{
  "Event": {
    "analysis": "1",
    "date": "2026-05-12",
    "extends_uuid": "",
    "info": "[Threat Intel] Shai-Hulud-Style npm Worm Hits",
    "protected": false,
    "publish_timestamp": "1785643445",
    "published": true,
    "threat_level_id": "2",
    "timestamp": "1785643444",
    "uuid": "5b26f0df-bf0b-43ee-ac87-c3c444238db7",
    "Orgc": {
      "name": "Rectifyq",
      "uuid": "cd9bd516-61fa-476b-980f-2f8de03992d4"
    },
    "Tag": [
      {
        "colour": "#ac3eed",
        "local": false,
        "name": "misp-galaxy:producer=\"Netskope\"",
        "relationship_type": ""
      },
      {
        "colour": "#ffffff",
        "local": false,
        "name": "tlp:clear",
        "relationship_type": ""
      },
      {
        "colour": "#004646",
        "local": false,
        "name": "type:OSINT",
        "relationship_type": ""
      },
      {
        "colour": "#b94b1d",
        "local": false,
        "name": "rectifyq:mitre-att&ck=\"none-from-src\"",
        "relationship_type": ""
      },
      {
        "colour": "#b94b1d",
        "local": false,
        "name": "rectifyq:mitre-att&ck=\"from-OTX\"",
        "relationship_type": ""
      },
      {
        "colour": "#e7d48a",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"System Owner/User Discovery - T1033\"",
        "relationship_type": ""
      },
      {
        "colour": "#bb2745",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Standard Encoding - T1132.001\"",
        "relationship_type": ""
      },
      {
        "colour": "#d3f567",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"JavaScript - T1059.007\"",
        "relationship_type": ""
      },
      {
        "colour": "#0ee843",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Cloud Instance Metadata API - T1552.005\"",
        "relationship_type": ""
      },
      {
        "colour": "#7d7034",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"System Information Discovery - T1082\"",
        "relationship_type": ""
      },
      {
        "colour": "#f95f85",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Credentials In Files - T1552.001\"",
        "relationship_type": ""
      },
      {
        "colour": "#08221e",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Steal Application Access Token - T1528\"",
        "relationship_type": ""
      },
      {
        "colour": "#a9f8b1",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Exfiltration Over C2 Channel - T1041\"",
        "relationship_type": ""
      },
      {
        "colour": "#83203e",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Cloud Account - T1136.003\"",
        "relationship_type": ""
      },
      {
        "colour": "#71ecdb",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Account Manipulation - T1098\"",
        "relationship_type": ""
      },
      {
        "colour": "#e43954",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Disable or Modify Tools - T1562.001\"",
        "relationship_type": ""
      },
      {
        "colour": "#4a87cb",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Malicious Image - T1204.003\"",
        "relationship_type": ""
      },
      {
        "colour": "#d596aa",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Compromise Software Supply Chain - T1195.002\"",
        "relationship_type": ""
      },
      {
        "colour": "#57b2ae",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Resource Hijacking - T1496\"",
        "relationship_type": ""
      },
      {
        "colour": "#15723e",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Launch Agent - T1543.001\"",
        "relationship_type": ""
      },
      {
        "colour": "#92e858",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Web Protocols - T1071.001\"",
        "relationship_type": ""
