600+ npm Packages Hit in Mini Shai-Hulud Supply Chain Attack
ID: f3736a03-3dbc-59f9-92ee-9b59def18a19
STIX ID: report--f3736a03-3dbc-59f9-92ee-9b59def18a19
Feed Name: Cyber Press
On May 19, 2026 a sophisticated supply-chain worm rapidly compromised hundreds of npm package versions (Socket/Endor Labs observed 600+ in one wave and 1,055 versions across 502 packages across ecosystems) by injecting obfuscated preinstall payloads and phantom-commit optionalDependencies; the implant daemonizes, harvests cloud and CI credentials (IMDSv2, ECS metadata, GCP keys, Vault tokens, GitHub OIDC), persists outside node_modules, exfiltrates data to filev2.getsession.org and GitHub repositories, and abuses Sigstore to produce cryptographically valid provenance attestations that make malicious packages appear legitimate.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
