Find notable cyber news and cases, enriched with sources, timelines, and signals.

MUT-4831 Vidar Stealer npm supply-chain campaign

Campaign
First reported
Last updated
Happening score
H score 38
1 unique sources, 1 articles

Summary

Hide ▲

A MUT-4831 supply-chain campaign pushed 17 npm packages that masqueraded as SDKs and silently delivered Vidar Stealer, expanding theft risk through the npm registry. The packages were downloaded at least 2,240 times before takedown, showing measurable reach before removal. The operation relied on postinstall scripts and external ZIP downloads to execute the payload.

Related Happenings

Packagist package.json hook supply chain attack campaign

Campaign
H score39 First: 23.05.2026 19:07 Last: 23.05.2026 19:07 Sources 1

About this happening: A coordinated supply chain attack campaign compromised eight Packagist packages, creating repeat execution risk for projects that install the affected versions. The malici...

Deadcode09284814 malicious npm packages delivering Phantom Bot and infostealers

Malware Activity
H score22 First: 18.05.2026 11:57 Last: 18.05.2026 11:57 Sources 1

About this happening: Four npm packages published by deadcode09284814 were found delivering information-stealing malware and Phantom Bot DDoS capability, putting installers at risk of *...

Mini Shai-Hulud npm supply-chain malware wave

Malware Activity
H score68 First: 12.05.2026 14:07 Last: 12.05.2026 14:07 Sources 1

About this happening: The Mini Shai-Hulud npm malware activity now includes the Miasma variant affecting Microsoft GitHub repositories in a self-replicating supply-chain campaign. O...

Latest development: 09.06.2026 18:42

On June 5, Microsoft removed 73 repositories across its Azure, microsoft, Azure-Samples, and MicrosoftDocs organizations on GitHub after concerns about potential malicious content tied to the Miasma/Shai-Hulud supply-chain campaign. The action disrupted continuous integration pipelines and broke workflows that depended on Azure/functions-action, while Microsoft said it temporarily removed some repositories during its investigation.

ZiChatBot PyPI supply-chain malware delivery

Malware Activity
H score30 First: 07.05.2026 12:20 Last: 07.05.2026 12:20 Sources 1

About this happening: A PyPI supply-chain attack used three packages to quietly deliver ZiChatBot, creating a cross-platform malware risk for Windows and Linux installs. The packages we...

Mini Shai-Hulud SAP-related npm supply-chain campaign

Campaign
H score45 First: 29.04.2026 19:26 Last: 29.04.2026 19:26 Sources 1

About this happening: A new Mini Shai-Hulud supply-chain campaign is targeting SAP-related npm packages, putting developer and CI/CD environments at risk of credential theft and malicious p...

Latest development: 12.05.2026 11:50

Mini Shai-Hulud expands beyond the original SAP-related npm packages to compromise TanStack, UiPath, Mistral AI, OpenSearch, Guardrails AI, and DraftLab packages across npm and PyPI, with malicious payloads using router_init.js, GitHub Actions abuse, and exfiltration to filev2.getsession[.]org, api.masscan[.]cloud, or attacker-controlled GitHub repositories.

Timeline

  1. 07.11.2025 08:48 2 articles · 8mo ago

    Vidar Stealer npm campaign disclosed

    Initial Disclosure

    Datadog Security Labs disclosed 17 npm packages that masqueraded as SDKs but used postinstall scripts to download ZIP archives from bullethost[.]cloud and execute Vidar Stealer, marking the first time the stealer had been distributed via the npm registry.

    Show sources