unit42 · Crawled Jul 16, 2026
The npm Threat Landscape: Attack Surface and Mitigations (Updated July 15)
56 IoCs 1 Actors
Read original article ↗
AI Summary
The npm ecosystem has faced escalating supply chain attacks since the emergence of the Shai-Hulud worm in September 2025. These attacks have evolved into sophisticated, wormable campaigns that steal credentials, propagate across packages, and establish persistent access in CI/CD pipelines. Recent operations, including Mini Shai-Hulud and Miasma variants, have targeted major organizations like Red Hat and AsyncAPI, using novel initial access techniques and resilient C2 infrastructure. The public release of Mini Shai-Hulud tooling has increased the risk of copycat campaigns.
AI-extracted · verify before operational use
Extracted Entities 1 found
Indicators of Compromise 56 extracted
| Type | Value | Detail |
|---|---|---|
| IP | 85[.]137[.]53[.]71 | Details → |
| IP | 94[.]154[.]172[.]43 | Details → |
| IP | 91[.]195[.]240[.]123 | Details → |
| Domain | audit[.]checkmarx[.]cx | Details → |
| Domain | checkmarx[.]cx | Details → |
| Domain | t[.]m-kosche[.]com | Details → |
| Domain | ethereum-rpc[.]publicnode[.]com | Details → |
| Domain | relay[.]damus[.]io | Details → |
| Domain | relay[.]nostr[.]com | Details → |
| Domain | router[.]bittorrent[.]com | Details → |
| Domain | dht[.]transmissionbt[.]com | Details → |
| Domain | ipfs[.]io | Details → |
| Domain | rentry[.]co | Details → |
| SHA-256 | 73b44b8724d31f80859018c988e9b033155c5fd8225205a914eda1a11b78a841 | Details → |
| SHA-256 | f7367ce5509f536a406deecdbb577c60e8585cb2ab77058a86bde6188a609cfd | Details → |
| SHA-256 | 9b2e65db653ca8575c9b10eefb9a80c6006404812c2ec212bf5675e3c690233b | Details → |
| SHA-256 | d425e4583cc6185d41e95c45eda00550045a5d1919b9a012236a4520d009dbd7 | Details → |
| SHA-256 | bfaeb987faa6de2b5a5eb63b1233d055215b09b0349a9394f2175fd7cdf385e4 | Details → |
| SHA-256 | 34014776d3d3ff11bc4439b02fd7ac0f02a887eb3a052eeafff236e2f6db8ad1 | Details → |
| SHA-256 | 082d733db0687dcd768104972b065d4b58cb1e6043688c6c20fa3702337f36ab | Details → |
| SHA-256 | c8cb3f6d5b90c46686d2bf531dc1a5786e27edc5 | Details → |
| SHA-256 | 4066781fa830224c8bbcc3aa005a396657f9c8f9016f9a64ad44a9d7f5f45e34 | Details → |
| SHA-256 | 6f933d00b7d05678eb43c90963a80b8947c4ae6830182f89df31da9f568fea95 | Details → |
| SHA-256 | f35475829991b303c5efc2ee0f343dd38f8614e8b5e69db683923135f85cf60d | Details → |
| SHA-256 | 18f784b3bc9a0bcdcb1a8d7f51bc5f54323fc40cbd874119354ab609bef6e4cb | Details → |
| SHA-256 | 167ce57ef59a32a6a0ef4137785828077879092d7f83ddbc1755d6e69116e0ad | Details → |
| SHA-1 | bc544f455d7c06c8a1f3446160a6d9a4a8236b11 | Details → |
| GitHub Repo | helloworm00/hello-world | Details → |
| GitHub User | helloworm00 | Details → |
| Registry User | 148100 | Details → |
| Filename | setup.mjs | Details → |
| Filename | execution.js | Details → |
| Filename | bw_setup.js | Details → |
| Filename | bw1.js | Details → |
| Filename | .github/workflows/format-check.yml | Details → |
| Filename | sync.js | Details → |
| Package | @bitwarden/[email protected] | Details → |
| Package | @cap-js/[email protected] | Details → |
| Package | @cap-js/[email protected] | Details → |
| Package | @cap-js/[email protected] | Details → |
| Package | [email protected] | Details → |
| Package | @asyncapi/[email protected] | Details → |
| Package | @asyncapi/[email protected] | Details → |
| Package | @asyncapi/[email protected] | Details → |
| Package | @asyncapi/[email protected] | Details → |
| Package | @asyncapi/[email protected] | Details → |
| SHA-256 | 540028bbd229cc8ce0f531f84e11296870f9b54faa231abb6f5da8557ae3df31 | Details → |
| SHA-256 | c70e105e212ff3c1daa04bb2a62507717f296b0b | Details → |
| SHA-256 | 22bf76fe317ea6769bd38619bd440e42d119bd6b | Details → |
| SHA-256 | a7e18d96efd3cdb127ef4cdcad9e3ad26c482bf2 | Details → |
| SHA-256 | 9890950adcbc2478e7a080234f053214adbad44e | Details → |
| SHA-256 | ssl://0432fa4ba871877d94081fe83323fa24dfa1491e9de8725cbab7b734de9e9be3b233ef6742fd6264437c9532223d687b05fa540b70af6a516b8539af84d0eeb48e | Details → |
| SHA-256 | 3eab3ec9304aa26081358330491d3cfeb55cc245 | Details → |
| SHA-256 | Qmet4fhsAaWMBUxNDfREHwgiyDeSWy4YSYs9wiKUW5jGyf | Details → |
| SHA-256 | QmQobZSp1wRPrpSEQ56qnyq7ecZh5Bg5k1fnjt4SUwwHb9 | Details → |
| GitHub Repo | zblgg/configuration | Details → |
MITRE ATT&CK TTPs 16 techniques
T1005 Data from Local System · Collection T1036.005 Match Legitimate Name or Location · Defense Evasion T1055 Process Injection · Defense Evasion T1059.001 PowerShell · Execution T1070.004 File Deletion · Defense Evasion T1071 Application Layer Protocol · Command And Control T1071.001 Web Protocols · Command And Control T1078 Valid Accounts · Defense Evasion T1081 T1081 T1090 Proxy · Command And Control T1098 Account Manipulation · Persistence T1133 External Remote Services · Persistence T1195.001 Compromise Software Dependencies and Development Tools · Initial Access T1548.001 Setuid and Setgid · Privilege Escalation T1553 Subvert Trust Controls · Defense Evasion T1566 Phishing · Initial Access