惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

爱范儿
爱范儿
大猫的无限游戏
大猫的无限游戏
J
Java Code Geeks
MongoDB | Blog
MongoDB | Blog
Martin Fowler
Martin Fowler
GbyAI
GbyAI
Microsoft Azure Blog
Microsoft Azure Blog
Recent Announcements
Recent Announcements
F
Fortinet All Blogs
B
Blog
U
Unit 42
B
Blog RSS Feed
D
DataBreaches.Net
Google DeepMind News
Google DeepMind News
人人都是产品经理
人人都是产品经理
腾讯CDC
量子位
酷 壳 – CoolShell
酷 壳 – CoolShell
V
Visual Studio Blog
博客园 - 聂微东
MyScale Blog
MyScale Blog
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
博客园 - 三生石上(FineUI控件)
Engineering at Meta
Engineering at Meta

Security Affairs

Carding service Jerry’s Store leak exposes 345,000 stolen payment cards Anthropic launches Claude Security to counter rapid AI-Powered exploits SonicWall patches three SonicOS flaws in Gen 6, 7 and 8 firewalls. Patch them now Copy Fail: New Linux bug enables Root via page‑cache corruption Agent’s claims on WhatsApp access spark security concerns Meta accused of violating DSA by failing to safeguard minors Large-scale Roblox hacking operation shut down by Ukrainian authorities CVE-2026-42208: LiteLLM bug exploited 36 hours after its disclosure Internet censorship index reveals Russia’s lead and widespread content blocking All supported cPanel versions hit by critical auth bug, now patched U.S. CISA adds Microsoft Windows Shell and ConnectWise ScreenConnect flaws to its Known Exploited Vulnerabilities catalog ShinyHunters exploit Anodot incident to target Vimeo CVE-2026-3854 GitHub flaw enables remote code execution Signal Phishing Campaign Targets German Officials in Suspected Russian Operation Microsoft fixes Entra ID flaw enabling privilege escalation New Android spyware Morpheus linked to Italian surveillance firm NCSC launches SilentGlass, a plug-in device to secure HDMI and DisplayPort links Medtronic discloses security incident after ShinyHunters claimed theft of 9M+ records Chinese spy posed as researcher in spear-phishing campaign targeting NASA to steal defense software LINKEDIN BROWSERGATE Firefox bug CVE-2026-6770 enabled cross-site tracking and Tor fingerprinting Fast16: Pre-Stuxnet malware that targeted precision engineering software Italy moves to extradite Chinese national to the U.S. over hacking charges U.S. utility giant Itron discloses a security breach Critical bug in CrowdStrike LogScale let attackers access files GopherWhisper: new China-linked APT targets Mongolia with Go-based malware SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 94 Trigona ransomware adopts custom tool to steal data and evade detection Security Affairs newsletter Round 574 by Pierluigi Paganini – INTERNATIONAL EDITION U.S. CISA adds SimpleHelp, Samsung, and D-Link flaws to its Known Exploited Vulnerabilities catalog
Shai-Hulud worm copycats emerge after source code leak
Pierluigi Pa · 2026-05-19 · via Security Affairs

Shai-Hulud worm copycats are already attacking NPM developers after its source code leaked, enabling fast supply chain exploitation.

The first copycats of the Shai-Hulud worm have already started showing up online, only a few days after the malware’s source code was dumped on GitHub. Researchers had warned this would happen almost immediately, and they were right.

According to cybersecurity firm Ox Security, at least one threat actor is already using modified versions of the worm in attacks against NPM developers.

Shai-Hulud first appeared back in September 2025 during a series of supply chain attacks targeting the open source ecosystem. The malware resurfaced again a few months later, compromising hundreds of NPM packages and potentially affecting thousands of developers. Its main purpose was straightforward: steal credentials, tokens, API keys, and other secrets from infected machines, then use those credentials to spread further by pushing malicious updates through compromised maintainer accounts.

Things escalated earlier this year when researchers connected the malware to TeamPCP, the group tied to several attacks against the open source community, including incidents involving Trivy, Bitwarden, Checkmarx, SAP, and TanStack.

Then came the turning point: TeamPCP briefly uploaded repositories containing the full Shai-Hulud source code to GitHub. Around the same time, posts appeared on BreachForums encouraging people to reuse the malware and launch their own supply chain campaigns.

Ox Security spotted a threat actor that has already published four malicious NPM packages, including a direct clone of Shai-Hulud called “chalk-tempalte.” The clone is simpler than the original version and doesn’t even try particularly hard to hide itself, but the core behavior is still there.

“The chalk-tempalte npm package contains a clone of the Shai-Hulud open source which was published last week in GitHub. The actor took the code, and almost without any change at all – uploaded a working version with its own C2 server and private key into npm.” reads the report published by Ox Security. “By analyzing the malware’s source code, the same patterns from previous Shai-Hulud attacks are immediately recognizable, as expected. This includes uploading stolen credentials to a new GitHub repository.”

The attacker also used typo-squatting tricks to target developers searching for Axios-related packages. Some of the malicious packages imitate legitimate utilities closely enough that a distracted developer could install them without noticing the difference.

One package reportedly goes beyond credential theft and attempts to pull infected systems into a DDoS botnet, which suggests the actor is experimenting with multiple monetization paths instead of relying only on stolen developer secrets.

According to the experts, the four identified packages:

  • @deadcode09284814/axios-util
  • axois-utils
  • chalk-tempalte
  • color-style-utils

had already accumulated more than 2,600 weekly downloads before being detected.

What’s worrying is not only the malware itself, but how fast others could reuse it once the code was exposed. A threat that was already dangerous for skilled actors has now become much easier for less capable ones to deploy.

“Threat actors are getting even more motivated to conduct supply chain and typo-squatting, as attacks become easier to perform with the Shai-Hulud code becoming open source.” concludes the report. “We’re now seeing a single actor with multiple techniques and infostealer types spreading malicious code onto NPM. It’s just the first phase of an upcoming wave of supply chain attacks coming.”

Modern software development relies heavily on third-party dependencies, often installed without close review, which creates supply chain risk if malicious code enters trusted repositories.

The release of the Shai-Hulud source code has worsened the threat by making a powerful attack tool reusable and easy to modify, even for less skilled actors. This has led to expectations of fast-growing copycat campaigns.

Defenders are urged to monitor dependency updates, watch for suspicious or typo-squatted packages, and better secure developer tokens and CI/CD credentials, which are common attacker targets.

“We’re seeing more and more vibe coded malware being spread on npm, each variant collecting different types of data and used for different purposes, from location information, sensitive repositories, Cloud credentials, and even a DDoS botnet all from the same npm account.” concludes the report.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, malware)