Executive Summary
In May 2026, a threat actor using the alias 'deadcode09284814' published four malicious packages on the npm registry, embedding a non-obfuscated version of the Shai-Hulud malware. These packages targeted developer credentials, secrets, cryptocurrency wallet data, and account information. Notably, one package also transformed infected systems into bots for distributed denial-of-service (DDoS) attacks. The malicious packages included 'chalk-tempalte', '@deadcode09284814/axios-util', 'axois-utils', and 'color-style-utils'. Researchers at OXsecurity identified these uploads, highlighting the use of typosquatting techniques to deceive developers. The 'chalk-tempalte' package contained a direct clone of the Shai-Hulud malware, originally attributed to the TeamPCP hacker group, indicating that other actors are now leveraging the leaked source code. This incident underscores the persistent threat of supply chain attacks within the open-source ecosystem, emphasizing the need for developers to exercise caution when integrating third-party packages. The reuse of the Shai-Hulud malware by different threat actors highlights the rapid dissemination and adaptation of malicious tools, posing ongoing risks to software supply chains.
Why This Matters Now
The rapid adaptation and deployment of the Shai-Hulud malware by new threat actors underscore the escalating risks in software supply chains. Developers must remain vigilant, as the open-source ecosystem continues to be a prime target for sophisticated attacks that can compromise sensitive data and system integrity.
Attack Path Analysis
The attack began with the publication of malicious npm packages containing the Shai-Hulud malware, leading to the compromise of developer systems upon installation. The malware then escalated privileges by harvesting sensitive credentials, including GitHub tokens and cloud API keys. Utilizing these credentials, the attackers moved laterally to infect additional repositories and systems. The compromised systems established command and control channels to exfiltrate stolen data to attacker-controlled servers. Exfiltrated data included developer credentials, secrets, and cryptocurrency wallet information. The impact of the attack was significant, resulting in unauthorized access to sensitive information and potential financial loss.
Kill Chain Progression
Initial Compromise
Description
Malicious npm packages containing the Shai-Hulud malware were published, leading to the compromise of developer systems upon installation.
MITRE ATT&CK® Techniques
Supply Chain Compromise: Compromise Software Dependencies and Development Tools
Valid Accounts
Unsecured Credentials: Credentials in Files
System Information Discovery
Exfiltration Over Web Service
Network Denial of Service
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Ensure the integrity of software and scripts
Control ID: 6.3.2
NYDFS 23 NYCRR 500 – Cybersecurity Policy
Control ID: 500.03
DORA – ICT Risk Management Framework
Control ID: Article 6
CISA ZTMM 2.0 – Data Security
Control ID: Pillar 3: Data
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Computer Software/Engineering
Supply chain attacks targeting npm packages directly compromise development environments, stealing credentials and secrets through malicious dependencies like Shai-Hulud clones.
Information Technology/IT
IT infrastructure faces credential theft and DDoS botnet recruitment through compromised npm packages, requiring immediate credential rotation and enhanced egress filtering.
Financial Services
Cryptocurrency wallet data theft and credential exfiltration expose financial institutions to regulatory violations and customer data breaches through developer workstation compromises.
Computer/Network Security
Security firms must address multi-vector attacks combining supply chain compromise with DDoS capabilities, demonstrating sophisticated threat actor evolution beyond traditional boundaries.
Sources
- Leaked Shai-Hulud malware fuels new npm infostealer campaignhttps://www.bleepingcomputer.com/news/security/leaked-shai-hulud-malware-fuels-new-npm-infostealer-campaign/Verified
- Shai-Hulud copycat hits another npm packagehttps://www.theregister.com/cyber-crime/2026/05/18/shai_hulud_copycat_hits_another_npm_package/Verified
- Shai Hulud attack ships signed malicious TanStack, Mistral npm packageshttps://www.bleepingcomputer.com/news/security/shai-hulud-attack-ships-signed-malicious-tanstack-mistral-npm-packages/Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Aviatrix Zero Trust CNSF is pertinent to this incident as it could have constrained the attacker's ability to move laterally and exfiltrate data by enforcing strict segmentation and controlled egress policies.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: The CNSF may have limited the malware's ability to communicate with external command and control servers, reducing the attacker's control over compromised systems.
Control: Zero Trust Segmentation
Mitigation: Zero Trust Segmentation would likely have constrained the malware's ability to access sensitive resources, limiting the scope of privilege escalation.
Control: East-West Traffic Security
Mitigation: East-West Traffic Security may have restricted unauthorized internal communications, thereby limiting the attacker's ability to move laterally within the network.
Control: Multicloud Visibility & Control
Mitigation: Multicloud Visibility & Control would likely have detected and constrained unauthorized outbound communications, reducing the effectiveness of command and control channels.
Control: Egress Security & Policy Enforcement
Mitigation: Egress Security & Policy Enforcement may have restricted unauthorized data exfiltration, limiting the attacker's ability to transfer sensitive information out of the network.
The implementation of Aviatrix Zero Trust CNSF would likely have reduced the overall impact by limiting the attacker's ability to access and exfiltrate sensitive data.
Impact at a Glance
Affected Business Functions
- Software Development
- Continuous Integration/Continuous Deployment (CI/CD)
- Cloud Infrastructure Management
Estimated downtime: 3 days
Estimated loss: $50,000
Developer credentials, cloud service API keys, and cryptocurrency wallet information were exfiltrated, potentially compromising sensitive projects and financial assets.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust Segmentation to restrict access and limit lateral movement within the network.
- • Enforce Egress Security & Policy Enforcement to monitor and control outbound traffic, preventing unauthorized data exfiltration.
- • Utilize Multicloud Visibility & Control to detect and respond to anomalous activities across cloud environments.
- • Deploy Inline IPS (Suricata) to identify and block known exploit patterns and malicious payloads.
- • Regularly audit and monitor software dependencies to detect and mitigate supply chain compromises.



