Shai-Hulud Hades Payload Hits 20 Leo/RStreams npm Packages in Fresh Supply Chain Attack
ID: 322fe58f-e565-50d1-b725-302efe18e8ec
STIX ID: report--322fe58f-e565-50d1-b725-302efe18e8ec
Feed Name: GBHackers
Threat Score
JFrog Security Research identified a supply-chain malware wave from the Shai-Hulud/Hades family that infected 20 Leo/RStreams npm packages using an evasive binding.gyp execution technique; the payload harvests credentials, persists across multiple ecosystems, exfiltrates data via GitHub repositories, and includes propagation/seed mechanisms, with IOCs and recommended mitigation steps provided.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
