logo

Leaked Shai-Hulud malware fuels new npm infostealer campaign

ID: 3c79e404-97e1-56e6-af73-087c180bfa6b

STIX ID: report--3c79e404-97e1-56e6-af73-087c180bfa6b

Feed Name: Bleeping Computer

Threat Score
70/100

Date Published: 2026-05-18

Date Updated: 2026-05-18

Author: Bill Toulas

...
...

Researchers at OXsecurity found four malicious npm packages (chalk-tempalte, @deadcode09284814/axios-util, axois-utils, color-style-utils) that include a non-obfuscated clone of the leaked Shai-Hulud infostealer and additional modules that exfiltrate developer credentials, secrets, crypto wallet data, and in one case add DDoS/“phantom bot” functionality; stolen data is sent to a reported C2 (87e0bbc636999b.lhr.life) and some uploads can publish stolen credentials to public GitHub repositories—developers are advised to remove affected packages and rotate credentials.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.