logo

New Shai-Hulud Miasma Wave Hits Hundreds of npm Packages

ID: 63066b75-5518-57c6-aae8-470f57b1a9f8

STIX ID: report--63066b75-5518-57c6-aae8-470f57b1a9f8

Feed Name: Security Boulevard

Threat Score
80/100

Date Published: 2026-06-04

Date Updated: 2026-06-05

Author: Sonatype Security Research Team

...
...

TL;DR: Sonatype Security Research reports a new Shai-Hulud “Miasma” wave impacting 281 npm package versions that abandon obvious preinstall/postinstall scripts and instead abuse binding.gyp/node-gyp at install time to execute code that harvests system, developer and CI/CD credentials, validates access, and can use stolen maintainer credentials to publish further malicious package versions; organizations with impacted installs should treat environments as potentially compromised and investigate and rotate credentials.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.