惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

F
Full Disclosure
V
Vulnerabilities – Threatpost
Attack and Defense Labs
Attack and Defense Labs
N
News and Events Feed by Topic
SecWiki News
SecWiki News
S
Security @ Cisco Blogs
Schneier on Security
Schneier on Security
B
Blog
TaoSecurity Blog
TaoSecurity Blog
The Last Watchdog
The Last Watchdog
H
Hacker News: Front Page
Hacker News - Newest:
Hacker News - Newest: "LLM"
博客园_首页
D
Docker
cs.AI updates on arXiv.org
cs.AI updates on arXiv.org
Y
Y Combinator Blog
W
WeLiveSecurity
N
News and Events Feed by Topic
F
Fortinet All Blogs
PCI Perspectives
PCI Perspectives
WordPress大学
WordPress大学
CTFtime.org: upcoming CTF events
CTFtime.org: upcoming CTF events
www.infosecurity-magazine.com
www.infosecurity-magazine.com
Recent Announcements
Recent Announcements
Forbes - Security
Forbes - Security
T
Tailwind CSS Blog
Hacker News: Ask HN
Hacker News: Ask HN
爱范儿
爱范儿
腾讯CDC
Last Week in AI
Last Week in AI
月光博客
月光博客
C
Cybersecurity and Infrastructure Security Agency CISA
P
Proofpoint News Feed
Help Net Security
Help Net Security
V
V2EX
C
Cyber Attacks, Cyber Crime and Cyber Security
C
CXSECURITY Database RSS Feed - CXSecurity.com
H
Heimdal Security Blog
L
LINUX DO - 最新话题
GbyAI
GbyAI
The Hacker News
The Hacker News
罗磊的独立博客
S
SegmentFault 最新的问题
H
Hackread – Cybersecurity News, Data Breaches, AI and More
博客园 - 【当耐特】
cs.CL updates on arXiv.org
cs.CL updates on arXiv.org
V2EX - 技术
V2EX - 技术
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
O
OpenAI News
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻

