Malicious npm Packages Steal SSH Keys, Cloud Credentials, and Crypto Wallets
ID: 3c18175b-77b8-58f7-802e-f359793e0bc1
STIX ID: report--3c18175b-77b8-58f7-802e-f359793e0bc1
Feed Name: GBHackers
## Executive Summary A supply-chain campaign in the npm ecosystem deployed four malicious typosquatted packages that immediately exfiltrate sensitive data (SSH keys, cloud credentials, env vars, crypto wallets), include a cloned Shai-Hulud infostealer variant, and one package installs a Go-based bot for DDoS; attacker C2 domains and repository exfiltration paths are documented and developers are advised to uninstall, rotate credentials, and scan for indicators such as the string "A Mini Sha1-Hulud has Appeared".
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
