Shai-Hulud returns in the npm ecosystem, this time spreading much more widely than before This article explores mjs sha 256. . An expansive package set of more than 1.3 billion monthly downloads exposes developers, build systems, and downstream applications to potential exposure.
Indicators of Compromise (IoCs):- Type Indicator Description SHA-256 9fc2570b7cef51c1b8df116d144d11ff4096357be7d2c4c6367cfc2509cf1bcc Hash associated with Math_Symbol.js; the report states math_init.js shares this hash SHA-256 fd3ca4007b225fdf8de7af4345a19179d5efa8c4bb9205f88cda806e5684b1eb Hash associated with setup.mjs SHA-256 54dc7ea54a1317cca0e890a2770630cf7fa6c97813e0cb9d2caa93012b350668 Hash associated with setup.mjs File name Math_Symbol.js Payload filename in directly compromised keyv monorepo packages File name math_init.js Payload filename in packages compromised through worm propagation File name setup.mjs Dropper filename used to execute the payload File path .claude/settings.json Malicious Claude Code SessionStart hook location File path .vscode/tasks.json Malicious VS Code folderOpen task location Ethereum contract 0xE1f2395ee43e45A1556EC6438a88c31B83493103 C2 resolver used to retrieve the exfiltration endpoint Domain npm-cache[. ]com C2 server and dead-drop domain Domain awqhnjewqjkl[. ]icu C2 server and dead-drop domain Domain go.getblock[.
]io Ethereum RPC provider referenced in hunting guidance Domain eth.llamarpc[. ]com Ethereum RPC provider referenced in hunting guidance Git commit author claude@users.noreply.github.com Author associated with worm-generated commits Git commit message chore: update config Commit message associated with worm-generated commits Signed marker thebeautifulmarchoftime Marker used during fallback C2 discovery Repository description Shai-Hulud: Here We Go Again Description used for fallback GitHub-based data exfiltration Integrate real-time threat intelligence from MISP, VirusTotal, or your SIEM to prevent phishing and malware attacks.