Cyber Security News

AIRecon: AI-Powered Penetration Testing Tool with Kali Linux Sandbox Critical Chrome Vulnerabilities Allow Attackers to Execute Arbitrary Code - Update Now! UNC3753 Uses Screen-Sharing Sessions and RMM Tools to Exfiltrate Sensitive Legal Data New OnionDrop Loader Campaign Uses gainmsg C2 to Deliver LegionLoader Payloads ClickFix Campaign Uses EtherHiding and GULoader to Infect Windows Users via Fake CAPTCHA Ghostwriter Hackers Abuse Gmail Admin-Themed Emails to Steal Credentials and 2FA Codes The Half-Life of Threat Intelligence: When Does an IOC Stop Being Useful? Critical Fortinet FortiSandbox Vulnerabilities Actively Exploited in Attacks Aembit Extends IAM for Agentic AI to Microsoft Copilot Studio India Temporarily Bans Telegram Messenger Over Medical Exam Fraud Microsoft 365 Device Code Phishing Campaign Bypasses Password Theft With Legitimate Login Flow AppViewX Launches Agent Identity Security to Govern Agents for the AI and Quantum Era Hackers Weaponize Microsoft Teams Relay to Hide Ransomware Traffic Developer laptops are the credential store attackers are picking through in 2026, GitGuardian announces Endpoint Protection Interlock and Rhysida Ransomware Operations Share Supper Backdoor and Malware Codebase Novo Nordisk Confirms Cyber Attack — Hackers Accessed Patient Medical Data and Internal AI Assets Russian and Chinese Influence Actors Use AI to Evade Bot Detection and Mimic Human Behavior Microsoft Teams Analyze the Wi-Fi Hotspot Data Connected to an Employee’s Device PRC-Nexus Hackers Exploit REDCap Servers to Spy on US Medical Research Institutions Infinite Campus Data Breach Exposes 137,000 Users Personal Details OptinMonster Plugin Hack Exposes 1.2 Million Wordpress Sites to Cyberattack Ransomware Ecosystem Consolidates Around LockBit Alumni, Qilin, Hyflock, and The Gentlemen Hackers Abuse Legitimate RMM Tools in The Quarry IRS and SSA Phishing Campaigns LiteSpeed cPanel Plugin 0-Day Vulnerability Actively Exploited in the Wild Cisco SD-WAN vManage Vulnerability Exploited in Zero-Day Attacks Nearly 14,000 SimpleHelp Servers Exposed Amid Critical Authentication Bypass Disclosure Microsoft Site Showing Warning Following Certificate Expiry DPAPISnoop Tool Extracts CREDHIST Hashes for Offline Windows Credential Recovery SHADOWBYT3$ Allegedly Claim Breach of Nintendo, Stealing Sensitive Data Anthropic Updated Privacy Policy to Include Identity Verification for Claude Users Critical Microsoft 365 Copilot Vulnerability Allows Attackers to Steal Data in One Click Hackers Use Microsoft Graph Reconnaissance to Target Payroll and HR Employees China-Nexus Hackers Use Backdoored PAM Modules for Credential Theft and Authentication Bypass SearchJack Campaign Uses 23 Chrome Extensions to Hijack Searches of 758,000 Users PromptSnatcher Ad Blocker Extensions Steal AI Chats From ChatGPT, Claude, and Gemini Hackers Abuse LNK Files, PowerShell, and Python Loader to Deploy NarwhalRAT Windows 11 Update KB5094126 Freezes Systems, Forces BitLocker Recovery, and More Critical Wazuh Vulnerability Lets Attackers Tamper with Alerts and Delete Security Evidence SecSuite - AI-powered Tool for OSINT, Web and API Security Testing WinRAR Vulnerability Exploited by Russian Hackers to Deploy GIFTEDCROOK Stealer Palo Alto Warns of GlobalProtect VPN Vulnerability Actively Exploited in the Wild Threat Actor Malware Platform Exposed via Unlocked PHP Installation Page Criminal IP at Infosecurity Europe 2026: Introducing AITEM, the Next Chapter of Attack Surface Management Maine Takes Data Breach Reporting Portal Offline After Fake VRChat and Discord Filings 152 Chrome Extensions Hide Ad Tracking and Fake Google Search Traffic New Agentjacking Attack Hijacks Your AI Coding Agent to Run Code From Hackers Server BugHunter - Bug Bounty Toolkit Powered by Claude and Free AI Providers Splunk Enterprise Pre-Auth RCE Chain Exposes Database With Zero Authentication Anthropic Fable 5 and Mythos 5 Access Blocked to All Users Following Government Directive Fancy Bear Hackers Abuse EdgeRouters and Cloud Services to Launch Stealthy Cyberattacks Hackers Abuse Legitimate NinjaOne RMM Software to Bypass Traditional Malware