logo

600+ npm Packages Hit in Mini Shai-Hulud Supply Chain Attack

ID: f3736a03-3dbc-59f9-92ee-9b59def18a19

STIX ID: report--f3736a03-3dbc-59f9-92ee-9b59def18a19

Feed Name: Cyber Press

Threat Score
92/100

Date Published: 2026-05-20

Date Updated: 2026-05-20

Author: Lucas Martin

...
...

On May 19, 2026 a sophisticated supply-chain worm rapidly compromised hundreds of npm package versions (Socket/Endor Labs observed 600+ in one wave and 1,055 versions across 502 packages across ecosystems) by injecting obfuscated preinstall payloads and phantom-commit optionalDependencies; the implant daemonizes, harvests cloud and CI credentials (IMDSv2, ECS metadata, GCP keys, Vault tokens, GitHub OIDC), persists outside node_modules, exfiltrates data to filev2.getsession.org and GitHub repositories, and abuses Sigstore to produce cryptographically valid provenance attestations that make malicious packages appear legitimate.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.