Close Menu
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
What's Hot

Four malicious npm packages deliver information theft and Phantom Bot DDoS malware

Organ-on-a-chip project investigates the relationship between diabetes and dementia

How Wildfire Protection, Inc. improves wildfire preparedness

Facebook X (Twitter) Instagram
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
Facebook X (Twitter) Instagram
Fyself News
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
Fyself News
Home » Four malicious npm packages deliver information theft and Phantom Bot DDoS malware
Identity

Four malicious npm packages deliver information theft and Phantom Bot DDoS malware

By May 18, 2026No Comments3 Mins Read
Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
Follow Us
Google News Flipboard
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

Ravi LakshmananMay 18, 2026Supply chain attack/botnet

Cybersecurity researchers have discovered four new npm packages containing information-stealing malware. One of them is a clone of the Shai-Hulud worm that was open sourced by TeamPCP.

The list of identified packages is below –

chalk-tempalte (825 downloads) @deadcode09284814/axios-util (284 downloads) axois-utils (963 downloads) color-style-utils (934 downloads)

“One of the packages (Choke Tempult) contains a direct clone of the Shai-Hulud source code that TeamPCP leaked last week, likely inspired as part of a supply chain attack contest published on BreachForums shortly thereafter,” said Moshe Siman Tov Bustan of OX Security.

Interestingly, the malicious payloads embedded in the four npm packages are different, even though they are published by the same npm user ‘deadcode09284814’. As of this writing, four libraries are still available for download from npm.

Analysis of the package revealed that ‘axois-utils’ is designed to deliver a Golang-based distributed denial of service (DDoS) botnet called Phantom Bot, with the ability to flood target websites using HTTP, TCP, and UDP protocols. It also establishes persistence on both Windows and Linux machines by adding the payload to the Windows startup folder and creating a scheduled task.

The remaining three drop stealer payloads on compromised systems. Of the three packages, the “chalk-tempalte” package contains a clone of the Shai-Hulud worm released by TeamPCP.

“The attackers took the code with few modifications and uploaded a working version to npm, including their own C2 server and private key,” OX Security said. “Stolen credentials are sent to a remote C2 server — 87e0bbc636999b.lhr”[.]life”

Additionally, the data is exported via the API to a new GitHub public repository using the stolen GitHub token. The repository has the description “A Mini Sha1-Hulud has appeared.”

Two other npm packages, ‘@deadcode09284814/axios-util’ and ‘color-style-utils’, have more direct functionality to siphon SSH keys, environment variables, cloud credentials, system information, IP addresses, and cryptocurrency wallet data to ‘80.200.28’.[.]28:2222” and “edcf8b03c84634.lhr”[.]Life”, respectively.

“The open sourcing of the Shai-Hulud code makes it easier to carry out attacks, giving threat actors even more incentive to engage in supply chain and typosquatting,” OX Security said. “We are currently seeing a single attacker with multiple techniques and information-stealing capabilities spreading malicious code to npm. This is just the first phase of a wave of supply chain attacks to come.”

Users who have downloaded the package should immediately uninstall the package, find and remove the malicious configuration from their IDE or coding agent like Claude Code, rotate secrets, check for GitHub repositories containing the string “A Mini Sha1-Hulud has Appeared,” and block network access to suspicious domains.


Source link

#BlockchainIdentity #Cybersecurity #DataProtection #DigitalEthics #DigitalIdentity #Privacy
Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticleOrgan-on-a-chip project investigates the relationship between diabetes and dementia

Related Posts

Stuxnet Fast16 and earlier malware tampers with nuclear weapon simulation

May 18, 2026

MiniPlasma Windows 0-Day enables SYSTEM privilege escalation on fully patched systems

May 18, 2026

NGINX CVE-2026-42945 can be exploited in the wild to cause worker crash and possible RCE

May 17, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest Posts

Four malicious npm packages deliver information theft and Phantom Bot DDoS malware

Organ-on-a-chip project investigates the relationship between diabetes and dementia

How Wildfire Protection, Inc. improves wildfire preparedness

Stuxnet Fast16 and earlier malware tampers with nuclear weapon simulation

Trending Posts

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Please enable JavaScript in your browser to complete this form.
Loading

Welcome to Fyself News, your go-to platform for the latest in tech, startups, inventions, sustainability, and fintech! We are a passionate team of enthusiasts committed to bringing you timely, insightful, and accurate information on the most pressing developments across these industries. Whether you’re an entrepreneur, investor, or just someone curious about the future of technology and innovation, Fyself News has something for you.

Castilla-La Mancha Ignites Innovation: fiveclmsummit Redefines Tech Future

Local Power, Health Innovation: Alcolea de Calatrava Boosts FiveCLM PoC with Community Engagement

The Future of Digital Twins in Healthcare: From Virtual Replicas to Personalized Medical Models

Human Digital Twins: The Next Tech Frontier Set to Transform Healthcare and Beyond

Facebook X (Twitter) Instagram Pinterest YouTube
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
© 2026 news.fyself. Designed by by fyself.

Type above and press Enter to search. Press Esc to cancel.