logo

Shai-Hulud copycat worm infects yet another npm package

ID: b5664f74-62e1-59e1-968b-59a6d53ddae9

STIX ID: report--b5664f74-62e1-59e1-968b-59a6d53ddae9

Feed Name: The Register (Security)

Threat Score
75/100

Date Published: 2026-05-18

Date Updated: 2026-05-18

...
...

A Shai-Hulud copycat and three additional credential-stealing npm packages were discovered masquerading as legitimate modules (chalk-tempalte, @deadcode09284814/axios-util, axois-utils, color-style-utils). The malware harvests SSH keys, environment variables, cloud credentials, crypto wallets, IP/geolocation data and, in one package, deploys a Go-based DDoS botnet; stolen data is exfiltrated to listed C2 domains and an IP. Researchers advise immediate uninstallation, key rotation, removal of malicious configurations, and searching repositories for related artifacts.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.