Detection Malicious npm Campaign Steals SSH Keys, API Tokens, Cloud Credentials, and Wallet Secrets Hackers Use OnyxC2 Malware-as-a-Service to Steal Credentials From 210 Applications Facebook and Instagram Down Globally, Users Reporting Multiple Issues Google Sues Chinese Cybercrime Network for Using Gemini AI to Launch Cyberattacks 400+ Arch Linux AUR Packages Compromised in a Supply Chain Attack Deploying Infostealers Critical Vulnerability Chain in LangGraph Allows Attackers to Gain Full Server Control SHEETCREEP C# RAT Abuses Google Sheets API as C2 to Target Diplomatic Organizations Authorities Dismantle Cryptocurrency Laundering Services ‘AudiA6’ Used by Ransomware Gangs Hackers Use Free Spotify Premium Hacks on TikTok and Instagram to Spread Vidar Infostealer Solana FakeFix Campaign Uses 25 Malicious npm and PyPI Packages to Steal Developer Secrets Microsoft Outlook and Word Vulnerabilities Allow Attackers to Execute Malicious Code Palo Alto PAN-OS Vulnerability Allows Attackers to Execute Arbitrary Commands as Root User Google Patches 28 Chrome Vulnerabilities that Allow Attackers to Execute Malicious Code Microsoft Teams for Android Vulnerability Allows Attackers to Disclose Sensitive Data Oracle PeopleSoft 0-Day RCE Vulnerability Exploited in Attacks by ShinyHunters CISA Requires Federal Agencies to Patch Critical Vulnerabilities Within 3 Days OceanLotus APT Compromises FireAnt MetaKit in Supply-Chain Attack on Stock Investors GoFlateLoader Uses Massive PE Overlay to Deliver Lumma, Vidar, and StealC Infostealers Critical Langflow Vulnerability Exploited to Execute Malicious Code Hackers Abuse SniperDz PhaaS Ecosystem for Brand Impersonation and Browser Hijacking Researcher Hacked Google Using AI and Earned $500,000 Bug Bounty GitHub to Automate Disable npm Script Installs to Block Supply Chain Attacks Claude Mythos Turning N-Days Into N-Hours With Rapid Working Exploit Creation CISA Warns of Check Point Security Gateway Vulnerability Actively Exploited in Ransomware Attacks Hackers Use Weaponized DMG Files to Target macOS Users With Infostealer Malware Hackers Use BLUERABBIT Backdoor to Encrypt Files and Wipe Disks Across Windows Systems Hackers Abuse Residential Proxy Networks to Hide Malicious Activity and Evade Detection Cybercriminals Abuse Chinese-Language Guarantee Marketplaces to Trade Stolen Credentials Ivanti Command Injection Vulnerability Exploited in Attacks Following PoC Release PoC Exploit Released for Guest-to-Host Escape Linux Kernel Vulnerability Oracle Emergency Security Update to Fix Critical RCE Vulnerability GreatXML BitLocker Bypass 0-Day Exploited Via Windows Defender Offline Scan Hackers Abuse VMware-Signed Binary to Sideload NIGHTFORGE Loader in Espionage Attacks Multiple Splunk Enterprise Vulnerabilities Allow Attackers to Execute Malicious Script Hackers Abuse AWS CloudTrail and Google Cloud Logging to Evade Detection and Exfiltrate Logs China-Linked JDY Botnet Uses 1,500+ SOHO and IoT Devices for Rapid Vulnerability Exploitation CISA Warns of SolarWinds Serv-U Vulnerability Exploited in Attacks Top 5 Best Tools for Simulated DDoS Attacks in 2026 Critical Vulnerability in Hugging Face Transformers Enables Remote Code Execution Attacks OWASP CVE Lite CLI - New Tool to Scan for Vulnerabilities in Your Projects Anthropic's Claude Services Down — claude.ai, Claude Code, and Cowork Affected [Updated] Hackers Publish Malicious Python Package Mimicking Legitimate Parsimonious Parser Hackers are Increasingly Weaponizing Trusted Tools to Deploy Notorious Malware New Magecart Attack Turns Stripe into a Malware Command Server Hola Browser for Windows Delivery Pipeline Compromised to Deliver Cryptominer New Gafgyt Variant Targets Multiple Linux Architectures With Modular Propagation Microsoft 365 Service Degradation Bypassed Windows Driver Auto-Update Controls New SHub Stealer Variant Malware Targets Chrome, Firefox, Brave, Edge, Opera, and Crypto Wallets Malicious Browser Add-Ons Target ChatGPT, Claude, Copilot, Gemini, and DeepSeek Users
Shai-Hulud Payload Steals GitHub, npm, Cloud, CI/CD, and SSH Credentials From Developers
Tushar Subhra Dutta · 2026-06-25 · via Cyber Security News

