TF-1814949
high
📛 Threat Title
Shai-Hulud: SHA256 hash of a malware sample (payload) 0fa99abf2a5af168ffc2b44bcf88020600bb2521b20d4e3367a2c1e996f71b8f
Description
Indicator that identifies a malware sample (payload). IOC type: SHA256 hash of a malware sample (payload). Attributed malware: Shai-Hulud. Confidence: 75. First seen: 2026-05-15 15:00:57 UTC. Reporter: TheRavenFile. Tags: js, npm, shai-hulud, supply chain attack.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
hash_sha256
0fa99abf2a5af168ffc2b44bcf88020600bb2521b20d4e3367a2c1e996f71b8f
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/0fa99abf2a5af168ffc2b44bcf88020600bb2521b20d4e3367a2c1e996f71b8f
IOC database
- Type
- hash_sha256
- Value
0fa99abf2a5af168ffc2b44bcf88020600bb2521b20d4e3367a2c1e996f71b8f- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- SHA256 hash of a malware sample (payload) attributed to Shai-Hulud
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/0fa99abf2a5af168ffc2b44bcf88020600bb2521b20d4e3367a2c1e996f71b8f
References (3)
- External reference Threatfox IOCs/Threats
- Malpedia profile Threatfox IOCs/Threats
-
ThreatFox IOC page
Threatfox IOCs/Threats
Indicator that identifies a malware sample (payload). IOC type: SHA256 hash of a malware sample (payload). Attributed malware: Shai-Hulud. Confidence: 75. First seen: 2026-05-15 15:00:57 UTC. Reporter: TheRavenFile. Tags: js, npm, shai-hulud, supply chain attack.
Remediations (8)
-
web:aws.amazon.com
The very next week, the Shai-Hulud worm started to spread autonomously through the npm trust chain. This malware uses its initial foothold in a developer's environment to harvest a variety of credentials, such as npm tokens, GitHub personal access tokens, and cloud credentials.
-
web:safedep.io
Critical npm supply chain attack compromises zapier-sdk, @asyncapi, posthog, and @postman packages with self-replicating malware . Technical analysis reveals credential harvesting, GitHub Actions exploitation, and worm-like propagation affecting 25,000+ repositories. Includes IOCs, detection methods, and remediation steps.
-
web:threatprotect.qualys.com
A renewed and intensified npm supply chain attack campaign linked to the original Shai-Hulud malware is making headlines. This campaign, active from November 21 to 23, 2025, comprises popular npm packages from major publishers, including Maven, Zapier, ENS Domains, PostHog, and Postman.
-
web:www.endorlabs.com
Analysis of Shai-Hulud 2, a new npm supply chain attack using Bun for execution, credential theft, and CI/CD propagation, with mitigation guidance.
-
web:www.microsoft.com
The Shai‑Hulud 2.0 supply chain attack represents one of the most significant cloud-native ecosystem compromises observed recently.
-
web:www.ox.security
The Infamous Credential Stealing Malware Once Again Hits npm & PyPi, Affecting Many Including Mistral AI, OpenSearch Project, TanStack. Breaking News: Shai-Hulud malware spreads again in npm and PyPi, stealing credentials and self-propagating. Currently with over 170+ packages affected, over 518M monthly downloads in total. Overview Shai-Hulud is a self spreading malware , which we extensively ...
-
web:www.upguard.com
Learn about the Shai-Hulud worm, a self-replicating malware targeting the NPM ecosystem that steals developer credentials and exposes them.
-
web:www.wiz.io
Shai-Hulud 2.0 Supply Chain Attack: 25K+ Repos Exposing Secrets Detect and mitigate malicious npm packages linked to the recent Shai - Hulud -style campaign. Over 25,000 affected repositories across ~350 unique users.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.