Shai-Hulud Detector’s Test Files Contained Executable Malware

Summary
G DATA found that test files for a Shai-Hulud detection tool contained real malware capable of deleting user directories and uploading data. The maintainer later neutralized the files.
Key points
- G DATA investigated files submitted as possible false positives and found they performed malicious actions.
- The test files could delete user directories and upload data to real threat actors if executed.
- Comments described the actions as simulated, but the commands would run on the system.
- The detection tool checks for patterns associated with Shai-Hulud, an npm worm that steals credentials and access tokens and uses them to spread.
- G DATA said live-malware tests should be run in a sandbox and test files should not be distributed.
- On February 17, 2026, the project maintainer neutralized the test files, removing the risk of accidental download or execution.
Article Details
- Event Type
- Inadvertent distribution of live malware in security-tool test files
- Impact
- If executed, the test files could delete user directories and upload data to threat actors. The files were not executed during normal use of the detector. The project maintainer subsequently neutralized them.