Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Malicious npm Packages Compromise Developer Credentials

Malicious npm Packages Compromise Developer Credentials

Posted on June 25, 2026 By CWS

A recent threat, identified as the Shai-Hulud payload, is compromising developers who work with cloud and serverless infrastructures by deploying malicious npm packages. This attack, linked to the Hades malware family, has expanded to the Leo/RStreams ecosystem, a widely-used library for AWS-native event streaming and data pipelines. Security researchers have raised concerns over this attack, which discreetly steals sensitive developer credentials upon installation of these packages.

Understanding the Threat

The Shai-Hulud payload operates by deeply embedding itself into the systems of affected developers. Upon installing a compromised package, it begins to harvest credentials from various sources such as files, environment variables, shell history, and GitHub CLI tokens. Additionally, it targets cloud access keys and CI/CD pipeline secrets, transmitting all collected data to attacker-controlled GitHub repositories. The extent of this breach is significant, with the affected packages being downloaded approximately 45,000 times in just one month, potentially impacting thousands of developers.

Technical Details and Implications

Detailed analysis by JFrog Security Research, as shared with Cyber Security News, reveals that although this threat is not new, it has been adapted with new targets and updated identifiers. The compromised libraries, central to cloud-native development workflows, integrate with AWS services like Kinesis, S3, and Lambda. This positioning allows a single compromised installation to expose more than just the developer’s local environment, potentially affecting broader cloud credentials and deployment tokens.

The Shai-Hulud operation remains active, with attackers recycling the payload and directing it towards new, trusted package families. This makes detection challenging, as reliance on outdated campaign names or signatures may result in missed threats.

Mitigation and Security Recommendations

To evade detection, the attackers use a sophisticated method by embedding execution commands within a file named binding.gyp, bypassing standard npm install script checks. Once deployed, the payload seeks out credentials from diverse sources such as GitHub tokens, npm publishing credentials, AWS access keys, and SSH keys. The stolen data is then encrypted and exfiltrated through a technique known as GitHub dead drop.

In response, JFrog advises isolating affected machines and CI runners before rotating any credentials. All persistence mechanisms, including system services and suspicious workflow files, should be eliminated. Following cleanup, it’s crucial to rotate GitHub, npm, cloud, SSH, Docker, and package registry credentials. Additionally, GitHub and npm accounts should be audited for any unexpected changes or releases.

Security experts also recommend continuous monitoring and updating of security measures to defend against such sophisticated threats. By staying informed and vigilant, developers and organizations can better safeguard their environments against future attacks.

Cyber Security News Tags:CI/CD, cloud infrastructure, cloud security, credential theft, cybersecurity news, data exfiltration, developer security, GitHub, Hades malware, JFrog Security Research, Leo/RStreams, Malware, NPM, Shai-Hulud payload, SSH keys

Post navigation

Previous Post: Lantronix Device Vulnerability Exploited in OT Attacks
Next Post: Popular Chrome Ad Blocker Raises Security Concerns

Related Posts

New Streamlit Vulnerability Allows Hackers to Launch Cloud Account Takeover Attacks New Streamlit Vulnerability Allows Hackers to Launch Cloud Account Takeover Attacks Cyber Security News
Vortex Werewolf Targets Russian Networks with Tor Vortex Werewolf Targets Russian Networks with Tor Cyber Security News
Halo Security Honored with 2025 MSP Today Product of the Year Award Halo Security Honored with 2025 MSP Today Product of the Year Award Cyber Security News
5 Email Attacks SOCs Cannot Detect Without A Sandbox  5 Email Attacks SOCs Cannot Detect Without A Sandbox  Cyber Security News
TanStack npm Packages Compromised in Major Attack TanStack npm Packages Compromised in Major Attack Cyber Security News
Mustang Panda Launches Complex PlugX RAT Cyberattack Mustang Panda Launches Complex PlugX RAT Cyberattack Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Microsoft Secure Boot Certificate Expiry Impacts Billions
  • Curl’s 25-Year Security Flaw Patched in Major Update
  • Popular Chrome Ad Blocker Raises Security Concerns
  • Malicious npm Packages Compromise Developer Credentials
  • Lantronix Device Vulnerability Exploited in OT Attacks

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Microsoft Secure Boot Certificate Expiry Impacts Billions
  • Curl’s 25-Year Security Flaw Patched in Major Update
  • Popular Chrome Ad Blocker Raises Security Concerns
  • Malicious npm Packages Compromise Developer Credentials
  • Lantronix Device Vulnerability Exploited in OT Attacks

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark