logo

Malicious npm Packages Steal SSH Keys, Cloud Credentials, and Crypto Wallets

ID: 3c18175b-77b8-58f7-802e-f359793e0bc1

STIX ID: report--3c18175b-77b8-58f7-802e-f359793e0bc1

Feed Name: GBHackers

Threat Score
75/100

Date Published: 2026-05-18

Date Updated: 2026-05-18

Author: Mayura Kathir

...
...

## Executive Summary A supply-chain campaign in the npm ecosystem deployed four malicious typosquatted packages that immediately exfiltrate sensitive data (SSH keys, cloud credentials, env vars, crypto wallets), include a cloned Shai-Hulud infostealer variant, and one package installs a Go-based bot for DDoS; attacker C2 domains and repository exfiltration paths are documented and developers are advised to uninstall, rotate credentials, and scan for indicators such as the string "A Mini Sha1-Hulud has Appeared".

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.