Shai-Hulud Detector’s Test Files Contained Executable Malware

· Original article ↗

Summary

G DATA found that test files for a Shai-Hulud detection tool contained real malware capable of deleting user directories and uploading data. The maintainer later neutralized the files.

Key points

  • G DATA investigated files submitted as possible false positives and found they performed malicious actions.
  • The test files could delete user directories and upload data to real threat actors if executed.
  • Comments described the actions as simulated, but the commands would run on the system.
  • The detection tool checks for patterns associated with Shai-Hulud, an npm worm that steals credentials and access tokens and uses them to spread.
  • G DATA said live-malware tests should be run in a sandbox and test files should not be distributed.
  • On February 17, 2026, the project maintainer neutralized the test files, removing the risk of accidental download or execution.

Article Details

Event Type
Inadvertent distribution of live malware in security-tool test files
Impact
If executed, the test files could delete user directories and upload data to threat actors. The files were not executed during normal use of the detector. The project maintainer subsequently neutralized them.

MITRE ATT&CK

Malware

Products

Related Articles