Threats Tagged 'shai-hulud'
View all threats tagged with 'shai-hulud'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'shai-hulud'
Click on any threat for detailed analysis and mitigation recommendations
Shai-Hulud Trinitite Hits @7nohe/openapi-react-query-codegen 0 A new Mini Shai-Hulud worm variant named Trinitite was detected targeting the npm package @7nohe/openapi-react-query-codegen. The attacker exploited a GitHub workflow vulnerability allowing any user to trigger npm publish via pull-request comments, resulting in rapid publication of malicious package versions. The worm uses obfuscation techniques to execute even when scripts are disabled, steals credentials from multiple developer and cloud platforms, and exfiltrates data via GitHub commits. It establishes persistence through systemd services and includes a destructive token revoke mechanism that can wipe user directories. This campaign is linked to the TeamPCP threat actor and appeared shortly after arrests of related suspects in Australia. Join the discussion | AlienVault OTX General | 08/31/2026, 15:26:41 UTC Added: 09/01/2026, 08:37:15 UTC |
Tracking Shai-Hulud: Inside the ChainDrop NPM Worm 0 On August 4, 2026, ChainDrop, a self-propagating worm variant of Mini Shai-Hulud linked to TeamPCP, infiltrated the npm ecosystem through a compromised maintainer account of the keyv ecosystem. The attacker injected malicious code into GitHub repositories, weaponizing legitimate CI/CD pipelines to publish poisoned packages with valid SLSA Build Level 3 provenance attestations, making them indistinguishable from clean releases. ChainDrop spread to over 400 packages within four hours by stealing npm tokens and republishing infected versions. The worm employs Ethereum smart contracts for C2 infrastructure, enabling domain rotation without modifying deployed malware. It features destructive capabilities, wiping victim home directories upon token revocation, and achieves persistence through IDE and AI-agent configuration files. The payload harvests credentials from npm, GitHub, AWS, Azure, GCP, Kubernetes, HashiCorp Vault, and other services, exfiltrating data via GitHub repositories and EtherHiding techniques. Join the discussion | AlienVault OTX General | 08/12/2026, 02:32:33 UTC Added: 08/12/2026, 06:41:18 UTC |
Showing 1 to 2 of 2 results