logo

Four Malicious npm Packages Deliver Infostealers and Phantom Bot DDoS Malware

ID: 79aeb32d-90bd-5b87-9d48-626606775374

STIX ID: report--79aeb32d-90bd-5b87-9d48-626606775374

Feed Name: The Hacker News

Threat Score
82/100

Date Published: 2026-05-18

Date Updated: 2026-05-18

Author: [email protected] (The Hacker News)

...
...

Researchers uncovered four malicious npm packages (chalk-tempalte, @deadcode09284814/axios-util, axois-utils, color-style-utils) published by a single account that install multiple malware types: three info-stealers (including a near-exact clone of the Shai-Hulud worm) and a Golang DDoS botnet named Phantom Bot that establishes persistence and exfiltrates credentials, SSH keys, cloud secrets, system info and crypto wallet data to observed C2 domains/IPs; users are advised to uninstall the packages, rotate secrets, remove malicious IDE/agent configs, search for the linked GitHub repo, and block the listed domains/IPs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.