---
title: "Shai-Hulud keeps burrowing: 314 npm packages infected after another account compromise"
url: https://daily.dev/posts/shai-hulud-keeps-burrowing-314-npm-packages-infected-after-another-account-compromise-1caqiazrh
source_url: https://www.devclass.com/security/2026/05/21/shai-hulud-keeps-burrowing-314-npm-packages-infected-after-another-account-compromise/5244482
type: article
source: "DEVCLASS"
published: 2026-05-21T18:57:11.853Z
updated: 2026-05-26T22:08:26.956Z
tags: ["security", "cyber", "github", "malware", "npm"]
reading_time: 3
upvotes: 0
comments: 0
language: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Shai-Hulud keeps burrowing: 314 npm packages infected after another account compromise

**[DEVCLASS](https://daily.dev/sources/devclass)** · 3 min read · 0 upvotes · 0 comments

## Summary

A compromised npm account (i@hust.cc) infected 314 npm packages with malware in a 22-minute window, hitting popular packages like size-sensor (4.2M monthly downloads), echarts-for-react (3.8M), and timeago.js. The malware — part of the ongoing Shai-Hulud campaign — steals credentials for GitHub, AWS, Azure, GCP, Docker, and Stripe from environment variables and files, exfiltrates them to attacker-controlled GitHub repos, and attempts container escapes. It also injects settings files targeting Claude Code and Codex for further execution. The attack used a stolen token for automation. Developers who installed affected versions should rotate all credentials, audit GitHub repos for unauthorized activity, and remove malicious systemd services. GitHub has responded with a statement about policy enforcement but has been criticized for limited action during the ongoing campaign.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://www.devclass.com/security/2026/05/21/shai-hulud-keeps-burrowing-314-npm-packages-infected-after-another-account-compromise/5244482>

## Similar posts on daily.dev

- [New Shai-Hulud malware wave compromises 600 npm packages](https://daily.dev/posts/new-shai-hulud-malware-wave-compromises-600-npm-packages-fc6izpxyv) · BleepingComputer · 5 upvotes · 1 comments

---

Tags: [#security](https://daily.dev/tags/security), [#cyber](https://daily.dev/tags/cyber), [#github](https://daily.dev/tags/github), [#malware](https://daily.dev/tags/malware), [#npm](https://daily.dev/tags/npm)

[View this post on daily.dev](https://daily.dev/posts/shai-hulud-keeps-burrowing-314-npm-packages-infected-after-another-account-compromise-1caqiazrh)
