Live Wave Icon New Blog: Mini Shai-Hulud Strikes Again: 314 npm Packages Compromised
•
Edit Calendar Icon 19 May 2026
SafeDep Logo
Pricing
Discover & Monitor
SCA & SBOM
SCA & SBOM

Scan dependencies, generate SBOMs, enforce policy.

AI Agent Discovery
AI Agent Discovery

See every AI tool and SDK in your org.

AI Agent Monitoring
AI Agent Monitoring

Audit every action your AI agents take.

Protect
Developer Security
Developer Security

Block malicious packages at install-time.

CI/CD Security
CI/CD Security

Block malicious packages in your pipeline.

MCP Server
MCP Server

Block threats inside your AI coding agent.

Agent API
Agent API

Threat intelligence API for custom agents.

Threat Intelligence
Threat Intelligence

Real-time malicious package verdicts.

Govern
Platform
Platform

Centralized policies, dashboard, compliance.

Vet
Vet

Scan and govern your dependencies across every PR and build.

PMG
PMG

Block malicious packages at install-time, before they enter your codebase.

xbom
xbom

Generate AI-enriched BOMs using real code evidence, not just manifests.

GRYPH
GRYPH

Monitor every AI coding agent action across your projects and workflows.

How it works Blog
Documentation
SDK
API
Threat Intelligence Hub
Login Book a Demo GitHub 1.5k Discord
safedep.io / ti / campaigns / tanvisoul9-npm-backdoors

tanvisoul9 npm Backdoors

npm packages published by a single operator that plant SSH backdoors and full remote access trojans on developer machines. All variants exfiltrate stolen data to the [email protected] mailbox, tying the packages to one actor.

discovered 2026-04-14
↓ JSON ↓ CSV

Objective

Gain persistent remote access to developer machines and steal credentials.

Packages

  • npmdom-utils-liteattributed-to
  • npmcentraloggerattributed-to
  • npmnode-env-resolveattributed-to

Indicators

  • domainxienztiavkygvacpqzgr.supabase.cocommunicates-with
  • domainndfcioahsbgsjmulpjgt.supabase.cocommunicates-with
  • sha2564600db4fc30fb6ffa68deed4a25679e674bb3a3e8dae31f3dfc83bea0d757a8findicates
  • sha2562e131f47090516e5a60553aa40d46823e08162390c1d6deb075cf317f00309f7indicates
  • email[email protected]exfiltrates-to
  • domain152.67.0.53communicates-with
  • ipv4152.67.0.53communicates-with
  • ipv4216.126.237.71communicates-with

Techniques

  • ttpT1195.001 Supply Chain Compromise: Compromise Software Dependencies and Development Toolsuses
  • ttpT1059.007 Command and Scripting Interpreter: JavaScriptuses
  • ttpT1041 Exfiltration Over C2 Channeluses
  • ttpT1552.004 Unsecured Credentials: Private Keysuses
  • ttpT1105 Ingress Tool Transferuses
  • ttpT1071.001 Application Layer Protocol: Web Protocolsuses
  • ttpT1102 Web Serviceuses
  • ttpT1546 Event Triggered Executionuses
  • ttpT1552.001 Unsecured Credentials: Credentials In Filesuses
  • ttpT1539 Steal Web Session Cookieuses
Read the full analysis →
SafeDep Logo
SafeDep
Terms · Privacy Policy
SOC 2 Type II Certified
ISO 27001:2013 Certified
SOC 2 Type II Certified
ISO 27001:2013 Certified
SOC 2 Type II Certified
ISO 27001:2013 Certified
Product
  • Features
  • Pricing
  • How it works
Solutions
  • AI Agent Discovery
  • AI Agent Monitoring
  • Threat Intel for Agents
  • Threat Intel for SecOps
  • MCP Server
  • Threat Intel Data Hub
  • Developer API
  • Partners
Support
  • Docs
  • Community Forum
  • FAQ
  • Professional Services
  • Status
Company
  • About
  • Blog
  • Contact
  • Careers
  • GitHub
© 2026 SafeDep, Inc. All rights reserved