      },
      {
        "colour": "#4c0fbb",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Ingress Tool Transfer - T1105\"",
        "relationship_type": ""
      },
      {
        "colour": "#5300bd",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Application Access Token - T1550.001\"",
        "relationship_type": ""
      },
      {
        "colour": "#37c019",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Cloud Accounts - T1078.004\"",
        "relationship_type": ""
      },
      {
        "colour": "#49a260",
        "local": false,
        "name": "rectifyq:category=\"threat\"",
        "relationship_type": ""
      },
      {
        "colour": "#130049",
        "local": false,
        "name": "rectifyq:sub-category=\"campaign-analysis\"",
        "relationship_type": ""
      },
      {
        "colour": "#18005e",
        "local": false,
        "name": "rectifyq:topic=\"supply-chain\"",
        "relationship_type": ""
      },
      {
        "colour": "#ffd12e",
        "local": false,
        "name": "rectifyq:target=\"broad-based\"",
        "relationship_type": ""
      },
      {
        "colour": "#55acee",
        "local": false,
        "name": "rectifyq:MY-relevancy=\"potentially-relevant\"",
        "relationship_type": ""
      },
      {
        "colour": "#0088cc",
        "local": false,
        "name": "misp-galaxy:malpedia=\"Shai-Hulud\"",
        "relationship_type": ""
      },
      {
        "colour": "#0088cc",
        "local": false,
        "name": "misp-galaxy:software-vendor=\"TanStack\"",
        "relationship_type": ""
      },
      {
        "colour": "#220082",
        "local": false,
        "name": "rectifyq:samples-found-in=\"MalwareBazaar\"",
        "relationship_type": ""
      },
      {
        "colour": "#230087",
        "local": false,
        "name": "rectifyq:samples-found-in=\"Tria.ge\"",
        "relationship_type": ""
      },
      {
        "colour": "#3800d9",
        "local": false,
        "name": "rectifyq:action-taken=\"VT-comment\"",
        "relationship_type": ""
      },
      {
        "colour": "#3d00e9",
        "local": false,
        "name": "rectifyq:action-taken=\"telegram\"",
        "relationship_type": ""
      }
    ],
    "Attribute": [
      {
        "category": "External analysis",
        "comment": "",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1785380425",
        "to_ids": false,
        "type": "link",
        "uuid": "6ce1e116-c94c-4b2f-baaf-70ffd68c0f1b",
        "value": "https://www.netskope.com/blog/shai-hulud-style-npm-worm-hits-tanstack"
      },
      {
        "category": "Other",
        "comment": "Description",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1785380425",
        "to_ids": false,
        "type": "text",
        "uuid": "3ece3447-a4b0-4520-89b6-289c5e2ea55b",
        "value": "Multiple npm packages across @tanstack, @mistralai, @uipath, @squawk, and safe-action namespaces were compromised in a worm-like attack affecting over 50 packages. The malicious code executes during installation, downloading the Bun runtime and running a payload that harvests GitHub credentials and cloud secrets. The attack specifically targets AWS environments by querying the IMDS and attempting privilege escalation through STS and SSM endpoints across multiple regions. Stolen credentials are automatically used to publish additional malicious package versions across different maintainer accounts, creating a self-propagating infection chain. The attack patterns mirror previous Shai-Hulud compromises, using a drop-and-execute technique and command-and-control infrastructure at git-tanstack.com, a domain designed to mimic legitimate tanstack.com traffic. Organizations should rotate GitHub credentials, audit AWS credentials, and check for suspicious activity."
