Gallery

Contacts

411 University St, Seattle, USA

engitech@oceanthemes.net

+1 -800-456-478-23

A leaked infostealer toolkit called Shai-Hulud has been weaponized by a second, unidentified threat actor who published four malicious packages to the npm registry, targeting Node.js developers who use the Axios HTTP library. The packages steal cloud credentials (AWS, GCP, Azure), cryptocurrency wallet data, and developer secrets, while at least one package also recruits infected machines into a DDoS botnet. Any organization with Node.js development pipelines that installed one of the four typosquatted packages may have exposed cloud infrastructure credentials and is at elevated risk of further compromise.

Author

Tech Jacks Solutions