logo

Shai-Hulud Is Back, and This Time It Ate the Whole Ecosystem

ID: ad7bab8b-fdcc-570a-8a15-1c151e3cfc2e

STIX ID: report--ad7bab8b-fdcc-570a-8a15-1c151e3cfc2e

Feed Name: TrustedSec blog

Threat Score
92/100

Date Published: 2026-05-21

Date Updated: 2026-05-23

...
...

Shai-Hulud is a widespread npm supply-chain campaign that compromised the atool account to push malicious preinstall/postinstall hooks across 300+ AntV ecosystem packages (impacting tens of millions of downloads). The payload harvests CI and local secrets (including scraping /proc memory for ACTIONS_ variables), sweeps hundreds of credential locations, exfiltrates via GitHub API dead-drops and a fallback OpenTelemetry-like C2 domain, and installs persistent VS Code/Claude backdoors; the report provides IOCs, hunt queries, detection rules, and step-by-step remediation (pin/downgrade, rotate credentials after cleanup, rebuild runners).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.