Open Source · · 1 day

nextmove-mcp npm package carried Shai-Hulud

JFrog listed 1 nextmove-mcp npm package in the May 2026 Shai-Hulud wave. This record scopes those artifacts to their own official distribution surface.

Part of Shai-Hulud hits npm and PyPI campaign

nextmove-mcp was one of the MCP-related package names caught in the May 2026 Shai-Hulud wave. JFrog listed five affected npm releases under the nextmove-mcp name during the May 11-12 TeamPCP window.

MCP and agent packages often run close to developer automation, local credentials, and service integrations. That made them useful distribution surfaces for Shai-Hulud: the malware did not need to compromise an application server if it could execute during package installation on a machine that already held tokens.

This page keeps nextmove-mcp separate from the campaign rollup so responders have a concrete inventory indicator. The campaign record explains the shared loader, infrastructure, credential theft, and propagation behavior; this record preserves the package name, affected releases, dates, and npm URLs.

Any matching install should be treated as host exposure. Build caches, local npm caches, lockfiles, and CI logs are all relevant evidence because the payload's opportunity was the install event itself, not long-term use of the package.

Notes

  • The network and payload indicators are the campaign-level set JFrog published for this wave, not observations of this package's own bytes. Indicators read from an acquired sample are marked as such where they appear.
  • These indicators were read from the acquired sample. The reconstruction of nextmove-mcp 0.1.7 holds setup.mjs as the preinstall script: it picks a Bun build per platform, downloads it from oven-sh/bun, and runs router_init.js.
  • No command-and-control host appears in setup.mjs. The address lives in router_init.js, the one member socket.dev could no longer serve, so the capture is payload_only and the C2 for this wave stays unrecovered.
  • The payload is not the one recorded for [[antv-npm]], although both carry the shai-hulud-here-we-go-again campaign: the antv wave beacons to t.m-kosche.com and none of its markers appear here. Indicators are kept per attack.

Appendix · Affected releases

0.1.7 sha256 1cfe3954…dca6f33e download unavailable
0.1.6 sha256 d69d9366…25730c07 download unavailable
0.1.5 sha256 2b9e1c82…364c50c9 download unavailable
0.1.4 sha256 cfbb071d…683ecb27 download unavailable
0.1.3 sha256 c543ffcc…5eb39bdb download unavailable

Indicators

  • file_sha256npm payload 29c729852fce5a53e30a1541d9fec79c915b2e13f1eda94a5978cf0aae0d88d9
  • file_sha256npm payload 2ec78d556d696e208927cc503d48e4b5eb56b31abc2870c2ed2e98d6be27fc96
  • file_sha256npm payload ab4fcadaec49c03278063dd269ea5eef82d24f2124a8e15d7b90f2fa8601266c
  • file_sha256npm payload d4a2086ea18f5e39cd867b8b06918a524eabb21d45ea98aad07357b98173458a
  • urlhttps://filev2.getsession.org/file/
  • domainseed1.getsession.org
  • domainseed2.getsession.org
  • domainseed3.getsession.org
  • domainapi.masscan.cloud
  • file~/.local/bin/gh-token-monitor.sh
  • file~/.config/systemd/user/gh-token-monitor.service
  • file~/Library/LaunchAgents/com.user.gh-token-monitor.plist
  • file~/.config/gh-token-monitor/
  • stringShai-Hulud: Here We Go Again
  • stringPUSH UR T3MPRR
  • stringFIRESCALE
  • commit_author[email protected]
  • filesetup.mjs
  • filerouter_init.js
  • commandnode setup.mjs
  • urlhttps://github.com/oven-sh/bun/releases/download/bun-v1.3.13/

References

  1. Shai-Hulud: Here We Go Again - Worm by TeamPCP Hits NPM and PyPIresearch.jfrog.com
  2. TanStack npm Packages Compromised in Ongoing Mini Shai-Hulud Supply Chain Attack - Socketsocket.dev
  3. Mini Shai-Hulud Is Back: npm Worm Hits over 160 Packages, including Mistral and Tanstack - Aikidoaikido.dev
  4. TanStack/router incident issue 7383github.com
  5. Software Heritage origin record for the deleted zblgg/configuration forkarchive.softwareheritage.org
  6. Hybrid Analysis report for router_init.js SHA-256 ab4fcadahybrid-analysis.com

Source record: oss/attacks/shai-hulud-nextmove-mcp-npm/meta.yaml