Mini Shai-Hulud
MITREOther
Unknown
Unknown
[Mini Shai-Hulud](https://attack.mitre.org/software/S9043) is a credential stealer and self-replicating supply chain worm, derived from [Shai-Hulud](https://attack.mitre.org/software/S9008), that has been used by [TeamPCP](https://attack.mitre.org/groups/G1056) to target Continuous Integration and Continuous Delivery/Deployment (CI/CD) workflows since at least 2026. [Mini Shai-Hulud](https://attack.mitre.org/software/S9043) can compromise credentials across multiple cloud, container, and AI configuration file paths and can use stolen npm and GitHub OIDC tokens to spread to other packages maintained by the compromised user. [Mini Shai-Hulud](https://attack.mitre.org/software/S9043) also has a targeted wiper component and has used multiple C2 and data exfiltration mechanisms.(Citation: Wiz Mini Shai-Hulud MAY 2026)(Citation: Trend Micro TeamPCP MAY 2026)(Citation: Hunt.io TeamPCP Toolkit MAY 2026)(Citation: Phoenix TeamPCP 20 MAY 2026)(Citation: Flashpoint Mini Shai-Hulud MAY 2026)(Citation: FBI TeamPCP JUL 2026)
Associated Techniques (55)
| ID | ATT&CK | Tactics |
|---|---|---|
| T1003.007 | Proc Filesystem | - |
| T1008 | Fallback Channels | - |
| T1016 | System Network Configuration Discovery | - |
| T1021.007 | Cloud Services | - |
| T1027.013 | Encrypted/Encoded File | - |
| T1033 | System Owner/User Discovery | - |
| T1036.005 | Match Legitimate Resource Name or Location | - |
| T1041 | Exfiltration Over C2 Channel | - |
| T1053.006 | Systemd Timers | - |
| T1059.006 | Python | - |
| T1059.007 | JavaScript | - |
| T1059.013 | Container CLI/API | - |
| T1070.004 | File Deletion | - |
| T1071.001 | Web Protocols | - |
| T1078.004 | Cloud Accounts | - |
Used by Actors (1)
Metadata
| ID: | 327645 |
| Created: | 06/08/2026 04:00 |
| Updated: | 09/08/2026 04:00 |