Malware
Shai-Hulud
A Javascript-based worm propagating through GitHub repositories and exfiltrating tokens and other credentials.
Indicators of Compromise 48
Domain abb1[.]life Domain amutes[.]com Domain awqhnjewqjkl[.]icu Domain js-mirror[.]com Domain npm-cache[.]com Domain pypi-get[.]com Filename .claude/settings.json Filename .claude/unicorn Filename .github/workflows/codeql_analysis.yml Filename .vscode/tasks.json Filename Math_Symbol.js Filename math_init.js Filename setup.mjs GitHub Repo Shai-Hulud GitHub Repo TeamPCP/Shai-Hulud GitHub Repo thebeautifulmarchoftime GitHub User ellie.191 SHA-256 54dc7ea54a1317cca0e890a2770630cf7fa6c97813e0cb9d2caa93012b350668 SHA-256 9fc2570b7cef51c1b8df116d144d11ff4096357be7d2c4c6367cfc2509cf1bcc SHA-256 b27b82afa5f15512f3856e549fb83d873fd0049759a4b62ce64c8d7d4dc2c678 SHA-256 fd3ca4007b225fdf8de7af4345a19179d5efa8c4bb9205f88cda806e5684b1eb IP 104[.]21[.]91[.]101 IP 104[.]243[.]42[.]117 IP 116[.]105[.]166[.]148 IP 117[.]72[.]74[.]48 IP 15[.]204[.]106[.]173 IP 172[.]67[.]215[.]154 IP 172[.]96[.]142[.]186 IP 198[.]255[.]70[.]210 IP 207[.]246[.]106[.]162 IP 23[.]236[.]182[.]215 IP 23[.]237[.]196[.]170 IP 3[.]235[.]109[.]125 IP 38[.]46[.]219[.]162 IP 38[.]46[.]219[.]163 IP 38[.]46[.]219[.]166 IP 47[.]251[.]72[.]239 IP 47[.]88[.]103[.]81 IP 95[.]214[.]112[.]26 Package @ctx/nightly-build Package @redhat-cloud-services/* Package Mini Shai-Hulud Package Shai-Hulud Package cacheable Package jackson-json Package keyv Package left-pad@1.0.1 Registry User IfYouBlockThisAPIKeyItWillCrashTheLiveProductionServersOfAllThirdPartyClients
MITRE ATT&CK TTPs 19
T1021.003 T1059.001 T1059.007 T1071 T1071.003 T1078 T1081 T1090 T1098 T1133 T1195 T1195.001 T1485 T1528 T1530 T1552 T1553 T1555 T1566
Distributed Component Object Model
Lateral Movement
PowerShell
Execution
JavaScript
Execution
Application Layer Protocol
Command And Control
Mail Protocols
Command And Control
Valid Accounts
Defense Evasion
T1081
Proxy
Command And Control
Account Manipulation
Persistence
External Remote Services
Persistence
Supply Chain Compromise
Initial Access
Compromise Software Dependencies and Development Tools
Initial Access
Data Destruction
Impact
Steal Application Access Token
Credential Access
Data from Cloud Storage
Collection
Unsecured Credentials
Credential Access
Subvert Trust Controls
Defense Evasion
Credentials from Password Stores
Credential Access
Phishing
Initial Access
Source Articles
ChainDrop: Inside a Self-Propagating npm Worm
ChainDrop is a self-propagating npm worm that infected over 400 packages, including widely used ones like keyv and cacheable-request, enabling it to steal cloud credentials, npm and GitHub tokens, SSH keys, and other sensitive developer data. The worm uses a combination of domain-based and GitHub-based exfiltration, with C2 infrastructure resolved via an Ethereum smart contract, allowing silent domain rotation through blockchain transactions. It establishes persistence through VS Code and Claude Code configurations, targets CI runners to extract ephemeral OIDC tokens, and can republish infected packages while preserving legitimate functionality, making detection difficult.
