Flashpoint. (2026, May 28). The Mini Shai-Hulud Worm and the New Era of CI/CD Exploitation. Retrieved July 16, 2026.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1003.007 Proc Filesystem |
MalwareMini Shai-Hulud | Mini Shai-Hulud has scraped runner process memory to extract short-lived identity tokens, which it then exchanged for per-package npm trusted-publisher tokens. |
| T1005 Data from Local System |
GroupTeamPCP | TeamPCP has stolen source code from victim environments including Mistral AI. |
| T1027.013 Encrypted/Encoded File |
MalwareMini Shai-Hulud | Mini Shai-Hulud has used a hybrid AES-256-GCM and RSA OAEP-SHA256 encryption to archive gathered data. Mini Shai-Hulud has also utilized custom MD5-keystream XOR cipher to encrypt data. Mini Shai-Hulud has also been deployed via an obfuscated script using Bun JavaScript runtime. |
| T1053.006 Systemd Timers |
MalwareMini Shai-Hulud | Mini Shai-Hulud has obtained persistence on Linux devices by writing the `gh-token-monitor` daemon within `~/.config/systemd/user/gh-token-monitor.service` that polls GitHub every 60 seconds. Mini Shai-Hulud has also leveraged a daemon called “kitty-monitor.service” to maintain persistence within Linux hosts. |
| T1059.007 JavaScript |
MalwareMini Shai-Hulud | Mini Shai-Hulud has leveraged JavaScript runtime to execute malicious scripts. |
| T1071.001 Web Protocols |
MalwareMini Shai-Hulud | Mini Shai-Hulud has has exfiltrated data through the use of HTTPS POST requests to C2 domains. |
| T1102.001 Dead Drop Resolver |
MalwareMini Shai-Hulud | Mini Shai-Hulud has leveraged GitHub commit-search API to recover fallback C2 domains stored in auto-created public Github repositories. |
| T1119 Automated Collection |
MalwareMini Shai-Hulud | Mini Shai-Hulud has the ability to automatically compile gathered credentials from configuration files and password vaults within an archive and exfiltrate stolen data leveraging both a primary and fallback C2. |
| T1176.002 IDE Extensions |
GroupTeamPCP | TeamPCP has compromised VS Code and Open VSX IDE extensions. |
| T1195.001 Compromise Software Dependencies and Development Tools |
GroupTeamPCP | TeamPCP has conducted coordinated supply chain attacks targeting open-source developer infrastructure including the NPM, VS Code, Docker, and PyPi ecosystems to compromise multiple software packages. Aikido TeamPCP Telnyx MAR 2026Aqua Security Trivy Compromise MAR 2026FBI TeamPCP JUL 2026Flashpoint Mini Shai-Hulud MAY 2026Google AI Threat Tracker MAY 2026Hunt.io TeamPCP Toolkit MAY 2026Palo Alto TeamPCP MAR 2026Phoenix TeamPCP 20 MAY 2026Trend Micro TeamPCP MAY 2026Wiz Mini Shai-Hulud MAY 2026Wiz TeamPCP KICS MAR 2026Wiz Trivy Compromise MAR 2026 |
| T1195.001 Compromise Software Dependencies and Development Tools |
MalwareMini Shai-Hulud | Mini Shai-Hulud has published itself on compromised victim code repositories to propagate malicious versions of packages to other victims. |
| T1485 Data Destruction |
MalwareMini Shai-Hulud | Mini Shai-Hulud has wiped data on devices that fall within specified parameters to include those that resolve to specific geolocations including Iran and Israel. Mini Shai-Hulud has also implemented a dead-man’s switch that wipes the victims home directory if the operator revokes a GitHub token created by the adversary. |
| T1528 Steal Application Access Token |
MalwareMini Shai-Hulud | Mini Shai-Hulud has stolen application access tokens and other tokens to include those associated with CI/CD. |
| T1543.002 Systemd Service |
MalwareMini Shai-Hulud | Mini Shai-Hulud has created .service files using Systemd on victim Linux hosts to establish persistence. |
| T1546 Event Triggered Execution |
MalwareMini Shai-Hulud | Mini Shai-Hulud has modified settings and configuration files of AI coding agents and other coding applications in order to create event triggered executions through creating hooks and runOn conditions. |
| T1550.001 Application Access Token |
MalwareMini Shai-Hulud | Mini Shai-Hulud has the ability to authenticate using stolen application access tokens. |
| T1552.001 Credentials In Files |
MalwareMini Shai-Hulud | Mini Shai-Hulud has collected credentials stored within configuration files. Mini Shai-Hulud has also gathered credentials from files stored in common credential file paths to include targeting git-credentials, azureProfile.json, and application_default_credentials.json. |
| T1552.004 Private Keys |
MalwareMini Shai-Hulud | Mini Shai-Hulud has gathered unsecured credentials to include SSH private keys within .ssh. |
| T1552.005 Cloud Instance Metadata API |
MalwareMini Shai-Hulud | Mini Shai-Hulud has gathered credentials and secrets from AWS, Google Cloud Platform (GCP) and Azure metadata API. |
| T1554 Compromise Host Software Binary |
MalwareMini Shai-Hulud | Mini Shai-Hulud has established persistence through modifying software binaries to include AI coding agents’ configuration or setting files that act as hooks, tasks or execution triggers. |
| T1555.006 Cloud Secrets Management Stores |
MalwareMini Shai-Hulud | Mini Shai-Hulud has captured credentials stored in cloud secret stores. |
| T1567.001 Exfiltration to Code Repository |
MalwareMini Shai-Hulud | Mini Shai-Hulud has exfiltrated data through the use of the victim’s own GitHub repository by creating a new public repository using a unique naming convention from a curated list of key words or themes. |
| T1583 Acquire Infrastructure |
GroupTeamPCP | In May 2026 TeamPCP announced co-ownership of the BreachForums cybercriminal forum claiming responsibility for platform operations, dispute resolution, personnel vetting, and hosting monetary contests. |
| T1657 Financial Theft |
GroupTeamPCP | TeamPCP has engaged in cryptocurrency mining and theft. TeamPCP has also partnered with ransomware and data theft extortion groups, sold leaked code, and crowdsourced supply chain compromises by open-sourcing their Mini Shai-Hulud malware. |
| T1677 Poisoned Pipeline Execution |
MalwareMini Shai-Hulud | Mini Shai-Hulud has utilized Github Actions to propagate through the use of triggered workflows. |
| T1677 Poisoned Pipeline Execution |
GroupTeamPCP | TeamPCP has compromised trusted CI/CD pipelines by injecting credential-stealing payloads into legitimate workflows and software packages including open-source security tools Trivy and KICS, and AI gateway LiteLLM. Aikido TeamPCP Telnyx MAR 2026Aqua Security Blog Trivy Compromise APR 2026Aqua Security Trivy Compromise MAR 2026FBI TeamPCP JUL 2026Flashpoint Mini Shai-Hulud MAY 2026Google AI Threat Tracker MAY 2026Hunt.io TeamPCP Toolkit MAY 2026Palo Alto TeamPCP MAR 2026Phoenix TeamPCP 20 MAY 2026Sysdig TeamPCP MAR 2026Trend Micro TeamPCP MAY 2026Wiz Mini Shai-Hulud MAY 2026Wiz TeamPCP KICS MAR 2026Wiz Trivy Compromise MAR 2026 |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.