logo

170 npm Packages Hijacked to Steal GitHub, AWS & Kubernetes Secrets

ID: 6a7b16b6-b14c-5fbb-8dc5-1d0ac6013ed2

STIX ID: report--6a7b16b6-b14c-5fbb-8dc5-1d0ac6013ed2

Feed Name: GBHackers

Threat Score
92/100

Date Published: 2026-05-14

Date Updated: 2026-05-14

Author: Mayura Kathir

...
...

**Executive summary:** Attackers compromised more than 170 npm packages and two PyPI libraries, embedding preinstall/import‑time loaders and heavily obfuscated payloads that steal GitHub, npm, cloud (AWS/GCP/Azure), Kubernetes, Vault, and local developer credentials, propagate by abusing CI/CD publishing tokens to republish infected packages, and include destructive features such as a dead‑man switch and system‑wiping second stages; JFrog linked the activity to the "Shai‑Hulud" family and observed rapid, worm‑like spread despite detection and blocking within 24 hours.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.