Itpro
Shai-Hulud npm Payload Resurfaces After 111 Days Dormancy
Article Content
A known malicious npm payload, associated with the Shai-Hulud attack on @AntV, has resurfaced after 111 days of inactivity. The original attack occurred on May 19, 2026, when a compromised maintainer account published 639 malicious versions of @antv packages. On September 7, 2026, four new packages containing the same malicious payload were uploaded, bypassing npm's newly implemented publish-time malware scanning. The payload's hash, e37e3ddeeaaa9e0c4fdbcb829b4895a6521031c80053fc436625b61e6ee5b1a6, was previously flagged and documented, raising concerns about the effectiveness of npm's scanning measures. Researchers from Aikido Security have noted that the reactivation of this payload indicates a significant gap in the detection capabilities of the npm registry. The packages involved include [email protected], [email protected], and [email protected]. Security teams are advised to monitor for these packages and associated command-and-control domains.
Key Points: • A known npm payload resurfaced after 111 days of inactivity. • Four new packages were uploaded on September 7, 2026, bypassing npm's malware scanning. • The payload's hash had been previously documented and flagged by security vendors.
Ask AI about this cluster
Answers cite the sources they use
Analyzing cluster data...
Referenced clusters
Something went wrong. Please try again.