Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

Here We Go Again - JavaScript Payload Analysis

0
Medium
Published: 08/06/2026 (08/06/2026, 09:43:34 UTC)
Source: AlienVault OTX General

Description

A 710 KB JavaScript payload was discovered in the compromised [email protected] package, representing a newer variant of Shai-Hulud with enhanced obfuscation techniques. The malicious code operates with four primary objectives: harvesting credentials from local systems, CI environments, cloud platforms, Kubernetes, and Vault; exfiltrating encrypted data through dynamic HTTPS endpoints or public GitHub repositories; leveraging stolen npm credentials to publish infected patch releases across accessible packages; and exploiting GitHub credentials with GitHub Actions to compromise repositories and extract additional credentials. The campaign demonstrates sophisticated supply chain attack capabilities, targeting the npm ecosystem and development infrastructure. Multiple components were identified including obfuscated JavaScript files, VS Code configuration files, and injected GitHub Actions workflows, indicating a comprehensive approach to credential theft and lateral movement across development environments.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/06/2026, 11:32:28 UTC

Technical Analysis

The threat involves a large, obfuscated JavaScript payload embedded in the compromised [email protected] npm package, identified as a newer variant of Shai-Hulud malware. It performs four main malicious activities: harvesting credentials from various environments including local machines, continuous integration systems, cloud platforms, Kubernetes clusters, and Vault secrets; exfiltrating stolen data through dynamically generated HTTPS endpoints or public GitHub repositories; leveraging stolen npm credentials to publish infected patch releases to other npm packages; and exploiting GitHub credentials via GitHub Actions workflows to further compromise repositories and extract additional credentials. The attack demonstrates a comprehensive supply chain compromise targeting developer tools and infrastructure, with multiple components such as obfuscated JavaScript files, VS Code configuration files, and injected GitHub Actions workflows facilitating credential theft and lateral movement.

Potential Impact

This malware campaign enables attackers to steal sensitive credentials across multiple environments including local systems, CI/CD pipelines, cloud platforms, Kubernetes, and Vault secrets. The stolen credentials can be used to exfiltrate data, propagate malicious code through npm package updates, and compromise GitHub repositories via GitHub Actions workflows. This can lead to widespread supply chain compromise affecting multiple packages and development environments, potentially exposing sensitive organizational secrets and infrastructure access.

Defensive Guidance

No official patch or remediation guidance is provided in the available data. Organizations should verify the integrity of the keyv package version 6.0.0 and audit their npm dependencies for compromise. Review and rotate credentials potentially exposed in local, CI, cloud, Kubernetes, and Vault environments. Inspect GitHub repositories for unauthorized GitHub Actions workflows and remove any injected malicious workflows. Monitor for suspicious npm package updates and consider using package integrity verification tools. Patch status is not yet confirmed — check vendor advisories and trusted security sources for updates.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Author
AlienVault
Tlp
white
References
["https://research.jfrog.com/post/shai-hulud-here-we-go-again/"]
Adversary
null
Pulse Id
6a745746ff40fa3e996fe0ec
Threat Score
null

Indicators of Compromise

Hash

ValueDescriptionCopy
hash00ca0c04d247ef09f2b2acc452029345
hashdbb9b09957113463bbeb420c2c4108b5
hash7b0278216ac31ec18eca9eb8bc1c1261a1b26f6c
hashff7ed7a0fa1c43eed01809d076feedbaed464fc7
hash14eb4ce01dd4307759887ff819359b70d7d9ff709ecde039a5abc1aac325b128
hash927387d0cfac1118df4b383decc2ea6ba49c9d2f98b47098bcbcba1efc026e1f
hash29ac906c8bd801dfe1cb39596197df49f80fff2270b3e7fbab52278c24e4f1a7
hash35a672cf34b996b91f3e1c28cbf3a05a37e036e4
hashf525d52ceb966516686b482d3dc0137028cc6a63
hash9fc2570b7cef51c1b8df116d144d11ff4096357be7d2c4c6367cfc2509cf1bcc
hashfd3ca4007b225fdf8de7af4345a19179d5efa8c4bb9205f88cda806e5684b1eb
hash4140f7e17e6f97f83aa3472473e01add
hash7bcf8d9f6834c44450eac145a967d2f2
hash3f3f42d072bd36860ab7bd7fb5e10ac0d22c741c13c89505ccd6ec0ea572eea7

Threat ID: 6a74684cbf8831d5399889e0

Added to database: 08/06/2026, 10:56:12 UTC

Last enriched: 08/06/2026, 11:32:28 UTC

Last updated: 08/06/2026, 19:09:57 UTC

Views: 15

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses