logo

Shai-Hulud Hades Payload Hits 20 Leo/RStreams npm Packages in Fresh Supply Chain Attack

ID: 322fe58f-e565-50d1-b725-302efe18e8ec

STIX ID: report--322fe58f-e565-50d1-b725-302efe18e8ec

Feed Name: GBHackers

Threat Score
78/100

Date Published: 2026-06-25

Date Updated: 2026-06-25

Author: Mayura Kathir

...
...

JFrog Security Research identified a supply-chain malware wave from the Shai-Hulud/Hades family that infected 20 Leo/RStreams npm packages using an evasive binding.gyp execution technique; the payload harvests credentials, persists across multiple ecosystems, exfiltrates data via GitHub repositories, and includes propagation/seed mechanisms, with IOCs and recommended mitigation steps provided.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.