Gold Open Source
ExplorePackagesVulnerabilitiesCWEsMCP ServersScan
Login
Gold Open Source

The authoritative source for production-ready open-source components. Every package, container image, AI model, and MCP server undergoes rigorous verification for security, malware, and license compliance.

Explore Gold

  • Explore Everything
  • Packages
  • Gold Certified Packages
  • Container Images
  • AI Models
  • MCP Servers
  • Agent Skills
  • Chip Manufacturers

Security Data & Tools

  • Scan Your Dependencies
  • Trending Threats
  • Threat RSS Feeds
  • CVE Database
  • Actively Exploited (KEV)
  • SGZ Zero-Days
  • CWE Index
  • MITRE ATT&CK
  • Malicious Packages
  • Security Glossary
  • Supply-Chain Report
  • Developers (API & Badge)
  • Chrome Extension
  • Credits & Data Sources

Products

  • The Platform
  • ESSCM
  • Portal
  • TPRM
  • OSM
  • Cowork
  • Code / Runner
  • Guard

Use Cases

  • Know Your Software
  • Auto-Fix Vulnerabilities
  • Asset Discovery
  • AI Governance
  • MCP Server Security
  • Supply Chain Compliance
  • Zero-Day Discovery
  • All Use Cases

Company

  • About
  • Pricing
  • Blog
  • Documentation
  • Safeguard Academy
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 Gold Open Source. All rights reserved.

Built with care bySafeguard
Home/ATT&CK/Software/S9043
MITRE ATT&CK Malware

Mini Shai-Hulud (S9043)

ShareXLinkedInRedditHN

[Mini Shai-Hulud](https://attack.mitre.org/software/S9043) is a credential stealer and self-replicating supply chain worm, derived from [Shai-Hulud](https://attack.mitre.org/software/S9008), that has been used by [TeamPCP](https://attack.mitre.org/groups/G1056) to target Continuous Integration and Continuous Delivery/Deployment (CI/CD) workflows since at least 2026. [Mini Shai-Hulud](https://attack.mitre.org/software/S9043) can compromise credentials across multiple cloud, container, and AI configuration file paths and can use stolen npm and GitHub OIDC tokens to spread to other packages maintained by the compromised user. [Mini Shai-Hulud](https://attack.mitre.org/software/S9043) also has a targeted wiper component and has used multiple C2 and data exfiltration mechanisms.(Citation: Wiz Mini Shai-Hulud MAY 2026)(Citation: Trend Micro TeamPCP MAY 2026)(Citation: Hunt.io TeamPCP Toolkit MAY 2026)(Citation: Phoenix TeamPCP 20 MAY 2026)(Citation: Flashpoint Mini Shai-Hulud MAY 2026)(Citation: FBI TeamPCP JUL 2026)

Platforms: Containers, IaaS, Linux, macOS, SaaS, Windows

▪Techniques implemented (55)

T1543.001Launch AgentT1090.003Multi-hop ProxyT1078.004Cloud AccountsT1546.018Python Startup HooksT1140Deobfuscate/Decode Files or InformationT1033System Owner/User DiscoveryT1016System Network Configuration DiscoveryT1560.001Archive via UtilityT1083File and Directory DiscoveryT1564.011Ignore Process InterruptsT1036.005Match Legitimate Resource Name or LocationT1205Traffic SignalingT1552.007Container APIT1059.013Container CLI/APIT1087.004Cloud AccountT1560Archive Collected DataT1614System Location DiscoveryT1213.003Code RepositoriesT1059.006PythonT1082System Information DiscoveryT1614.001System Language DiscoveryT1480Execution GuardrailsT1497.001System ChecksT1132.001Standard EncodingT1555.005Password ManagersT1021.007Cloud ServicesT1041Exfiltration Over C2 ChannelT1008Fallback ChannelsT1124System Time DiscoveryT1105Ingress Tool TransferT1059.007JavaScriptT1027.013Encrypted/Encoded FileT1528Steal Application Access TokenT1550.001Application Access TokenT1195.001Compromise Software Dependencies and Development ToolsT1003.007Proc FilesystemT1677Poisoned Pipeline ExecutionT1555.006Cloud Secrets Management StoresT1552.001Credentials In FilesT1552.004Private KeysT1552.005Cloud Instance Metadata APIT1567.001Exfiltration to Code RepositoryT1071.001Web ProtocolsT1102.001Dead Drop ResolverT1053.006Systemd TimersT1543.002Systemd ServiceT1554Compromise Host Software BinaryT1119Automated CollectionT1609Container Administration CommandT1485Data DestructionT1559Inter-Process CommunicationT1497Virtualization/Sandbox EvasionT1070.004File DeletionT1649Steal or Forge Authentication CertificatesT1546Event Triggered Execution

▪Used by groups (1)

G1056TeamPCP
S9043on MITRE ATT&CK →

MITRE ATT&CK® is a registered trademark of The MITRE Corporation. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation.