<img height="1" width="1" style="display:none;" alt="" src="https://px.ads.linkedin.com/collect/?pid=10643465&amp;fmt=gif">

First Shai-Hulud Worm Clones Emerge

Shai-Hulud malware clone spreads via NPM, targeting developers in a new wave of open source supply chain attacks.
Content Team

Cybercriminals have already cloned the Shai-Hulud malware, days after TeamPCP published its source code on GitHub under an MIT License on May 12. The original worm first hit the open source ecosystem in September 2025 — and again that November — stealing credentials and API keys from developers to spread through NPM packages.

Ox Security discovered four malicious NPM packages: 'chalk-tempalte', a near-unchanged clone of the leaked worm that typo-squats chalk-template; 'axois-utils' and '@deadcode09284814/axios-util', both going after Axios users; and 'color-style-utils'. Together they were pulling around 2,678 downloads a week. One of them, 'axois-utils', drops Phantom Bot — a Go-based DDoS botnet that presses infected machines into HTTP, TCP and UDP floods.

All four were still downloadable from NPM when researchers published. If you've installed any of them: uninstall, rotate your keys, delete any malicious IDE or coding-agent configs left behind, and check your GitHub account for a repo named 'A Mini Sha1-Hulud has Appeared'. Ox Security expects this is only the first phase of a wider wave.

Source: Security Week

Share this article
Share on facebook Share on linkedin Share on twitter Share on email
blog_book_a_demo_cta_3x
Have questions about protecting your software?
Our escrow experts are standing by to help.
Book a free demo