A new wave of malicious npm packages is targeting developers who work with cloud and serverless infrastructure.

The threat, known as the Shai-Hulud payload carrying the Hades malware family, has now expanded its reach to the Leo/RStreams ecosystem, a set of libraries widely used for AWS-native event streaming and data pipelines.

Security teams are raising the alarm as the attack quietly steals sensitive developer credentials the moment a package is installed.

What makes this campaign especially dangerous is how deep it digs. When a developer installs one of the affected packages, the payload begins collecting credentials stored across files, environment variables, shell history, GitHub CLI tokens, cloud access keys, and CI/CD pipeline secrets.

It works silently in the background and sends everything it finds to attacker-controlled GitHub repositories.

The scale of exposure is hard to ignore. The affected packages recorded roughly 45,000 downloads in a single month, meaning thousands of developers may have already been affected without knowing it.

Analysts at JFrog Security Research identified the new wave and published their findings in a report shared with Cyber Security News (CSN).

Researcher Yair Benamou noted this is not a completely new threat but another turn of the same campaign, with the same credential theft machinery but fresh targets and updated markers.

The Leo/RStreams libraries sit at the center of cloud-native development workflows. They wrap AWS services like Kinesis, S3, Lambda, and DynamoDB, meaning any developer installing these tools is likely working in an environment rich with cloud credentials and deployment tokens.

This positioning means that a single compromised install can expose far more than just one developer’s workstation. This latest wave confirms that the Shai-Hulud operation is still active and still growing.

Rather than building new malware from scratch, the attackers are recycling a proven payload and pointing it at new, trusted package families. Defenders who rely only on old campaign names or outdated signatures are still very likely to miss it entirely.

Shai-Hulud Payload Steals GitHub, npm, Cloud, CI/CD, and SSH Credentials

The malicious packages use a clever delivery trick that helps them slip past basic security scanners. Instead of placing harmful code inside the standard npm install scripts that most tools check, the attacker hides execution inside a file called binding.gyp.

Undreds of public repositories using this new description string (Source - JFrog)
Undreds of public repositories using this new description string (Source – JFrog)

When npm finds a package with this file and no explicit install script, it automatically runs node-gyp, which processes shell commands embedded inside that file. This gives the attacker a way to run code during installation while staying off the radar.

Once running, the payload collects credentials from a wide range of sources on the developer’s machine. It targets GitHub tokens, npm and PyPI publishing credentials, AWS access keys, JFrog and Artifactory tokens, and SSH keys.

Any stolen data is packaged into encrypted files and exfiltrated by creating repositories under a stolen GitHub token and committing the results there, a technique known as a GitHub dead drop.

Persistence and Lateral Movement Tactics

The payload does not stop at stealing credentials during installation. It plants several persistence hooks to keep running long after the initial install.

It sets itself up as a systemd service on Linux or a LaunchAgent on macOS, while also hooking into AI development tools by modifying configuration files for tools like Cursor, Copilot, and Gemini.

SSH keys found on the compromised machine are used to attempt lateral movement into other systems the developer has access to. The payload also injects itself into GitHub Actions workflows to dump pipeline secrets.

A single infected install on one machine could ripple outward into team repositories, cloud accounts, and production pipelines.

JFrog recommends isolating affected machines and CI runners before rotating any credentials. All persistence artifacts, including the monitor service, AI-tool hooks, and suspicious workflow files, must be removed first.

After cleanup, all GitHub, npm, cloud, SSH, Docker, and package registry credentials should be rotated. GitHub and npm accounts should also be audited for unexpected repositories, package releases, or suspicious workflow changes.

Indicators of Compromise (IoCs):-

Malicious npm Package Versions

TypeIndicatorDescription
npm Packageleo-auth v4.0.6Hijacked Leo/RStreams package (XRAY-1009715)
npm Packageleo-aws v2.0.4Hijacked Leo/RStreams package (XRAY-1009716)
npm Packageleo-cache v1.0.2Hijacked Leo/RStreams package (XRAY-1009726)
npm Packageleo-cdk-lib v0.0.2Hijacked Leo/RStreams package (XRAY-1009721)
npm Packageleo-cli v3.0.3Hijacked Leo/RStreams package (XRAY-1009724)
npm Packageleo-config v1.1.1Hijacked Leo/RStreams package (XRAY-1009720)
npm Packageleo-connector-elasticsearch v2.0.6Hijacked Leo/RStreams package (XRAY-1009713)
npm Packageleo-connector-mongo v3.0.8Hijacked Leo/RStreams package (XRAY-1009714)
npm Packageleo-connector-mysql v3.0.3Hijacked Leo/RStreams package (XRAY-1009729)
npm Packageleo-connector-oracle v2.0.1Hijacked Leo/RStreams package (XRAY-1009718)
npm Packageleo-connector-redshift v3.0.6Hijacked Leo/RStreams package (XRAY-1009725)
npm Packageleo-cron v2.0.2Hijacked Leo/RStreams package (XRAY-1009723)
npm Packageleo-logger v1.0.8Hijacked Leo/RStreams package (XRAY-1009727)
npm Packageleo-sdk v6.0.19Hijacked Leo/RStreams package (XRAY-1009717)
npm Packageleo-streams v2.0.1Hijacked Leo/RStreams package (XRAY-1009728)
npm Packagerstreams-metrics v2.0.2Hijacked Leo/RStreams package (XRAY-1009731)
npm Packagerstreams-shard-util v1.0.1Hijacked Leo/RStreams package (XRAY-1009732)
npm Packageserverless-convention v2.0.4Hijacked Leo/RStreams package (XRAY-1009719)
npm Packageserverless-leo v3.0.14Hijacked Leo/RStreams package (XRAY-1009730)
npm Packagesolo-nav v1.0.1Hijacked Leo/RStreams package (XRAY-1009722)

