logo

Shai-Hulud Payload Steals GitHub, npm, Cloud, CI/CD, and SSH Credentials From Developers

ID: d93284d4-7e9b-5ce2-8d46-652389e47036

STIX ID: report--d93284d4-7e9b-5ce2-8d46-652389e47036

Feed Name: cybersecurityNews.com

Threat Score
80/100

Date Published: 2026-06-25

Date Updated: 2026-06-25

Author: Tushar Subhra Dutta

...
...

A wave of malicious npm packages (Shai-Hulud / Hades) targeting the Leo/RStreams ecosystem has been observed stealing GitHub, npm, cloud, CI/CD, and SSH credentials during installation by abusing binding.gyp/node-gyp execution; the payload persists via systemd/LaunchAgent and AI-tool hooks, attempts lateral movement, exfiltrates encrypted results to attacker-controlled GitHub repositories (dead-drop), and has been downloaded tens of thousands of times — the report provides extensive IoCs and remediation steps including isolation, artifact removal, and credential rotation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.