npm Package Uses Prompt Injection and Token Flooding to Target AI Malware Scanners

Summary
Socket researchers analyzed an npm package that uses prompt-injection comments, token flooding, and obfuscated JavaScript to disrupt AI malware review. They found no evidence it carries the credential-stealing payload seen in related campaigns.
Key points
- Socket identified shai_hulululud@1.0.48596 as a package apparently designed to probe and disrupt AI-based malware scanners.
- Its approximately 9.28 MB index.js contains prompt-injection and safety-triggering text in comments, which do not affect JavaScript execution but may interfere with AI review.
- Tens of thousands of repeated comments push the file beyond 3.5 million tokens, potentially exhausting context limits or burying code from scanners.
- Obfuscated JavaScript at the file’s end uses a character-code array, ROT-style substitution, eval, and a second AES-related layer.
- Researchers classified the package as protestware or potentially unwanted behavior and said it does not appear to contain the credential-stealing payload found in related campaigns.
- The analysis recommends treating package content as untrusted input, prioritizing executable code, combining AI review with static and behavioral analysis, and failing closed on refusals, timeouts, or errors.
Article Details
- Attack Vectors
- The npm package shai_hulululud@1.0.48596 appears designed to interfere with AI-assisted malware review through non-executable JavaScript comments containing fake system override instructions.
- Policy-triggering biological and nuclear weapons content appears intended to cause model refusal or analysis failure. Similar content reappears after deobfuscation.
- The approximately 9.28 MB index.js contains repetitive comments observed around lines 191–33118 and exceeds 3.5 million tokens, potentially exhausting scanner context or causing truncation before executable code is analyzed.
- Executable JavaScript is appended after the comment-heavy sections and concealed using character-code encoding, ROT-style substitution, dynamic eval execution, and a second layer involving AES encryption.
- Decoded strings resemble credential theft, installation hooks, callback infrastructure, and other malware indicators, but the article does not establish that these referenced behaviors are implemented. Socket classified the decoded package as “Protestware or potentially unwanted behavior.”
- Defensive Notes
- Treat package contents as untrusted data rather than instructions to the reviewing model.
- Use deterministic preprocessing to strip or isolate comments where appropriate and prioritize executable code paths.
- Detect context flooding and avoid submitting or chunking large files without prioritizing executable content.
- Combine LLM review with static analysis, AST parsing, entropy checks, deobfuscation, behavioral rules, and sandboxing.
- Account for additional prompt-injection or safety-triggering content revealed during deobfuscation.
- Fail closed: model refusals, timeouts, and safety errors must not be treated as clean scan results.
MITRE ATT&CK
T1027 · Obfuscated Files or InformationThe package conceals its appended JavaScript using character-code encoding, ROT-style substitution, and a second layer involving AES encryption.T1140 · Deobfuscate/Decode Files or InformationThe JavaScript wrapper reconstructs encoded character data and applies ROT-style substitution before executing the reconstructed program with eval.
Malware
ChainDropLast week, Socket Threat Research reported that newer Mini Shai-Hulud, Miasma, and Hades packages were embedding fake prompt-injection headers before obfuscated JavaScript payloads. Those comments did not affect runtimeHadesLast week, Socket Threat Research reported that newer Mini Shai-Hulud, Miasma, and Hades packages were embedding fake prompt-injection headers before obfuscated JavaScript payloads. Those comments did not affect runtimeMiasmaLast week, Socket Threat Research reported that newer Mini Shai-Hulud, Miasma, and Hades packages were embedding fake prompt-injection headers before obfuscated JavaScript payloads. Those comments did not affect runtime
Products
npmSocket Threat Research identified shai_hulululud@1.0.48596, a newly published npm package that appears to target AI-based malware scanners directly. The package ships a large `index.js` file containing policy-triggeringPyPIIn the earlier campaign, malicious PyPI wheels used fake prompt-injection headers at the beginning of _index.js payloads. Those headers were not executed by JavaScript, but they appeared designed to pollute AI-assisted