Find notable cyber news and cases, enriched with sources, timelines, and signals.

Shai-Hulud worm clone activity on NPM

Malware Activity
First reported
Last updated
Happening score
H score 69
4 unique sources, 7 articles

Summary

Hide ▲

The Shai-Hulud malware activity has continued to evolve across the npm supply chain and related developer ecosystems. It first infected npm packages in September 2025, self-replicated through developer installs, and stole npm tokens, SSH keys, API keys, and other secrets before publishing stolen credentials in public GitHub repositories. In November 2025, the campaign expanded into Maven through org.mvnpm:posthog-node:4.18.1, with the same payload components linked to compromised PostHog releases and more than 28,000 affected repositories. A later May 2026 wave showed clone activity after TeamPCP released the malware source code, including malicious NPM packages that targeted Axios users, reused worm logic, and in one case pulled infected machines into a DDoS botnet.

Related Happenings

AsyncAPI malicious npm package supply-chain malware

Malware Activity
H score21 First: 15.07.2026 18:37 Last: 15.07.2026 18:37 Sources 1

About this happening: Malicious AsyncAPI npm releases pushed a remote access trojan and info-stealing payload into packages with more than 2.25 million weekly downloads, putting downstr...

AsyncAPI repositories and npm publishing workflow hit by network compromise

Incident
H score27 First: 15.07.2026 12:16 Last: 15.07.2026 12:16 Sources 1

About this happening: The AsyncAPI npm publishing pipeline was compromised in a July 14 supply-chain attack that used the project’s normal GitHub Actions release path to publish trojani...

Lucide proxy npm packages browser DDoS botnet

Malware Activity
H score31 First: 14.07.2026 10:08 Last: 14.07.2026 10:08 Sources 1

About this happening: A 148-package npm campaign turned visitor browsers into a distributed denial-of-service botnet, turning ordinary proxy-page visits into attack traffic. The browser payload...

Jscrambler hit by network compromise

Incident
H score15 First: 13.07.2026 22:44 Last: 13.07.2026 22:44 Sources 1

About this happening: The Jscrambler npm package suffered an unauthorized publication of a malicious version that exposed developers to infostealer theft risk. The bad release stayed li...

@Injectivelabs/[email protected] wallet-stealing package

Malware Activity
H score30 First: 10.07.2026 20:29 Last: 10.07.2026 20:29 Sources 1

About this happening: The malicious @injectivelabs/[email protected] package is a wallet-stealing malware activity that can expose private keys and mnemonic seed phrases when library functions...

Timeline

  1. 18.05.2026 12:45 3 articles · 1mo ago

    Shai-Hulud clones and malicious NPM packages surface after source-code release

    Initial Disclosure

    Shai-Hulud worm clones surfaced on GitHub only days after TeamPCP released the malware source code, and a threat actor published four malicious NPM packages targeting Axios users and the broader open source package ecosystem. One package, 'chalk-tempalte', was a direct clone of the worm and used its own C&C server and private key, while the others used typosquatting; the code stole credentials, API keys, tokens, and other secrets, republished malicious versions through victim-maintained packages, and in one case pulled infected machines into a DDoS botnet. The four packages had a combined weekly download count of over 2,600.

    Show sources
  2. 26.11.2025 20:08 2 articles · 7mo ago

    Shai-Hulud v2 expands from npm into Maven

    Campaign Scope Update

    Shai-Hulud v2 expanded from npm into Maven after a mirrored Maven Central artifact, org.mvnpm:posthog-node:4.18.1, was found to embed setup_bun.js and bun_environment.js, the same payload components linked to the wider campaign; the activity was also tied to compromised PostHog releases in both JavaScript/npm and Java/Maven ecosystems and to more than 28,000 affected repositories.

    Show sources
  3. 23.09.2025 12:20 1 articles · 9mo ago

    GitHub hardens npm publishing after Shai-Hulud

    Mitigation Patch Update

    GitHub is tightening npm authentication and publishing controls in response to the Shai-Hulud supply-chain worm, deprecating legacy classic tokens and TOTP 2FA, shortening granular publishing tokens to seven days, defaulting publishing to trusted publishing or 2FA-enforced local publishing, removing the option to bypass 2FA, and expanding trusted publishing providers.

    Show sources
  4. 16.09.2025 17:08 1 articles · 10mo ago

    Shai-Hulud worm first compromises NPM packages

    Exploitation Observed

    Shai-Hulud infected NPM packages and began self-replicating through developer installs, stealing npm tokens, SSH keys, API keys, and other secrets before publishing stolen credentials in public GitHub repositories. The first compromised NPM package was altered around 17:58 UTC on Sept. 14, and CrowdStrike-managed packages were briefly affected before malicious versions were removed.

    Show sources