addresses and domains (git-tanstack[.]com, seed1[.]getsession[.]org) and a list of compromised package artifacts spanning the @tanstack, @uipath, @mistralai, @squawk, and @draftlab namespaces.

🚨 MistEye TI Alert 🚨

MistEye has detected a highly sophisticated npm worm, "Mini Shai-Hulud," spreading through trusted developer projects like TanStack, UiPath, and DraftLab. The attackers hijacked GitHub credentials to publish malicious, yet seemingly legitimate, package… pic.twitter.com/XPCDyavFtI

— SlowMist (@SlowMist_Team) May 12, 2026

The attack is attributed to the threat group TeamPCP, which has been escalating its supply chain operations since September 2025 — previously compromising Aqua Security’s Trivy vulnerability scanner in March 2026 and the Bitwarden CLI npm package in April 2026.

How the Worm Works

Unlike traditional npm malware that relies on typosquatting — publishing similarly named packages to trick developers — Mini Shai-Hulud hijacks the legitimate build pipeline itself. The attack chain, documented in detail by StepSecurity, Socket, Wiz, and Snyk, exploits a three-step vulnerability chain in GitHub Actions.

First, the attacker created a fork of the TanStack/router repository on May 10 using the GitHub account “voicproducoes,” deliberately renaming it to avoid appearing in fork-list searches. They then opened a pull request that triggered a pull_request_target workflow — a GitHub Actions trigger type that runs with base-repository permissions even for fork PRs — and used it to poison the shared GitHub Actions cache with a malicious pnpm dependency store.

When a legitimate maintainer PR was merged the next day, the release workflow restored the poisoned cache. The malicious code then extracted OIDC tokens directly from the GitHub Actions runner’s process memory and used them to publish malicious versions of the packages through the project’s own release pipeline.

The result: malicious packages published under the real TanStack namespace, from the real build infrastructure, with real cryptographic attestations.

First Npm Worm With Valid SLSA Provenance

In what security researchers are calling an unprecedented escalation, the compromised packages carry valid SLSA Build Level 3 provenance attestations — cryptographic certificates generated by Sigstore that are meant to verify a package was built from a trusted source. This means automated security scanners checking for provenance would have marked the malicious packages as legitimate.

“SLSA provenance confirms which pipeline produced the artifact, not whether the pipeline was behaving as intended,” StepSecurity’s analysis noted. The distinction is critical: if the build pipeline itself is compromised, every downstream trust check fails silently.

This is the first documented npm supply chain attack to produce validly attested malicious packages — a landmark failure of the current provenance verification model.

Crypto Wallets: A Primary Target

The worm’s payload — a heavily obfuscated 2.3 MB JavaScript file disguised as router_init.js — runs using the Bun JavaScript runtime specifically to evade Node.js-based security monitoring tools. Once executed, it aggressively harvests sensitive data from over 100 file paths.

Cryptocurrency assets are a primary target. The malware specifically searches for and exfiltrates wallet files and keys for Bitcoin, Ethereum, Monero, Zcash, Electrum, Exodus, Atomic Wallet, and others. It also targets browser extension data associated with MetaMask and Phantom. Beyond crypto, the payload harvests AWS, Azure, GCP, and Kubernetes credentials, SSH keys, VPN configurations, npm tokens, GitHub PATs, and even AI tool settings.

The stolen data is encrypted using AES-256-GCM and exfiltrated through three redundant channels: a typosquat domain (git-tanstack[.]com), the decentralized Session messenger network, and GitHub API dead drops—repositories created on the victim’s own account with the description “A Mini Shai-Hulud has Appeared.” The GitHub-native exfiltration is particularly insidious, as it blends with normal developer activity.

The Dead Man’s Switch

The worm includes a destructive failsafe mechanism. On developer machines, the malware installs a persistent daemon (via macOS LaunchAgent or Linux systemd) that polls GitHub every 60 seconds to check if stolen tokens are still valid. If it detects that a token has been revoked—a natural first step in incident response—the daemon triggers a destructive routine that attempts to execute rm -rf ~/, wiping the user’s entire home directory.

Security researchers have warned organizations not to revoke tokens until the infected machine is fully isolated, disconnected from the internet, and its drive has been imaged for forensic analysis—a counterintuitive but critical step.

Scale of the Blast Radius

The attack’s impact is enormous. @tanstack/react-router alone has approximately 12 million weekly downloads. Across all compromised namespaces, more than 25,000 repositories tied to hundreds of developers have been affected. The npm team is actively removing malicious versions, and TanStack maintainer Tanner Linsley has confirmed that the team shut down all publishing pipelines while investigating.

Critically, because many of the compromised packages are transitive dependencies, developers may be running the malicious code even if they never directly installed a TanStack package—simply because one of their other tools depends on it.

Socket detected and flagged the compromised artifacts within six minutes of publication. The attack has been assigned CVE-2026-45321.

