Shai-Hulud npm payload reemerges after 111 days, slipping past npm's malware scanning

jedisct1 · x · 2026-09-07

Security researcher Charlie Eriksen reports that the Shai-Hulud payload behind May's @AntV npm attack has resurfaced with the exact same file hash, 111 days after going dark — the longest dormancy-to-reactivation gap seen from this worm.

Key facts:

Dubbed a "zombie," the reactivation shows known supply-chain attack payloads can lie dormant for months and bypass npm's publish-time scanning.

Original post →

More from coding & agent

coding & agent channel →