logo

Shai-Hulud worm copycats emerge after source code leak

ID: f6c4dafe-7ffc-5291-961f-b81f3f8794e0

STIX ID: report--f6c4dafe-7ffc-5291-961f-b81f3f8794e0

Feed Name: Security Affairs

Threat Score
75/100

Date Published: 2026-05-19

Date Updated: 2026-05-19

Author: Pierluigi Paganini

...
...

The Shai-Hulud worm's source code leak has enabled rapid reuse: researchers observed copycat NPM packages (including chalk-tempalte, axois-utils, color-style-utils, and @deadcode09284814/axios-util) that steal developer credentials, upload stolen data to GitHub, and in one instance attempt to recruit systems into a DDoS botnet; the leak increases supply-chain and typo-squatting risk and defenders are urged to monitor dependencies and secure developer tokens and CI/CD credentials.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.