Shai-Hulud npm Payload Resurfaces After 111 Days Dormancy

Shai-Hulud npm Payload Resurfaces After 111 Days Dormancy

First seen 9 Sep 2026, 13:45 UTC Aikido.DevItpro 69.0

Article Content

Browse articles
ThreatCluster

A known malicious npm payload, associated with the Shai-Hulud attack on @AntV, has resurfaced after 111 days of inactivity. The original attack occurred on May 19, 2026, when a compromised maintainer account published 639 malicious versions of @antv packages. On September 7, 2026, four new packages containing the same malicious payload were uploaded, bypassing npm's newly implemented publish-time malware scanning. The payload's hash, e37e3ddeeaaa9e0c4fdbcb829b4895a6521031c80053fc436625b61e6ee5b1a6, was previously flagged and documented, raising concerns about the effectiveness of npm's scanning measures. Researchers from Aikido Security have noted that the reactivation of this payload indicates a significant gap in the detection capabilities of the npm registry. The packages involved include [email protected], [email protected], and [email protected]. Security teams are advised to monitor for these packages and associated command-and-control domains.

Key Points: • A known npm payload resurfaced after 111 days of inactivity. • Four new packages were uploaded on September 7, 2026, bypassing npm's malware scanning. • The payload's hash had been previously documented and flagged by security vendors.

Ask AI about this cluster

Timeline

2026-05-19
Shai-Hulud attack on @AntV
A compromised maintainer account published 639 malicious npm packages in one hour.
Aikido.Dev
2026-09-07
Resurfacing of Shai-Hulud payload
Four new packages with the same malicious payload were uploaded to npm after a 111-day gap.
Itpro