INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
Four npm Packages Spew Infostealers and Phantom Bot DDoS Malware
| 2026-05-18 08:57 LOW HIGH DATA BREACH SUPPLY CHAIN MALWARE & BOTNETS DDOS & DISRUPTION
Executive Summary
AI-generated
On May 18, 2026, four malicious npm packages containing information-stealing malware and a Golang-based distributed denial-of-service (DDoS) botnet called Phantom Bot were discovered. The identified entities affected by the attack are users who downloaded these packages, with no specific number provided in the source article. The attack works by delivering a DDoS botnet that floods target websites using HTTP, TCP, and UDP protocols, as well as establishing persistence on compromised systems through scheduled tasks. Currently, the four libraries remain available for download from npm, despite being identified as malicious payloads embedded into them.
Technical Mitigations AI-generated
• Patch the "chalk-tempalte" package to prevent Shai-Hulud worm execution.
• Block network access to suspicious domains, including 80.200.28[.]28 and <a href="/auth/login?next=/detail/D4vEPp4B-OEKoAx9bt6X" class="ioc-censored-pill text-decoration-none" title="Protected IoC: Sign in to view" data-bs-toggle="tooltip"><span class="badge bg-black text-warning border border-warning border-opacity-75 font-monospace ioc-lock-tag align-middle"><i class="bi bi-lock-fill me-1"></i>[IOC HIDDEN • LOGIN REQUIRED]</span></a>[.]life.
• Use a different SSH key for GitHub repositories containing the string "A Mini Sha1-Hulud has Appeared".
• Rotate secrets immediately after discovering malicious configuration in IDEs and coding agents like Claude Code.
• Block network access to <a href="/auth/login?next=/detail/D4vEPp4B-OEKoAx9bt6X" class="ioc-censored-pill text-decoration-none" title="Protected IoC: Sign in to view" data-bs-toggle="tooltip"><span class="badge bg-black text-warning border border-warning border-opacity-75 font-monospace ioc-lock-tag align-middle"><i class="bi bi-lock-fill me-1"></i>[IOC HIDDEN • LOGIN REQUIRED]</span></a>[.]life.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected
Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.
87•••••.lhr
ed•••••.lhr
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Shai-HuludShai-Hulud
Target & Sectors
Global Scope
technologytechnology
Incident Timeline
May 18, 2026
Threat actors used the identified npm packages to deliver infostealers and Phantom Bot DDoS malware, with "chalk-tempalte" containing a Shai-Hulud worm clone.
Click on any entity below to view its context and source!
infrastructure
Windows
It also establishes persistence on both Windows and Linux machines by adding the payload to the Windows Startup folder and creating a scheduled task.
infrastructure
Linux
It also establishes persistence on both Windows and Linux machines by adding the payload to the Windows Startup folder and creating a scheduled task.
infrastructure
825 Downloads
The list of
identified packages
is below -
chalk-tempalte (825 Downloads)
@deadcode09284814/axios-util (284 Downloads)
axois-utils (963 Downloads)
color-style-utils (934 Downloads)
infrastructure
284 Downloads
The list of
identified packages
is below -
chalk-tempalte (825 Downloads)
@deadcode09284814/axios-util (284 Downloads)
axois-utils (963 Downloads)
color-style-utils (934 Downloads)
infrastructure
963 Downloads
The list of
identified packages
is below -
chalk-tempalte (825 Downloads)
@deadcode09284814/axios-util (284 Downloads)
axois-utils (963 Downloads)
color-style-utils (934 Downloads)
infrastructure
934 Downloads
The list of
identified packages
is below -
chalk-tempalte (825 Downloads)
@deadcode09284814/axios-util (284 Downloads)
axois-utils (963 Downloads)
color-style-utils (934 Downloads)
Tactical Metrics
Metrics
infrastructure
Windows
Affected Product
Click for context!
It also establishes persistence on both Windows and Linux machines by adding the payload to the Windows Startup folder and creating a scheduled task.
Metrics
infrastructure
Linux
Affected Product
It also establishes persistence on both Windows and Linux machines by adding the payload to the Windows Startup folder and creating a scheduled task.
Metrics
infrastructure
825
Downloads
The list of
identified packages
is below -
chalk-tempalte (825 Downloads)
@deadcode09284814/axios-util (284 Downloads)
axois-utils (963 Downloads)
color-style-utils (934 Downloads)
Metrics
infrastructure
284
Downloads
The list of
identified packages
is below -
chalk-tempalte (825 Downloads)
@deadcode09284814/axios-util (284 Downloads)
axois-utils (963 Downloads)
color-style-utils (934 Downloads)
Metrics
infrastructure
963
Downloads
The list of
identified packages
is below -
chalk-tempalte (825 Downloads)
@deadcode09284814/axios-util (284 Downloads)
axois-utils (963 Downloads)
color-style-utils (934 Downloads)
Metrics
infrastructure
934
Downloads
The list of
identified packages
is below -
chalk-tempalte (825 Downloads)
@deadcode09284814/axios-util (284 Downloads)
axois-utils (963 Downloads)
color-style-utils (934 Downloads)
Intelligence Sources
The Hacker News
2026-05-18
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-10-07T11:04
Comprehensive Tactical Telemetry
Highly Correlated Entities
11x
organisation
Identified Entity
Phantom Bot DDoS
entity
4x
infrastructure
Downloads
825
downloads
2x
tactic
Cyber Operation Type
Ddos
tactic
2x
tactic
MITRE ATT&CK Technique
T1588.001 - Malware
technique
2x
timeline
Temporal Reference
May 18, 2026
date
2x
infrastructure
Affected Product
Windows
software
Contextual Telemetry
Context Block
1 METRICS
malware
Malware Payload
Shai-Hulud
tool
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.