Open Source · · 1 day

guardrails-ai PyPI package carried Shai-Hulud

JFrog listed 1 guardrails-ai PyPI package in the May 2026 Shai-Hulud wave. This record scopes those artifacts to their own official distribution surface.

Part of Shai-Hulud hits npm and PyPI campaign

guardrails-ai is the PyPI outlier in a campaign dominated by npm. JFrog listed guardrails-ai version 0.10.1 as part of the May 2026 Shai-Hulud wave, showing that TeamPCP's package-publisher focus was not limited to JavaScript.

The risk profile was still familiar. A Python package install can run in notebooks, CI jobs, build containers, and developer shells that hold cloud credentials, repository tokens, and package-registry secrets. Shai-Hulud's campaign logic treated those environments as credential sources first and application runtimes second.

This record keeps the PyPI package separate from the npm aggregate so Python dependency inventories have a precise indicator. The campaign page explains the shared actor, infrastructure, and propagation behavior; this page pins the package name, version, registry location, and May 11-12 exposure window.

For response, the useful question is whether any trusted environment installed guardrails-ai==0.10.1 during the window. A match should lead to credential rotation and review from a clean machine, especially for systems that also had package-publishing or CI authority.

Notes

  • The network and payload indicators are the campaign-level set JFrog published for this wave, not observations of this package's own bytes. Indicators read from an acquired sample are marked as such where they appear.
  • Minimal campaign-linked record created to keep Shai-Hulud package evidence scoped by vendor, organization, maintainer account, or package distribution surface.
  • Complete synthetic 0.10.1 sdist and wheel trees were reconstructed from registry-verified 0.10.0 distributions plus retained Socket diffs. The sdist matches all 185 Socket member hashes; the wheel matches all 186 in its RECORD.
  • Both stay named RECONSTRUCTED because their deterministic container hashes do not match the two authoritative original PyPI hashes recorded on the artifact.

Appendix · Affected releases

0.10.1 sha256 fc858321…4e6da7af download unavailable
  • Hash order is the complete malicious guardrails_ai-0.10.1-py3-none-any.whl and guardrails_ai-0.10.1.tar.gz. The audit script's archive-specific detector names both files and digests; these are not loader or transformers.pyz hashes.

Indicators

  • file_sha256__init__.py 2a314ea8be337e1ca9ec833ed13ed854d9fd38bce0a519cf288f3bec8d9e6f30
  • file_sha256transformers.pyz 5245eb032e336b85cff0dbb3450d591826bf2ef214fd30d7eba1a763664e151b
  • ipv483.142.209.194
  • urlhttp://83.142.209.194/transformers.pyz
  • urlhttp://83.142.209.194/v1/models
  • urlhttp://83.142.209.194/v1/weights
  • urlhttp://83.142.209.194/audio.mp3
  • file/tmp/transformers.pyz
  • file~/.local/bin/pgmonitor.py
  • file/etc/systemd/system/pgsql-monitor.service
  • stringShai-Hulud: Here We Go Again
  • stringFIRESCALE

References

  1. Shai-Hulud: Here We Go Again - Worm by TeamPCP Hits NPM and PyPIresearch.jfrog.com
  2. Over 100 npm, PyPI Packages Hit in New Shai-Hulud Supply Chain Attacks - SecurityWeeksecurityweek.com
  3. Mini Shai-Hulud Is Back: npm Worm Hits over 160 Packages, including Mistral and Tanstack - Aikidoaikido.dev
  4. Malicious code in guardrails-ai 0.10.1 - Guardrails AI security advisorygithub.com
  5. Mini Shai-Hulud archive and payload audit scriptgist.github.com
  6. Retained current PyPI project metadata showing the quarantined 0.10.1 release is absentpypi.org
  7. Retained OSV record for the Guardrails AI compromiseapi.osv.dev
  8. Retained Guardrails AI incident timeline and remediation advisoryraw.githubusercontent.com
  9. Guardrails AI issue tracking PyPI quarantine and restorationgithub.com
  10. Retained Socket overview for malicious guardrails-ai 0.10.1socket.dev
  11. Retained Socket source-distribution diff from guardrails-ai 0.10.0 to 0.10.1socket.dev
  12. Retained Socket file record for the injected guardrails-ai 0.10.1 loadersocket.dev
  13. Retained PyPI metadata for clean guardrails-ai 0.10.0pypi.org
  14. Retained Socket source-distribution member listing for clean guardrails-ai 0.10.0socket.dev
  15. Retained Socket source-distribution member listing for malicious guardrails-ai 0.10.1socket.dev
  16. Retained Socket API source-distribution member listing for malicious guardrails-ai 0.10.1socket.dev
  17. Retained Socket wheel member listing for clean guardrails-ai 0.10.0socket.dev
  18. Socket API wheel-list attempt that returned the source-distribution listingsocket.dev
  19. Retained Socket wheel diff from guardrails-ai 0.10.0 to 0.10.1socket.dev

Source record: oss/attacks/shai-hulud-guardrails-ai-pypi/meta.yaml