Shai-Hulud npm payload reemerges after 111 days, slipping past npm's malware scanning
jedisct1 · x · 2026-09-07
Security researcher Charlie Eriksen reports that the Shai-Hulud payload behind May's @AntV npm attack has resurfaced with the exact same file hash, 111 days after going dark — the longest dormancy-to-reactivation gap seen from this worm.
Key facts:
- npm introduced publish-time malware scanning, yet the payload — already fingerprinted by npm and multiple vendors months ago — passed through
- Four packages published within one hour on Sep 7 by the same account carried it: [email protected], [email protected], [email protected], [email protected]
- Detection history shows 319 package versions carrying this hash
Dubbed a "zombie," the reactivation shows known supply-chain attack payloads can lie dormant for months and bypass npm's publish-time scanning.
More from coding & agent
- One line in agents.md is all it takes to bend Astra to your will, says prompt guide — pvncher · 2026-09-07
- Developer on Astra: code as unreadable as minified JS, but tolerable to boss around — Aryvyo · 2026-09-07
- Your LLM Gateway Holds the Keys: Rethinking LiteLLM Security for Action-Taking Agents — Technical_Map_2105 · 2026-09-07
- Zero Blender skills, one prompt, 40 minutes: recreating a game with Codex — FuSheng_0306 · 2026-09-07
- LLM-powered revival of Put-That-There brings speech and gesture window control to XR — twi_mar · 2026-09-07
- 18-year-old dev builds post-apocalyptic Godot game scene via Blender MCP in half a day — majidmanzarpour · 2026-09-07