Open Source · · 1 day
guardrails-ai PyPI package carried Shai-Hulud
JFrog listed 1 guardrails-ai PyPI package in the May 2026 Shai-Hulud wave. This record scopes those artifacts to their own official distribution surface.
Part of Shai-Hulud hits npm and PyPI campaign
guardrails-ai is the PyPI outlier in a campaign dominated by npm. JFrog listed guardrails-ai version 0.10.1 as part of the May 2026 Shai-Hulud wave, showing that TeamPCP's package-publisher focus was not limited to JavaScript.
The risk profile was still familiar. A Python package install can run in notebooks, CI jobs, build containers, and developer shells that hold cloud credentials, repository tokens, and package-registry secrets. Shai-Hulud's campaign logic treated those environments as credential sources first and application runtimes second.
This record keeps the PyPI package separate from the npm aggregate so Python dependency inventories have a precise indicator. The campaign page explains the shared actor, infrastructure, and propagation behavior; this page pins the package name, version, registry location, and May 11-12 exposure window.
For response, the useful question is whether any trusted environment installed guardrails-ai==0.10.1 during the window. A match should lead to credential rotation and review from a clean machine, especially for systems that also had package-publishing or CI authority.
Notes
- The network and payload indicators are the campaign-level set JFrog published for this wave, not observations of this package's own bytes. Indicators read from an acquired sample are marked as such where they appear.
- Minimal campaign-linked record created to keep Shai-Hulud package evidence scoped by vendor, organization, maintainer account, or package distribution surface.
- Complete synthetic 0.10.1 sdist and wheel trees were reconstructed from registry-verified 0.10.0 distributions plus retained Socket diffs. The sdist matches all 185 Socket member hashes; the wheel matches all 186 in its RECORD.
- Both stay named RECONSTRUCTED because their deterministic container hashes do not match the two authoritative original PyPI hashes recorded on the artifact.
Appendix · Affected releases
- Hash order is the complete malicious guardrails_ai-0.10.1-py3-none-any.whl and guardrails_ai-0.10.1.tar.gz. The audit script's archive-specific detector names both files and digests; these are not loader or transformers.pyz hashes.
Indicators
- file_sha256__init__.py 2a314ea8be337e1ca9ec833ed13ed854d9fd38bce0a519cf288f3bec8d9e6f30
- file_sha256transformers.pyz 5245eb032e336b85cff0dbb3450d591826bf2ef214fd30d7eba1a763664e151b
- ipv483.142.209.194
- urlhttp://83.142.209.194/transformers.pyz
- urlhttp://83.142.209.194/v1/models
- urlhttp://83.142.209.194/v1/weights
- urlhttp://83.142.209.194/audio.mp3
- file/tmp/transformers.pyz
- file~/.local/bin/pgmonitor.py
- file/etc/systemd/system/pgsql-monitor.service
- stringShai-Hulud: Here We Go Again
- stringFIRESCALE
References
- Shai-Hulud: Here We Go Again - Worm by TeamPCP Hits NPM and PyPIresearch.jfrog.com
- Over 100 npm, PyPI Packages Hit in New Shai-Hulud Supply Chain Attacks - SecurityWeeksecurityweek.com
- Mini Shai-Hulud Is Back: npm Worm Hits over 160 Packages, including Mistral and Tanstack - Aikidoaikido.dev
- Malicious code in guardrails-ai 0.10.1 - Guardrails AI security advisorygithub.com
- Mini Shai-Hulud archive and payload audit scriptgist.github.com
- Retained current PyPI project metadata showing the quarantined 0.10.1 release is absentpypi.org
- Retained OSV record for the Guardrails AI compromiseapi.osv.dev
- Retained Guardrails AI incident timeline and remediation advisoryraw.githubusercontent.com
- Guardrails AI issue tracking PyPI quarantine and restorationgithub.com
- Retained Socket overview for malicious guardrails-ai 0.10.1socket.dev
- Retained Socket source-distribution diff from guardrails-ai 0.10.0 to 0.10.1socket.dev
- Retained Socket file record for the injected guardrails-ai 0.10.1 loadersocket.dev
- Retained PyPI metadata for clean guardrails-ai 0.10.0pypi.org
- Retained Socket source-distribution member listing for clean guardrails-ai 0.10.0socket.dev
- Retained Socket source-distribution member listing for malicious guardrails-ai 0.10.1socket.dev
- Retained Socket API source-distribution member listing for malicious guardrails-ai 0.10.1socket.dev
- Retained Socket wheel member listing for clean guardrails-ai 0.10.0socket.dev
- Socket API wheel-list attempt that returned the source-distribution listingsocket.dev
- Retained Socket wheel diff from guardrails-ai 0.10.0 to 0.10.1socket.dev
Source record: oss/attacks/shai-hulud-guardrails-ai-pypi/meta.yaml