Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

Major Shai Hulud campaign strikes npm again, affecting keyv and 400+ packages

0
Medium
Published: 08/06/2026 (08/06/2026, 09:42:36 UTC)
Source: AlienVault OTX General

Description

A sophisticated supply-chain attack campaign named Shai-Hulud has compromised over 400 npm packages across 1700+ versions, beginning with keyv and cacheable libraries. The malware operates as a self-propagating worm that collects credentials from local filesystems, CI/CD environments, cloud platforms, Kubernetes clusters, and HashiCorp Vault. It exfiltrates stolen data through dynamic HTTPS endpoints or public GitHub repositories, then uses compromised npm tokens to publish infected versions of all writable packages. The campaign also injects execution hooks into GitHub repositories via VS Code and Claude configuration files, harvests GitHub Actions secrets through injected workflows, and includes a targeted attack against npm trusted publishing flows. Command and control infrastructure leverages Ethereum smart contracts and GitHub commit messages for resilience.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/06/2026, 11:32:37 UTC

Technical Analysis

Shai-Hulud is a complex supply-chain malware campaign targeting the npm ecosystem, initially compromising keyv and cacheable libraries among over 400 packages and 1700+ versions. The malware functions as a self-propagating worm that collects sensitive credentials from various environments including local filesystems, CI/CD pipelines, cloud platforms, Kubernetes clusters, and HashiCorp Vault. It exfiltrates this data through dynamic HTTPS endpoints or public GitHub repositories. Using stolen npm tokens, it publishes infected versions of all writable packages, thereby spreading the infection. The campaign further compromises GitHub repositories by injecting execution hooks via VS Code and Claude configuration files and harvesting GitHub Actions secrets through malicious workflows. It also includes targeted attacks on npm trusted publishing processes. The attackers employ resilient command and control mechanisms leveraging Ethereum smart contracts and GitHub commit messages to maintain persistence and control.

Potential Impact

The campaign compromises a large number of npm packages, potentially affecting any projects depending on these infected packages. It enables credential theft from multiple environments including local, CI/CD, cloud, Kubernetes, and secret management systems like HashiCorp Vault. The stolen credentials can lead to further compromise of developer environments, cloud infrastructure, and continuous integration pipelines. The malware’s ability to self-propagate and publish infected package versions increases the risk of widespread supply-chain contamination. Injection of execution hooks and harvesting of GitHub Actions secrets further escalate the risk of unauthorized access and lateral movement within development and deployment environments.

Defensive Guidance

No official patch or remediation guidance is provided in the available data. Organizations should monitor official vendor advisories and security research updates for remediation instructions. Immediate mitigation steps include auditing npm package dependencies for compromised versions, revoking and rotating npm tokens and other credentials, reviewing GitHub repository configurations for unauthorized hooks or workflows, and enhancing secret management practices. Since this is a supply-chain attack, organizations should consider implementing strict package integrity verification and supply-chain security best practices. Patch status is not yet confirmed — check the vendor advisory for current remediation guidance.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Author
AlienVault
Tlp
white
References
["https://research.jfrog.com/post/shai-hulud-is-back-august/"]
Adversary
null
Pulse Id
6a74570cf5cc7a08cd8e9903
Threat Score
null

Indicators of Compromise

Hash

ValueDescriptionCopy
hashbbbca2ddaa5d8feaa63e36b76fdaad77386f024f
hashde0fac2e4500dabe0009e67214ff5f5447ce83dd
hash00ca0c04d247ef09f2b2acc452029345
hashdbb9b09957113463bbeb420c2c4108b5
hash7b0278216ac31ec18eca9eb8bc1c1261a1b26f6c
hashff7ed7a0fa1c43eed01809d076feedbaed464fc7
hash14eb4ce01dd4307759887ff819359b70d7d9ff709ecde039a5abc1aac325b128
hash927387d0cfac1118df4b383decc2ea6ba49c9d2f98b47098bcbcba1efc026e1f
hash29ac906c8bd801dfe1cb39596197df49f80fff2270b3e7fbab52278c24e4f1a7
hash35a672cf34b996b91f3e1c28cbf3a05a37e036e4
hashf525d52ceb966516686b482d3dc0137028cc6a63
hash9fc2570b7cef51c1b8df116d144d11ff4096357be7d2c4c6367cfc2509cf1bcc
hashfd3ca4007b225fdf8de7af4345a19179d5efa8c4bb9205f88cda806e5684b1eb
hash4140f7e17e6f97f83aa3472473e01add
hash7bcf8d9f6834c44450eac145a967d2f2
hash3f3f42d072bd36860ab7bd7fb5e10ac0d22c741c13c89505ccd6ec0ea572eea7

Threat ID: 6a74684cbf8831d5399889ce

Added to database: 08/06/2026, 10:56:12 UTC

Last enriched: 08/06/2026, 11:32:37 UTC

Last updated: 08/06/2026, 21:36:32 UTC

Views: 15

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses