s2
--:--:--UTC

Searching APEX

Starting…

  1. ○ Searching Threats, IOCs & Threat Intelligence locally
  2. ○ Querying external providers
  3. ○ Asking AI Forensic Validator
  4. ○ Creating new entry from validated hit

0s elapsed

TF-1814948 high

📛 Threat Title

Shai-Hulud: SHA256 hash of a malware sample (payload) 18f784b3bc9a0bcdcb1a8d7f51bc5f54323fc40cbd874119354ab609bef6e4cb

Category: Shai-Hulud Published: Source updated: First seen: Last updated: Source: Threatfox IOCs/Threats

Description

Indicator that identifies a malware sample (payload). IOC type: SHA256 hash of a malware sample (payload). Attributed malware: Shai-Hulud. Confidence: 75. First seen: 2026-05-15 15:00:57 UTC. Reporter: TheRavenFile. Tags: js, npm, shai-hulud, supply chain attack.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

hash_sha256 18f784b3bc9a0bcdcb1a8d7f51bc5f54323fc40cbd874119354ab609bef6e4cb VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/18f784b3bc9a0bcdcb1a8d7f51bc5f54323fc40cbd874119354ab609bef6e4cb

IOC database

Type
hash_sha256
Value
18f784b3bc9a0bcdcb1a8d7f51bc5f54323fc40cbd874119354ab609bef6e4cb
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
SHA256 hash of a malware sample (payload) attributed to Shai-Hulud

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/18f784b3bc9a0bcdcb1a8d7f51bc5f54323fc40cbd874119354ab609bef6e4cb

References (3)

  • External reference Threatfox IOCs/Threats
  • Malpedia profile Threatfox IOCs/Threats
  • ThreatFox IOC page Threatfox IOCs/Threats

    Indicator that identifies a malware sample (payload). IOC type: SHA256 hash of a malware sample (payload). Attributed malware: Shai-Hulud. Confidence: 75. First seen: 2026-05-15 15:00:57 UTC. Reporter: TheRavenFile. Tags: js, npm, shai-hulud, supply chain attack.

Remediations (8)

  • web:help.sonatype.com

    These attacks are sophisticated, with payloads designed to steal credentials, exfiltrate sensitive data, and even self-propagate like a worm; an incredibly dangerous adaptation for malware . An evolution in the Shai-Hulud campaign (Sonatype ID: sonatype-2025-007248) added new techniques for faster, more disruptive self-propagation.

  • web:hodeitek.com

    The Shai-Hulud v2 malware is the latest reminder that software supply-chain attacks have become a persistent, high-impact risk for any organization that builds, ships, or relies on JavaScript and Node.js. As reported by The Hacker News, researchers observed a new wave of malicious npm packages distributing the Shai-Hulud v2 malware through developer workflows, abusing trust in open-source ...

  • web:safedep.io

    Critical npm supply chain attack compromises zapier-sdk, @asyncapi, posthog, and @postman packages with self-replicating malware . Technical analysis reveals credential harvesting, GitHub Actions exploitation, and worm-like propagation affecting 25,000+ repositories. Includes IOCs, detection methods, and remediation steps.

  • web:threatprotect.qualys.com

    A renewed and intensified npm supply chain attack campaign linked to the original Shai-Hulud malware is making headlines. This campaign, active from November 21 to 23, 2025, comprises popular npm packages from major publishers, including Maven, Zapier, ENS Domains, PostHog, and Postman.

  • web:www.microsoft.com

    The Shai‑Hulud 2.0 supply chain attack represents one of the most significant cloud-native ecosystem compromises observed recently.

  • web:www.ox.security

    The Infamous Credential Stealing Malware Once Again Hits npm & PyPi, Affecting Many Including Mistral AI, OpenSearch Project, TanStack. Breaking News: Shai-Hulud malware spreads again in npm and PyPi, stealing credentials and self-propagating. Currently with over 170+ packages affected, over 518M monthly downloads in total. Overview Shai-Hulud is a self spreading malware , which we extensively ...

  • web:www.upguard.com

    Learn about the Shai-Hulud worm, a self-replicating malware targeting the NPM ecosystem that steals developer credentials and exposes them.

  • web:www.wiz.io

    Shai-Hulud 2.0 Supply Chain Attack: 25K+ Repos Exposing Secrets Detect and mitigate malicious npm packages linked to the recent Shai - Hulud -style campaign. Over 25,000 affected repositories across ~350 unique users.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.