INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

Four npm Packages Spew Infostealers and Phantom Bot DDoS Malware

| 2026-05-18 08:57 LOW HIGH DATA BREACH SUPPLY CHAIN MALWARE & BOTNETS DDOS & DISRUPTION
Executive Summary
AI-generated
On May 18, 2026, four malicious npm packages containing information-stealing malware and a Golang-based distributed denial-of-service (DDoS) botnet called Phantom Bot were discovered. The identified entities affected by the attack are users who downloaded these packages, with no specific number provided in the source article. The attack works by delivering a DDoS botnet that floods target websites using HTTP, TCP, and UDP protocols, as well as establishing persistence on compromised systems through scheduled tasks. Currently, the four libraries remain available for download from npm, despite being identified as malicious payloads embedded into them.
Technical Mitigations AI-generated
• Patch the "chalk-tempalte" package to prevent Shai-Hulud worm execution. • Block network access to suspicious domains, including 80.200.28[.]28 and <a href="/auth/login?next=/detail/D4vEPp4B-OEKoAx9bt6X" class="ioc-censored-pill text-decoration-none" title="Protected IoC: Sign in to view" data-bs-toggle="tooltip"><span class="badge bg-black text-warning border border-warning border-opacity-75 font-monospace ioc-lock-tag align-middle"><i class="bi bi-lock-fill me-1"></i>[IOC HIDDEN &bull; LOGIN REQUIRED]</span></a>[.]life. • Use a different SSH key for GitHub repositories containing the string "A Mini Sha1-Hulud has Appeared". • Rotate secrets immediately after discovering malicious configuration in IDEs and coding agents like Claude Code. • Block network access to <a href="/auth/login?next=/detail/D4vEPp4B-OEKoAx9bt6X" class="ioc-censored-pill text-decoration-none" title="Protected IoC: Sign in to view" data-bs-toggle="tooltip"><span class="badge bg-black text-warning border border-warning border-opacity-75 font-monospace ioc-lock-tag align-middle"><i class="bi bi-lock-fill me-1"></i>[IOC HIDDEN &bull; LOGIN REQUIRED]</span></a>[.]life.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected

Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.

87•••••.lhr
ed•••••.lhr
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Shai-HuludShai-Hulud
Target & Sectors
Global Scope technologytechnology
Incident Timeline
‎May 18, 2026
Threat actors used the identified npm packages to deliver infostealers and Phantom Bot DDoS malware, with "chalk-tempalte" containing a Shai-Hulud worm clone.
infrastructure Windows
infrastructure Linux
infrastructure 825 Downloads
infrastructure 284 Downloads
infrastructure 963 Downloads
infrastructure 934 Downloads
Tactical Metrics
Metrics
infrastructure
‎Windows
Affected Product
Metrics
infrastructure
‎Linux
Affected Product
Metrics
infrastructure
825
Downloads
Metrics
infrastructure
284
Downloads
Metrics
infrastructure
963
Downloads
Metrics
infrastructure
934
Downloads
Intelligence Sources