Skip to main content
mediabuyer
Saved
Self-replicating Shai-hulud worm spreads token-stealing malware on npm
via mediabuyer
First seen
Apr 30
Last seen
Apr 30
Days running
0
OutbrainUS0d
Wrong category? Suggest:

Self-replicating Shai-hulud worm spreads token-stealing malware on npm

ReversingLabs@reversinglabs

RL researchers have detected the first self-replicating worm compromising popular npm packages with cloud token-stealing malware.

Visit page

Landing page intelligence

reversinglabs.com

Redirect chain

1 hop
  1. finalreversinglabs.com

Landing page snapshot

Landing page screenshot

Captured 2026-05-11

Tracking parameters

utm_source
Outbrain
utm_medium
Discovery
utm_campaign
202206-outbrain-promotion
utm_content
richiob
utm_funnel
awareness
utm_term
002116bef8e288df2cae54b73a4e635250
OutbrainClickId
{{ob_click_id}}
obOrigUrl
true

+ 1 known tracker hidden (cloaker IDs scrubbed at ingest).

Tracking setup · Outbrain

Outbrain emits ob_click_id (your unique click), ob_source (publisher), ob_section (placement), and ob_position. Forward ob_click_id to your tracker as the postback key. ob_source and ob_section are the two highest-signal sub-IDs for blacklisting.

?ob_click_id={ob_click_id}&ob_source={ob_source}&ob_section={ob_section}&ob_position={ob_position}

Default Outbrain setup template: ?ob_click_id={ob_click_id}&ob_source={ob_source}&ob_section={ob_section}&ob_position={ob_position}

More from ReversingLabs

Inside the EmEditor supply chain compromise
mediabuyer
OutbrainOther
Inside the EmEditor supply chain compromise
ReversingLabs@reversinglabs
🇺🇸US16d
reversinglabs.com
Visit
Commercial software risk: New controls required
mediabuyer
OutbrainOther
Commercial software risk: New controls required
ReversingLabs@reversinglabs
🇺🇸US16d
reversinglabs.com
Visit
How AI coding is breathing new life into Rust
mediabuyer
OutbrainOther
How AI coding is breathing new life into Rust
ReversingLabs@reversinglabs
🇺🇸US9d
reversinglabs.com
Visit
AI coding gets weaponized: What your AppSec team needs to know
mediabuyer
OutbrainOther
AI coding gets weaponized: What your AppSec team needs to know
ReversingLabs@reversinglabs
🇺🇸US9d
reversinglabs.com
Visit
Fake recruiter campaign targets crypto devs
mediabuyer
OutbrainOther
Fake recruiter campaign targets crypto devs
ReversingLabs@reversinglabs
🇺🇸US15d
reversinglabs.com
Visit
When it comes to threat modeling, not all threats are created equal
mediabuyer
OutbrainOther
When it comes to threat modeling, not all threats are created equal
ReversingLabs@reversinglabs
🇺🇸US13d
reversinglabs.com
Visit
Anthropic’s PSF investment: Why it matters
mediabuyer
OutbrainOther
Anthropic’s PSF investment: Why it matters
ReversingLabs@reversinglabs
🇺🇸US18d
reversinglabs.com
Visit
5 ways AI will transform the SOC
mediabuyer
OutbrainContent Arb
5 ways AI will transform the SOC
ReversingLabs@reversinglabs
🇺🇸US17d
reversinglabs.com
Visit