      },
      {
        "category": "Other",
        "comment": "Summary",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1785380425",
        "to_ids": false,
        "type": "text",
        "uuid": "5b80da70-5eeb-43df-83de-abd8e55105e2",
        "value": "Name: Shai-Hulud-Style npm Worm Hits\nAuthor: AlienVault\nAdversary: \nTags: [\"github credentials\", \"supply chain attack\", \"infostealer\", \"cloud secrets\", \"aws\", \"npm\", \"@tanstack\", \"worm\"]\nTgtd countries: []\nMlwr families: []\nAttack_ids: [\"T1033\", \"T1132.001\", \"T1059.007\", \"T1552.005\", \"T1082\", \"T1552.001\", \"T1528\", \"T1041\", \"T1136.003\", \"T1098\", \"T1562.001\", \"T1204.003\", \"T1195.002\", \"T1496\", \"T1543.001\", \"T1071.001\", \"T1105\", \"T1550.001\", \"T1078.004\"]\nIndustries: [\"Technology\"]"
      },
      {
        "category": "Network activity",
        "comment": "lookalike of tanstack.com",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1785642909",
        "to_ids": true,
        "type": "domain",
        "uuid": "bac56672-ecee-4172-bda7-dc29d7f9015d",
        "value": "git-tanstack.com",
        "Tag": [
          {
            "colour": "#342294",
            "local": false,
            "name": "CommentAdded",
            "relationship_type": ""
          }
        ]
      },
      {
        "category": "Network activity",
        "comment": "legitimate service used to fetch the Bun runtime",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1785642930",
        "to_ids": true,
        "type": "hostname",
        "uuid": "296f012c-b27d-4449-ac60-1af7bea466ac",
        "value": "codeload.github.com",
        "Tag": [
          {
            "colour": "#2c2142",
            "local": false,
            "name": "false-positive:risk=\"high\"",
            "relationship_type": ""
          },
          {
            "colour": "#342294",
            "local": false,
            "name": "CommentAdded",
            "relationship_type": ""
          }
        ]
      }
    ],
    "Object": [
      {
        "comment": "",
        "deleted": false,
        "description": "File object describing a file with meta-information",
        "first_seen": "2026-05-11T21:44:47+00:00",
        "last_seen": "2026-05-21T05:12:59+00:00",
        "meta-category": "file",
        "name": "file",
        "template_uuid": "688c46fb-5edb-40a3-8273-1af7923e2215",
        "template_version": "25",
        "timestamp": "1785642951",
        "uuid": "9cbb5557-e589-41b7-9443-7fa8d992c804",
        "Attribute": [
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "first_seen": "2026-05-11T21:44:47+00:00",
            "last_seen": "2026-05-21T05:12:59+00:00",
            "object_relation": "md5",
            "timestamp": "1785642951",
            "to_ids": true,
            "type": "md5",
            "uuid": "33ca91cd-7294-48b3-9235-ffd2ebc1b721",
            "value": "b82e54923f7e440664d2d75bd31588ca",
            "Tag": [
              {
                "colour": "#260091",
                "local": false,
                "name": "rectifyq:ioc=\"enriched\"",
                "relationship_type": ""
              },
              {
                "colour": "#220085",
                "local": false,
                "name": "rectifyq:samples-found-in=\"VirusTotal\"",
                "relationship_type": ""
              },
              {
                "colour": "#220082",
                "local": false,
                "name": "rectifyq:samples-found-in=\"MalwareBazaar\"",
                "relationship_type": ""
              },
              {
                "colour": "#230087",
                "local": false,
                "name": "rectifyq:samples-found-in=\"Tria.ge\"",
                "relationship_type": ""
              },
              {
                "colour": "#342294",
                "local": false,
                "name": "CommentAdded",
                "relationship_type": ""
              }
            ]
          },
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "first_seen": "2026-05-11T21:44:47+00:00",
            "last_seen": "2026-05-21T05:12:59+00:00",
            "object_relation": "sha1",
            "timestamp": "1785633251",
            "to_ids": true,
            "type": "sha1",
            "uuid": "c45f7588-db57-4476-bcbb-d34aecb25a9e",
            "value": "e7d582b98ca80690883175470e96f703ef6dc497",
            "Tag": [
              {
                "colour": "#260091",
                "local": false,
                "name": "rectifyq:ioc=\"enriched\"",
                "relationship_type": ""
