Shai-Hulud Payload Steals GitHub, npm, Cloud, CI/CD, and SSH Credentials From Developers
ID: d93284d4-7e9b-5ce2-8d46-652389e47036
STIX ID: report--d93284d4-7e9b-5ce2-8d46-652389e47036
Feed Name: cybersecurityNews.com
A wave of malicious npm packages (Shai-Hulud / Hades) targeting the Leo/RStreams ecosystem has been observed stealing GitHub, npm, cloud, CI/CD, and SSH credentials during installation by abusing binding.gyp/node-gyp execution; the payload persists via systemd/LaunchAgent and AI-tool hooks, attempts lateral movement, exfiltrates encrypted results to attacker-controlled GitHub repositories (dead-drop), and has been downloaded tens of thousands of times — the report provides extensive IoCs and remediation steps including isolation, artifact removal, and credential rotation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
