s2
--:--:--UTC

Searching APEX

Starting…

  1. ○ Searching Threats, IOCs & Threat Intelligence locally
  2. ○ Querying external providers
  3. ○ Asking AI Forensic Validator
  4. ○ Creating new entry from validated hit

0s elapsed

TF-1814949 high

📛 Threat Title

Shai-Hulud: SHA256 hash of a malware sample (payload) 0fa99abf2a5af168ffc2b44bcf88020600bb2521b20d4e3367a2c1e996f71b8f

Category: Shai-Hulud Published: Source updated: First seen: Last updated: Source: Threatfox IOCs/Threats

Description

Indicator that identifies a malware sample (payload). IOC type: SHA256 hash of a malware sample (payload). Attributed malware: Shai-Hulud. Confidence: 75. First seen: 2026-05-15 15:00:57 UTC. Reporter: TheRavenFile. Tags: js, npm, shai-hulud, supply chain attack.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

hash_sha256 0fa99abf2a5af168ffc2b44bcf88020600bb2521b20d4e3367a2c1e996f71b8f VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/0fa99abf2a5af168ffc2b44bcf88020600bb2521b20d4e3367a2c1e996f71b8f

IOC database

Type
hash_sha256
Value
0fa99abf2a5af168ffc2b44bcf88020600bb2521b20d4e3367a2c1e996f71b8f
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
SHA256 hash of a malware sample (payload) attributed to Shai-Hulud

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/0fa99abf2a5af168ffc2b44bcf88020600bb2521b20d4e3367a2c1e996f71b8f

References (3)

  • External reference Threatfox IOCs/Threats
  • Malpedia profile Threatfox IOCs/Threats
  • ThreatFox IOC page Threatfox IOCs/Threats

    Indicator that identifies a malware sample (payload). IOC type: SHA256 hash of a malware sample (payload). Attributed malware: Shai-Hulud. Confidence: 75. First seen: 2026-05-15 15:00:57 UTC. Reporter: TheRavenFile. Tags: js, npm, shai-hulud, supply chain attack.

Remediations (8)

  • web:aws.amazon.com

    The very next week, the Shai-Hulud worm started to spread autonomously through the npm trust chain. This malware uses its initial foothold in a developer's environment to harvest a variety of credentials, such as npm tokens, GitHub personal access tokens, and cloud credentials.

  • web:safedep.io

    Critical npm supply chain attack compromises zapier-sdk, @asyncapi, posthog, and @postman packages with self-replicating malware . Technical analysis reveals credential harvesting, GitHub Actions exploitation, and worm-like propagation affecting 25,000+ repositories. Includes IOCs, detection methods, and remediation steps.

  • web:threatprotect.qualys.com

    A renewed and intensified npm supply chain attack campaign linked to the original Shai-Hulud malware is making headlines. This campaign, active from November 21 to 23, 2025, comprises popular npm packages from major publishers, including Maven, Zapier, ENS Domains, PostHog, and Postman.

  • web:www.endorlabs.com

    Analysis of Shai-Hulud 2, a new npm supply chain attack using Bun for execution, credential theft, and CI/CD propagation, with mitigation guidance.

  • web:www.microsoft.com

    The Shai‑Hulud 2.0 supply chain attack represents one of the most significant cloud-native ecosystem compromises observed recently.

  • web:www.ox.security

    The Infamous Credential Stealing Malware Once Again Hits npm & PyPi, Affecting Many Including Mistral AI, OpenSearch Project, TanStack. Breaking News: Shai-Hulud malware spreads again in npm and PyPi, stealing credentials and self-propagating. Currently with over 170+ packages affected, over 518M monthly downloads in total. Overview Shai-Hulud is a self spreading malware , which we extensively ...

  • web:www.upguard.com

    Learn about the Shai-Hulud worm, a self-replicating malware targeting the NPM ecosystem that steals developer credentials and exposes them.

  • web:www.wiz.io

    Shai-Hulud 2.0 Supply Chain Attack: 25K+ Repos Exposing Secrets Detect and mitigate malicious npm packages linked to the recent Shai - Hulud -style campaign. Over 25,000 affected repositories across ~350 unique users.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.