npm Package Uses Prompt Injection and Token Flooding to Target AI Malware Scanners

· Original article ↗

Summary

Socket researchers analyzed an npm package that uses prompt-injection comments, token flooding, and obfuscated JavaScript to disrupt AI malware review. They found no evidence it carries the credential-stealing payload seen in related campaigns.

Key points

  • Socket identified shai_hulululud@1.0.48596 as a package apparently designed to probe and disrupt AI-based malware scanners.
  • Its approximately 9.28 MB index.js contains prompt-injection and safety-triggering text in comments, which do not affect JavaScript execution but may interfere with AI review.
  • Tens of thousands of repeated comments push the file beyond 3.5 million tokens, potentially exhausting context limits or burying code from scanners.
  • Obfuscated JavaScript at the file’s end uses a character-code array, ROT-style substitution, eval, and a second AES-related layer.
  • Researchers classified the package as protestware or potentially unwanted behavior and said it does not appear to contain the credential-stealing payload found in related campaigns.
  • The analysis recommends treating package content as untrusted input, prioritizing executable code, combining AI review with static and behavioral analysis, and failing closed on refusals, timeouts, or errors.

Article Details

Attack Vectors
  • The npm package shai_hulululud@1.0.48596 appears designed to interfere with AI-assisted malware review through non-executable JavaScript comments containing fake system override instructions.
  • Policy-triggering biological and nuclear weapons content appears intended to cause model refusal or analysis failure. Similar content reappears after deobfuscation.
  • The approximately 9.28 MB index.js contains repetitive comments observed around lines 191–33118 and exceeds 3.5 million tokens, potentially exhausting scanner context or causing truncation before executable code is analyzed.
  • Executable JavaScript is appended after the comment-heavy sections and concealed using character-code encoding, ROT-style substitution, dynamic eval execution, and a second layer involving AES encryption.
  • Decoded strings resemble credential theft, installation hooks, callback infrastructure, and other malware indicators, but the article does not establish that these referenced behaviors are implemented. Socket classified the decoded package as “Protestware or potentially unwanted behavior.”
Defensive Notes
  • Treat package contents as untrusted data rather than instructions to the reviewing model.
  • Use deterministic preprocessing to strip or isolate comments where appropriate and prioritize executable code paths.
  • Detect context flooding and avoid submitting or chunking large files without prioritizing executable content.
  • Combine LLM review with static analysis, AST parsing, entropy checks, deobfuscation, behavioral rules, and sandboxing.
  • Account for additional prompt-injection or safety-triggering content revealed during deobfuscation.
  • Fail closed: model refusals, timeouts, and safety errors must not be treated as clean scan results.

MITRE ATT&CK

Malware

Products

Tools

Related Articles