logo

Threat Actors Testing Modified and Highly Obfuscated Version of Shai Hulud Strain

ID: 04a94772-f430-5ae4-9aaa-fd3bb4ac18e8

STIX ID: report--04a94772-f430-5ae4-9aaa-fd3bb4ac18e8

Feed Name: cybersecurityNews.com

Threat Score
70/100

Date Published: 2026-01-02

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

Aikido researchers identified a new Shai Hulud malware variant that infects JavaScript development environments via compromised packages and supply-chain propagation to steal API keys, environment variables, and repository data; the variant shows deliberate obfuscation, functional refinements (e.g., bun installer naming, Windows bun.exe handling), and removal of a dead-man switch, implying active development by actors with access to the original source.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.