TF-1814948
high
📛 Threat Title
Shai-Hulud: SHA256 hash of a malware sample (payload) 18f784b3bc9a0bcdcb1a8d7f51bc5f54323fc40cbd874119354ab609bef6e4cb
Description
Indicator that identifies a malware sample (payload). IOC type: SHA256 hash of a malware sample (payload). Attributed malware: Shai-Hulud. Confidence: 75. First seen: 2026-05-15 15:00:57 UTC. Reporter: TheRavenFile. Tags: js, npm, shai-hulud, supply chain attack.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
hash_sha256
18f784b3bc9a0bcdcb1a8d7f51bc5f54323fc40cbd874119354ab609bef6e4cb
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/18f784b3bc9a0bcdcb1a8d7f51bc5f54323fc40cbd874119354ab609bef6e4cb
IOC database
- Type
- hash_sha256
- Value
18f784b3bc9a0bcdcb1a8d7f51bc5f54323fc40cbd874119354ab609bef6e4cb- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- SHA256 hash of a malware sample (payload) attributed to Shai-Hulud
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/18f784b3bc9a0bcdcb1a8d7f51bc5f54323fc40cbd874119354ab609bef6e4cb
References (3)
- External reference Threatfox IOCs/Threats
- Malpedia profile Threatfox IOCs/Threats
-
ThreatFox IOC page
Threatfox IOCs/Threats
Indicator that identifies a malware sample (payload). IOC type: SHA256 hash of a malware sample (payload). Attributed malware: Shai-Hulud. Confidence: 75. First seen: 2026-05-15 15:00:57 UTC. Reporter: TheRavenFile. Tags: js, npm, shai-hulud, supply chain attack.
Remediations (8)
-
web:help.sonatype.com
These attacks are sophisticated, with payloads designed to steal credentials, exfiltrate sensitive data, and even self-propagate like a worm; an incredibly dangerous adaptation for malware . An evolution in the Shai-Hulud campaign (Sonatype ID: sonatype-2025-007248) added new techniques for faster, more disruptive self-propagation.
-
web:hodeitek.com
The Shai-Hulud v2 malware is the latest reminder that software supply-chain attacks have become a persistent, high-impact risk for any organization that builds, ships, or relies on JavaScript and Node.js. As reported by The Hacker News, researchers observed a new wave of malicious npm packages distributing the Shai-Hulud v2 malware through developer workflows, abusing trust in open-source ...
-
web:safedep.io
Critical npm supply chain attack compromises zapier-sdk, @asyncapi, posthog, and @postman packages with self-replicating malware . Technical analysis reveals credential harvesting, GitHub Actions exploitation, and worm-like propagation affecting 25,000+ repositories. Includes IOCs, detection methods, and remediation steps.
-
web:threatprotect.qualys.com
A renewed and intensified npm supply chain attack campaign linked to the original Shai-Hulud malware is making headlines. This campaign, active from November 21 to 23, 2025, comprises popular npm packages from major publishers, including Maven, Zapier, ENS Domains, PostHog, and Postman.
-
web:www.microsoft.com
The Shai‑Hulud 2.0 supply chain attack represents one of the most significant cloud-native ecosystem compromises observed recently.
-
web:www.ox.security
The Infamous Credential Stealing Malware Once Again Hits npm & PyPi, Affecting Many Including Mistral AI, OpenSearch Project, TanStack. Breaking News: Shai-Hulud malware spreads again in npm and PyPi, stealing credentials and self-propagating. Currently with over 170+ packages affected, over 518M monthly downloads in total. Overview Shai-Hulud is a self spreading malware , which we extensively ...
-
web:www.upguard.com
Learn about the Shai-Hulud worm, a self-replicating malware targeting the NPM ecosystem that steals developer credentials and exposes them.
-
web:www.wiz.io
Shai-Hulud 2.0 Supply Chain Attack: 25K+ Repos Exposing Secrets Detect and mitigate malicious npm packages linked to the recent Shai - Hulud -style campaign. Over 25,000 affected repositories across ~350 unique users.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.