Skip to content
ThreatCluster

ShadowPad Attack Exploits WSUS Vulnerability Affecting 25K+ npm Repos

First seen 7 Dec 2025, 20:47 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •March 12, 2026 at 13:27 UTC

The ShadowPad malware attack has exploited a remote code execution vulnerability (CVE-2025-59287) in Windows Server Update Services (WSUS). This incident has exposed over 25,000 npm repositories, allowing cyber threat actors to target users of messaging applications. Morphisec has reported that the attack is linked to Russian cyber operations.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 212d ago How this analysis works

More articles in this cluster (2)

Following this threat?

Track Shai-hulud 2.0 and CVE-2025-59287 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed