Scan to download
BTC $80,829.78 +0.10%
ETH $2,286.17 -1.94%
BNB $659.17 +1.22%
XRP $1.47 +1.27%
SOL $95.60 +0.80%
TRX $0.3494 -0.27%
DOGE $0.1097 +0.19%
ADA $0.2763 -0.28%
BCH $445.09 -1.22%
LINK $10.38 -1.81%
HYPE $41.29 -1.48%
AAVE $98.99 -1.28%
SUI $1.27 +1.67%
XLM $0.1661 -0.73%
ZEC $557.36 -2.61%
BTC $80,829.78 +0.10%
ETH $2,286.17 -1.94%
BNB $659.17 +1.22%
XRP $1.47 +1.27%
SOL $95.60 +0.80%
TRX $0.3494 -0.27%
DOGE $0.1097 +0.19%
ADA $0.2763 -0.28%
BCH $445.09 -1.22%
LINK $10.38 -1.81%
HYPE $41.29 -1.48%
AAVE $98.99 -1.28%
SUI $1.27 +1.67%
XLM $0.1661 -0.73%
ZEC $557.36 -2.61%

Slow Fog has detected the high-risk npm worm "Mini Shai-Hulud," which can steal CI/CD keys and encrypted wallet information

2026-05-12 15:31:47
Collection

According to the blockchain security organization SlowMist (@SlowMistTeam), a highly complex npm worm named "Mini Shai-Hulud" is spreading through well-known developer projects such as TanStack, UiPath, and DraftLab, as monitored by their threat monitoring system MistEye. Attackers hijack GitHub credentials to publish malicious packages disguised as legitimate updates, embedding a hidden script routerinit.js that runs silently in CI/CD environments like GitHub Actions, specifically designed to steal CI/CD keys, cloud infrastructure keys, and cryptocurrency wallet information, using GitHub's own infrastructure for data exfiltration.

SlowMist has synchronized relevant threat intelligence (IOC) with clients and recommends that projects using the affected packages immediately check their CI/CD pipelines for the presence of the router_init.js file, rotate all exposed GitHub, cloud service, and cryptocurrency credentials, and continuously monitor for abnormal background activities in the development environment.

app_icon
ChainCatcher Building the Web3 world with innovations.