unit42 ·3w ago
Cloud Threat Highlights: H1 2026
In H1 2026, a surge in cloud-based threats was driven by aggressive software supply-chain attacks, particularly by the group TeamPCP, which compromised developer toolchains across npm, PyPI, and VSCode extensions to steal credentials and propagate across cloud environments. TeamPCP's malware evolved to exploit CI misconfigurations, extract OIDC tokens, and deploy wipers with Dune-themed taunts. North Korea's UNC1069 conducted parallel campaigns, trojanizing the axios package and compromising over 140 @mastra-related packages. The open-sourced Shai-Hulud worm enabled follow-on attacks like IronWorm, which used Rust-based binaries and eBPF rootkits for stealth. A new extortion group, JINX-0163, emerged, targeting cloud identities across AWS, Azure, and GCP to steal secrets and enable ransom threats via the alias 'FulcrumSec'.
wiz
Token Jacking: Cybercriminals Could Be Stealing Your AI Resources
Unit 42 has identified a growing threat called 'token jacking,' where cybercriminals steal API keys (tokens) used to access AI platforms, leading to massive financial losses due to unmonitored usage. These stolen tokens are often funneled into 'transfer stations'—gray-market services that resell discounted AI computing capacity—using proxy platforms like new-api or one-api. Attackers obtain tokens via phishing, information stealers, or malicious npm packages such as Shai-Hulud and Miasma, which self-propagate and harvest credentials from development environments. The stolen tokens are then used to generate millions of API calls, resulting in hundreds of thousands of dollars in unauthorized charges before detection.
unit42 ·3w ago
Massive ChainDrop npm supply-chain attack infects hundreds of packages
A massive supply-chain attack dubbed ChainDrop has compromised over 1,300 npm packages with a combined 2 billion monthly downloads. The attack began with the compromise of the Keyv maintainer's GitHub account, allowing the threat actor to push malicious code directly to main branches and publish poisoned versions through legitimate CI/CD workflows. The malware, named ChainDrop and based on the Shai-Hulud worm, includes a dropper (setup.mjs) and an obfuscated infostealer (Math_Symbol.js) that collects developer and cloud credentials, encrypts them, and exfiltrates them to a public GitHub repository. The attack spreads laterally by self-propagating to other packages maintained by developers whose environments were infected.
bleeping-computer ·4w ago
Find Unused, Stale, and OIDC-Replaceable GitHub Actions Secrets Across Your GitHub Organization
Threat actors are increasingly targeting GitHub Actions secrets through campaigns like GhostAction and Megalodon, which exfiltrated thousands of secrets from public repositories. These attacks exploit the accumulation of unused, stale, or long-lived credentials that organizations fail to clean up. The Shai-Hulud worm exemplifies the risk, spreading by stealing npm tokens to publish malicious packages. Transitioning to OIDC-based authentication and eliminating unused secrets can reduce the attack surface significantly.
step-security ·1mo ago
Suno Breached via Shai-Hulud Worm, Leaked Code Exposes AI Music Scraping
AI music generator Suno suffered a breach stemming from the Shai-Hulud worm, which compromised a developer's machine and exfiltrated GitHub and cloud credentials. The attacker, using the handle ellie.191, accessed Suno's source code, customer data, and payment information without the company's public notification. The breach highlights the ongoing impact of the Shai-Hulud campaign, which spreads via trojanized npm, PyPI, and Packagist packages and exfiltrates credentials to public GitHub repositories.
socket-dev
Maven Support Comes to GitHub Checks and OSS Package Search
The Java ecosystem is increasingly targeted by supply chain attacks, as demonstrated by the Shai-Hulud worm's second wave and a malicious lookalike of the Jackson JSON library published to Maven Central. These attacks leverage compromised or freshly published dependencies to deliver payloads such as Cobalt Strike, exploiting the window between publication and detection. Traditional vulnerability scanners are often too slow to respond, making real-time protection critical. StepSecurity now extends its Maven support to GitHub Checks and OSS Package Search to block compromised and newly published malicious Java dependencies during pull requests.
step-security ·2mo ago