logo

Four Malicious npm Packages Steal SSH Keys, Cloud Credentials, and Crypto Wallets

ID: 413aa70f-13a0-5a9b-9524-cbfcfaa9ed91

STIX ID: report--413aa70f-13a0-5a9b-9524-cbfcfaa9ed91

Feed Name: cybersecurityNews.com

Threat Score
78/100

Date Published: 2026-05-18

Date Updated: 2026-05-22

Author: Guru Baran

...
...

Four malicious npm packages distributed via typosquatting (chalk-tempalte, @deadcode09284814/axios-util, axois-utils, and color-style-utils) were discovered to contain infostealers and a Go-based DDoS bot; one package is a near-identical weaponization of the recently leaked Shai-Hulud source. All versions are considered malicious, with active C2 domains/IPs listed, approximately 2,678 weekly downloads combined, and immediate remediation actions recommended (uninstall, rotate credentials, block IOCs).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.