              },
              {
                "colour": "#220085",
                "local": false,
                "name": "rectifyq:samples-found-in=\"VirusTotal\"",
                "relationship_type": ""
              },
              {
                "colour": "#220082",
                "local": false,
                "name": "rectifyq:samples-found-in=\"MalwareBazaar\"",
                "relationship_type": ""
              },
              {
                "colour": "#230087",
                "local": false,
                "name": "rectifyq:samples-found-in=\"Tria.ge\"",
                "relationship_type": ""
              }
            ]
          },
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "first_seen": "2026-05-11T21:44:47+00:00",
            "last_seen": "2026-05-21T05:12:59+00:00",
            "object_relation": "sha256",
            "timestamp": "1785633251",
            "to_ids": true,
            "type": "sha256",
            "uuid": "4be121c1-5b87-4d68-8062-1382e61ea475",
            "value": "2ec78d556d696e208927cc503d48e4b5eb56b31abc2870c2ed2e98d6be27fc96",
            "Tag": [
              {
                "colour": "#260091",
                "local": false,
                "name": "rectifyq:ioc=\"enriched\"",
                "relationship_type": ""
              },
              {
                "colour": "#220085",
                "local": false,
                "name": "rectifyq:samples-found-in=\"VirusTotal\"",
                "relationship_type": ""
              },
              {
                "colour": "#220082",
                "local": false,
                "name": "rectifyq:samples-found-in=\"MalwareBazaar\"",
                "relationship_type": ""
              },
              {
                "colour": "#230087",
                "local": false,
                "name": "rectifyq:samples-found-in=\"Tria.ge\"",
                "relationship_type": ""
              }
            ]
          },
          {
            "category": "Other",
            "comment": "Checked: 02/08/2026\nLast-scan: 30/07/2026",
            "deleted": false,
            "disable_correlation": true,
            "first_seen": "2026-05-11T21:44:47+00:00",
            "last_seen": "2026-05-21T05:12:59+00:00",
            "object_relation": "text",
            "timestamp": "1785632975",
            "to_ids": false,
            "type": "text",
            "uuid": "2905715d-cfd9-4dff-ad4d-dce51c0b2174",
            "value": "Type Description: JavaScript\nMicrosoft: Trojan:JS/Malgent.LTSN!MTB\nClamAV: None\nVT Total Detection: 41/74\nFirst Seen In The Wild: 2026-05-12T00:06:26+00:00\nFirst Submission: 2026-05-11T21:44:47+00:00\nLast Submission: 2026-05-21T05:12:59+00:00"
          },
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "first_seen": "2026-05-11T21:44:47+00:00",
            "last_seen": "2026-05-21T05:12:59+00:00",
            "object_relation": "ssdeep",
            "timestamp": "1785632975",
            "to_ids": true,
            "type": "ssdeep",
            "uuid": "d15f19d3-753e-428e-99a0-9dc2c5ad1302",
            "value": "49152:e126CoQ9JTiMDR/mWcMAsiaFD0eppIbfgvL7PiN8vds8KnHqvJOQHu/toKg4ae1X:Mp"
          },
          {
            "category": "Other",
            "comment": "",
            "deleted": false,
            "disable_correlation": true,
            "first_seen": "2026-05-11T21:44:47+00:00",
            "last_seen": "2026-05-21T05:12:59+00:00",
            "object_relation": "size-in-bytes",
            "timestamp": "1785632975",
            "to_ids": false,
            "type": "size-in-bytes",
            "uuid": "472f2ac9-48df-485c-8480-ebea72302934",
            "value": "2339346"
          },
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "first_seen": "2026-05-11T21:44:47+00:00",
            "last_seen": "2026-05-21T05:12:59+00:00",
            "object_relation": "vhash",
            "timestamp": "1785632975",
            "to_ids": true,
            "type": "vhash",
            "uuid": "6e48327d-8382-43ed-9838-328923e08cfc",
            "value": "ef6433bf70047acfd9321c13727adadc"
          },
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": true,
            "first_seen": "2026-05-11T21:44:47+00:00",
            "last_seen": "2026-05-21T05:12:59+00:00",
            "object_relation": "filename",
            "timestamp": "1785632975",
            "to_ids": true,
            "type": "filename",
            "uuid": "32d898f8-1a82-495b-a4a3-725b4b0b7eed",
            "value": "router_init.js"
          }
        ]
      }
    ]
  }
}