Skip to content
SlowMist Detects High-Risk npm Worm Stealing Crypto Information

SlowMist Detects High-Risk npm Worm Stealing Crypto Information

Kucoin • May 12, 2026

According to SlowMist monitoring, the npm worm named "Mini Shai-Hulud" spreads through projects such as TanStack and UiPath, hijacking GitHub credentials to publish malicious packages and steal CI/CD keys, cloud service credentials, and cryptocurrency wallet information. SlowMist recommends affected projects inspect the router_init.js file, rotate exposed credentials, and monitor for suspicious activity.

Extracted Entities

Attack Types (2)

Malware (1)

Platforms (1)

Tools (1)