Find notable cyber news and cases, enriched with sources, timelines, and signals.

Shai-Hulud credential-stealing npm worm spreading through poisoned package releases

Malware Activity
First reported
Last updated
Happening score
H score 37
1 unique sources, 1 articles

Summary

Hide ▲

A credential-stealing npm worm spread through poisoned package releases on August 4, 2026, exposing developer and CI credentials and broadening supply-chain risk. The activity began with [email protected] and quickly extended beyond the original namespace into hundreds of packages.

Related Happenings

Rollup polyfill npm package malware activity for remote access and data theft

Malware Activity
H score16 First: 03.07.2026 19:07 Last: 03.07.2026 19:07 Sources 1

About this happening: Malicious npm packages disguised as Rollup polyfill tooling are now delivering remote-access and data-theft payloads to developer workstations and build machines. The...

Shai-Hulud PyPI supply-chain malware activity

Malware Activity
H score22 First: 08.06.2026 23:41 Last: 08.06.2026 23:41 Sources 1

About this happening: The Shai-Hulud supply-chain malware compromised 19 PyPI packages, turning routine installs into secret-stealing execution and putting developer credentials at risk. Th...

IronWorm npm supply-chain infection and self-propagation

Malware Activity
H score15 First: 04.06.2026 18:25 Last: 04.06.2026 18:25 Sources 1

About this happening: IronWorm is a Rust infostealer in a npm supply-chain activity that hides behind an eBPF kernel rootkit, communicates over Tor, and targets 86 environment var...

Red Hat npm Namespace Hijacked in Supply Chain hit by cyberattack

Incident
H score13 First: 01.06.2026 20:40 Last: 01.06.2026 20:40 Sources 1

About this happening: Red Hat's official npm namespace was hijacked in a supply chain attack that republished 32 packages in the @redhat-cloud-services scope on June 1, 2026. The ma...

JINX-0164 cryptocurrency recruitment-lure campaign

Campaign
H score39 First: 28.05.2026 10:54 Last: 28.05.2026 10:54 Sources 1

About this happening: A JINX-0164 campaign is targeting cryptocurrency firms and developers with LinkedIn recruiter lures, a fake meeting-and-fix workflow, and macOS malware to steal cr...

Timeline

  1. 04.08.2026 16:30 2 articles · 2h ago

    [email protected] launches a credential-stealing npm worm across the registry

    Initial Disclosure

    The first confirmed malicious release, [email protected], spread a credential-stealing npm worm beyond the Keyv and Cacheable namespaces into hundreds of packages across multiple organizations on August 4, 2026.

    Show sources
  2. 04.08.2026 16:30 1 articles · 2h ago

    Aikido places the npm worm in the Shai-Hulud family

    Attribution Update

    SafeDep and Socket describe a malicious preinstall bundle that runs in developer and CI environments, harvests GitHub, npm, cloud, Vault, Kubernetes, database, and private-key material, and can use stolen npm access to poison more packages; the repository also retained Claude Code and VS Code hook paths, and Aikido places the August activity in the Shai-Hulud family while the initial access path and named operator remain unknown.

    Show sources