Home ยท Wiki ยท Incidents & Campaigns
type: incident ยท created: 2026-09-04 ยท updated: 2026-09-04 ยท tags: ยท confidence: reported ยท severity: medium ยท affected_sectors: ยท au_impact: true

Shai-Hulud Infostealer Expands to 469 Credential Locations

Incident note โ€” 3 September 2026

On 3 September 2026, GitGuardian reported that a recent variant of the Shai-Hulud infostealer worm has significantly expanded its credential-hunting scope. The variant now scans for credentials across 469 locations in developer environments, CI/CD tooling, cloud configurations and AI tool configuration files โ€” up from the previous 189 paths.

Coverage shifts are notable: Linux locations have risen from 89 to 290, reflecting a deliberate expansion beyond its historical focus. New cloud targets include Hetzner, Alibaba Cloud and Tencent Cloud, broadening the tool's applicability to providers popular outside the traditional Western cloud fleet.

Given the worm's self-propagating nature and its focus on developer and CI/CD systems, the credential theft risk to technology supply chains is significant, including for Australian development teams who use the affected cloud and AI tooling.