Why Crypto Developers Are Especially Vulnerable

SlowMist emphasized that developers working on blockchain, DeFi, or Web3 projects are prime targets because their environments frequently store or interact with private keys, seed phrases, wallet.dat files, and signing credentials. A single compromised CI/CD pipeline can lead to drained wallets, unauthorized transactions, or downstream attacks on smart contracts and deployed infrastructure.

This is not a theoretical risk. In previous Shai-Hulud waves, the Trust Wallet team experienced a compromise linked to stolen credentials from the same worm family. The September 2025 npm supply chain attack — which compromised the Chalk package (2 billion weekly downloads) — injected code that replaced cryptocurrency wallet addresses at execution time, though financial losses were limited to approximately $500 due to a fortuitous crash in the attacker’s code.

The Mini Shai-Hulud campaign is significantly more sophisticated, with the self-propagation mechanism, valid provenance attestation, multi-channel exfiltration, and destructive failsafe representing a generational leap in supply chain attack capability.

Recommendations

SlowMist and multiple security firms urge immediate action for anyone who ran npm install on any @tanstack/, @uipath/, @mistralai/, @squawk/, or @draftlab/* package on or after May 11: treat the install environment as fully compromised. Rotate all credentials — GitHub tokens, npm accounts, cloud keys, SSH keys, and any cryptocurrency wallet seeds or private keys that may have been accessible. Audit CI/CD pipelines for the presence of router_init.js or suspicious preinstall hooks. Monitor for unauthorized GitHub repositories. Do not revoke tokens before isolating and imaging the machine.

Also Read: Bybit Uncovers macOS Malware Campaign Targeting Developers Searching for Claude Code

Disclaimer: The information researched and reported by The Crypto Times is for informational purposes only and is not a substitute for professional financial advice. Investing in crypto assets involves significant risk due to market volatility. Always Do Your Own Research (DYOR) and consult with a qualified Financial Advisor before making any investment decisions.

Follow The Crypto Times on Google News to Stay Updated!      Google News

Daily Crypto Puzzles
Tickerdle Tickerdle Crypto Connections Crypto Connections Crypto Crossword Crypto Crossword
TAGGED:BlockchainCrypto Scam
Share This Article
Whatsapp Whatsapp LinkedIn Telegram Copy Link

Daily Crypto Puzzles

Tickerdle crypto game Tickerdle Crypto Connections game Crypto Connections Crypto Crossword game Crypto Crossword

Latest News

DWF Labs Takes BitGo to Court Over $141M Token Lock-Up Dispute
DWF Labs Takes BitGo to Court Over $141M Token Lock-Up Dispute
BitBay and EtherVista logo display blocks in front of an illuminated metallic SlowMist logo on a dark wall
SlowMist Flags BitBay and EtherVista Hacks as Attackers Drain $32,600 From DeFi Vault & Pool
Netflix "The Altruists" series poster featuring Sam Bankman-Fried and Caroline Ellison characters
Netflix Revisits FTX’s $8B Scandal in ‘The Altruists’ Trailer
Starknet (STRK) Price Jumps 40.1% as Network Weighs Move Beyond Ethereum
Starknet (STRK) Price Jumps 40.1% as Network Weighs Move Beyond Ethereum
Physical MicroStrategy (MSTR) token coin standing on a reflective dark surface in front of a financial candlestick price chart
MSTR Stock Falls 11% From Weekly High as Bitcoin Rejects $87,000 for the Third Time

Find Us on Socials

You may also like

Physical gold Bitcoin (BTC) and silver Ethereum (ETH) coins standing side by side against a financial chart background

Bitcoin, Ethereum Options Expiry: $2.16B Settles Today as BTC Trades Below $84K Max Pain

Smartphone screen displaying the yellow Binance logo and wordmark against a blurred geometric background

Binance to Restrict 8 Services and Delist 22 Tokens in Brazil on October 27

White dimensional Lloyds Bank signage mounted on a green storefront fascia over brickwork

Lloyds Share Price Slips 1.66% to 100.60p: Why UK’s Most Tokenization-Forward Bank Matters to Crypto

White Citrini Research logo and text set against a dark blue gradient background

Citrini Says Agentic Finance Could Reshape Crypto Investing

The Crypto Times Logo PNG

News

All News
Market News
Bitcoin News
Ethereum News
Altcoin News
Regulations & Policies
DeFi News
Blockchain News
Industry News

Sections

Exclusive
Opinions
Learn
Insights
Videos
Glossary

India Premium Indices

Stablecoins
USDT
USDC

Play

Daily Crypto Puzzles
Tickerdle
Crypto Connections
Crypto Crossword

Company

About Us
Our Authors
Masthead
Editorial Policy
AI Policy
Advertorial Policy
Contact Us
Career

Follow Us

X-twitter Linkedin Telegram Youtube Instagram
© 2026 The Crypto Times | Protocols And Tokens Pvt Ltd.
DMCA.com Protection Status
  • Terms and Conditions
  • Disclaimer
  • Privacy Policy
  • Cookie policy
Do Not Sell or Share My Personal Information