Shai-Hulud credential-stealing npm worm spreading through poisoned package releases
Malware Activity
Summary
Hide ▲
Show ▼
A credential-stealing npm worm spread through poisoned package releases on August 4, 2026, exposing developer and CI credentials and broadening supply-chain risk. The activity began with [email protected] and quickly extended beyond the original namespace into hundreds of packages.
Related Happenings
Rollup polyfill npm package malware activity for remote access and data theft
Malware Activity
H score16
First: 03.07.2026 19:07
Last: 03.07.2026 19:07
Sources 1
About this happening:
Malicious npm packages disguised as Rollup polyfill tooling are now delivering remote-access and data-theft payloads to developer workstations and build machines. The...
Rollup polyfill npm package malware activity for remote access and data theft
Malware ActivityAbout this happening: Malicious npm packages disguised as Rollup polyfill tooling are now delivering remote-access and data-theft payloads to developer workstations and build machines. The...
Shai-Hulud PyPI supply-chain malware activity
Malware Activity
H score22
First: 08.06.2026 23:41
Last: 08.06.2026 23:41
Sources 1
About this happening:
The Shai-Hulud supply-chain malware compromised 19 PyPI packages, turning routine installs into secret-stealing execution and putting developer credentials at risk. Th...
Shai-Hulud PyPI supply-chain malware activity
Malware ActivityAbout this happening: The Shai-Hulud supply-chain malware compromised 19 PyPI packages, turning routine installs into secret-stealing execution and putting developer credentials at risk. Th...
IronWorm npm supply-chain infection and self-propagation
Malware Activity
H score15
First: 04.06.2026 18:25
Last: 04.06.2026 18:25
Sources 1
About this happening:
IronWorm is a Rust infostealer in a npm supply-chain activity that hides behind an eBPF kernel rootkit, communicates over Tor, and targets 86 environment var...
IronWorm npm supply-chain infection and self-propagation
Malware ActivityAbout this happening: IronWorm is a Rust infostealer in a npm supply-chain activity that hides behind an eBPF kernel rootkit, communicates over Tor, and targets 86 environment var...
Red Hat npm Namespace Hijacked in Supply Chain hit by cyberattack
Incident
H score13
First: 01.06.2026 20:40
Last: 01.06.2026 20:40
Sources 1
About this happening:
Red Hat's official npm namespace was hijacked in a supply chain attack that republished 32 packages in the @redhat-cloud-services scope on June 1, 2026. The ma...
Red Hat npm Namespace Hijacked in Supply Chain hit by cyberattack
IncidentAbout this happening: Red Hat's official npm namespace was hijacked in a supply chain attack that republished 32 packages in the @redhat-cloud-services scope on June 1, 2026. The ma...
JINX-0164 cryptocurrency recruitment-lure campaign
Campaign
H score39
First: 28.05.2026 10:54
Last: 28.05.2026 10:54
Sources 1
About this happening:
A JINX-0164 campaign is targeting cryptocurrency firms and developers with LinkedIn recruiter lures, a fake meeting-and-fix workflow, and macOS malware to steal cr...
JINX-0164 cryptocurrency recruitment-lure campaign
CampaignAbout this happening: A JINX-0164 campaign is targeting cryptocurrency firms and developers with LinkedIn recruiter lures, a fake meeting-and-fix workflow, and macOS malware to steal cr...
Timeline
-
04.08.2026 16:30 2 articles · 2h ago
[email protected] launches a credential-stealing npm worm across the registry
Initial DisclosureThe first confirmed malicious release, [email protected], spread a credential-stealing npm worm beyond the Keyv and Cacheable namespaces into hundreds of packages across multiple organizations on August 4, 2026.
Show sources
- Keyv-Linked npm Worm Poisons Hundreds of Packages, Plants Claude Code and VS Code Hooks — thehackernews.com — 04.08.2026 16:30
- Keyv-Linked npm Worm Poisons Hundreds of Packages, Plants Claude Code and VS Code Hooks — thehackernews.com — 04.08.2026 16:30
-
04.08.2026 16:30 1 articles · 2h ago
Aikido places the npm worm in the Shai-Hulud family
Attribution UpdateSafeDep and Socket describe a malicious preinstall bundle that runs in developer and CI environments, harvests GitHub, npm, cloud, Vault, Kubernetes, database, and private-key material, and can use stolen npm access to poison more packages; the repository also retained Claude Code and VS Code hook paths, and Aikido places the August activity in the Shai-Hulud family while the initial access path and named operator remain unknown.
Show sources
- Keyv-Linked npm Worm Poisons Hundreds of Packages, Plants Claude Code and VS Code Hooks — thehackernews.com — 04.08.2026 16:30