Threat Actors Testing Modified and Highly Obfuscated Version of Shai Hulud Strain
ID: 04a94772-f430-5ae4-9aaa-fd3bb4ac18e8
STIX ID: report--04a94772-f430-5ae4-9aaa-fd3bb4ac18e8
Feed Name: cybersecurityNews.com
Threat Score
Aikido researchers identified a new Shai Hulud malware variant that infects JavaScript development environments via compromised packages and supply-chain propagation to steal API keys, environment variables, and repository data; the variant shows deliberate obfuscation, functional refinements (e.g., bun installer naming, Windows bun.exe handling), and removal of a dead-man switch, implying active development by actors with access to the original source.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
