logo

Shai-Hulud malware worms Red Hat npm package versions downloaded 80K times a week

ID: a33a9e86-4ec7-5f4f-9883-d9d1cd24d3e9

STIX ID: report--a33a9e86-4ec7-5f4f-9883-d9d1cd24d3e9

Feed Name: The Register (Security)

Threat Score
80/100

Date Published: 2026-06-01

Date Updated: 2026-06-03

...
...

A supply-chain infection used compromised Red Hat npm package releases to deliver a Mini Shai-Hulud–style worm via npm preinstall hooks; the malware actively steals GitHub Actions secrets, npm tokens, cloud credentials (GCP and Azure), SSH and Git credentials, and includes encrypted exfiltration and propagation mechanisms. Researchers observed the infected packages being downloaded at scale (~80,000 downloads per week), declared the threat live, and reported the packages were removed while investigations continue.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.