A new variant of the Shai-Hulud npm supply chain worm, dubbed Shai-Hulud 3.0, has been discovered embedded in the npm package @vietmoney/react-big-calendar version 0.26.2. This updated strain features enhanced obfuscation, improved error handling, and better Windows compatibility, but retains the core infection and exfiltration mechanics of previous versions. The malware executes malicious code at install time via a preinstall script, leveraging the Bun runtime to steal secrets and evade detection, posing a significant risk to CI/CD pipelines and developer environments.
Researchers have identified several changes in this latest strain, including new file names such as bun_installer.js and environment_source.js, and altered GitHub repository descriptions used for exfiltration. Notably, the "dead man switch" present in earlier versions appears to have been removed. At the time of discovery, there was no evidence of widespread infection, suggesting the attackers may have been testing their payload. Security teams are advised to monitor for suspicious activity related to this package and review dependencies for potential compromise.

Trace attribution and downstream blast radius.
5 events from the most recent confirmed update back to the earliest known activity.
Researchers documented altered file structure and filenames, removal of the prior dead-man switch, improved TruffleHog timeout handling, better Windows and Bun compatibility, and changed GitHub exfiltration behavior using repositories described as "Goldox-T3chs: Only Happy Girl." They also noted a likely bug involving fetching "c0nt3nts.json" but saving "c9nt3nts.json."
Initial analysis found no evidence of major spread, widespread infections, or multiple compromised packages beyond the single npm package. Researchers concluded the actor was likely testing or probing the updated payload rather than conducting a broad campaign.
On December 29, 2025, researchers identified a new Shai-Hulud variant, dubbed "The Golden Path" or v3.0, in npm package @vietmoney/react-big-calendar version 0.26.2. Analysis indicated the malware was re-obfuscated from original source code and represented an evolution of the existing worm.
A later report says researchers had not observed any new packages or repositories linked to the malware after December 10, 2025. This marked a lull in visible activity before the newly reported variant appeared.
Reporting on the new variant states the broader Shai-Hulud campaign was first detected in September 2025. The malware is known for harvesting developer credentials and self-propagating through compromised npm packages.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See attribution and downstream blast radius, and whether this package or vendor reaches your builds.
7 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcethehackernews.com
Open sourceupwind.io
Open sourcesnyk.io
Open sourcegovinfosecurity.com
Open sourceaikido.dev
Open sourcegetsafety.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.