Network and Service Indicators

TypeIndicatorDescription
URLhxxps[:]//api[.]anthropic[.]com/v1/apiAnthropic API camouflage used for payload communication
URLhxxps[:]//api[.]github[.]comGitHub API used for dead-drop exfiltration
URLhxxps[:]//api[.]github[.]com/search/commits?q=firedalazherGitHub commit search endpoint used in campaign tracking
URLhxxps[:]//github[.]com/oven-sh/bun/releases/download/bun-v1.3.13/Bun runtime download used by payload
URLhxxps[:]//github[.]com/oven-sh/bun/releases/download/bun-v1.3.14/Bun runtime download used by payload

Host and Persistence Indicators

TypeIndicatorDescription
File Path/tmp/p*.jsTemporary payload script
File Path/tmp/b-/bunBun runtime binary dropped in temp
File Path/tmp/b-/b.zipBun runtime archive in temp
File Path~/.config/gh-token-monitor/Persistence config directory
File Path~/.config/gh-token-monitor/tokenStored token file for monitor service
File Path~/.config/gh-token-monitor/handlerHandler script for monitor service
File Path~/.local/bin/gh-token-monitor.shMonitor shell script
File Path~/.config/systemd/user/gh-token-monitor.serviceLinux systemd persistence service
File Path~/Library/LaunchAgents/com.user.gh-token-monitor.plistmacOS LaunchAgent persistence
File Path~/.local/share/updater/update.pyPython updater persistence script
File Path~/.local/share/updater/update-monitor.serviceUpdater systemd service
File Path~/.config/index.jsPayload config index
File Nameai_setup.shAI tool setup hook script
File Nameai_init.jsAI tool initialization hook script
File Pathresults/results-.jsonExfiltrated credential result files

Repository and Workflow Indicators

TypeIndicatorDescription
Campaign MarkerAlright Lets See If This WorksCurrent wave public repository description marker
Token StringRevokeAndItGoesKaboomCurrent token relay marker string
Token StringTheBeautifulSandsOfTimeAlternate campaign marker string
Token StringthebeautifulmarchofftimeAlternate campaign marker string
Env VariableSEED_PATGitHub PAT used in gated seeder path
Env VariableVARIABLE_STOREVariable storage environment reference
File Nameformat-results.txtCredential formatting output file
AI Config.cursor/rules/setup.mdcCursor AI rules hook
AI Config.gemini/settings.jsonGemini AI settings hook
AI Config.cursorrulesCursor rules persistence file
AI Config.windsurfrulesWindsurf rules persistence file
AI Config.github/copilot-instructions.mdCopilot instructions persistence file
AI Configmcp.jsonMCP configuration hook
AI Config.aider.conf.ymlAider AI configuration hook

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Follow us on Google NewsLinkedIn, and X to Get More Instant UpdatesSet CSN as a Preferred Source in Google.

Tushar Subhra Dutta

Tushar Subhra Dutta

Tushar is a senior cybersecurity and breach reporter. He specializes in covering cybersecurity news, trends, and emerging threats, data breaches, and malware attacks. With years of experience, he brings clarity and depth to complex security topics.