Researchers reported that the npm package shai_hulululud@1.0.48596 was built to interfere with AI-assisted malware analysis rather than to execute a conventional JavaScript payload. The package’s 9.28 MB index.js file embeds policy-triggering text, fake system instructions, a large Japanese-language comment block, and tens of thousands of repetitive comment lines intended to cause LLM refusals, truncation, timeouts, or misclassification before analysts or automated tools reach the executable code. Reports said the file can expand to more than 3.5 million tokens, while the actual logic is hidden later in an obfuscated try{eval(...)} wrapper using character-code arrays and substitution routines.
Socket assessed the package as protestware or a potentially unwanted adversarial test case, not the same credential-stealing malware seen in earlier Mini Shai-Hulud, Miasma, and Hades npm campaigns, but warned that the technique could be adopted by more capable threat actors. Coverage of the package highlighted that the malicious or suspicious content sits inside comments and is therefore aimed at LLM-first review pipelines, while traditional methods such as static analysis, AST parsing, string extraction, deobfuscation, entropy checks, YARA, and behavioral rules remain effective. Recommended defenses include stripping comments before model analysis, detecting context flooding, prioritizing executable code paths, combining LLM review with conventional scanning, and failing closed when AI systems refuse, time out, or return incomplete results.

Trace attribution and downstream blast radius.
1 event from the most recent confirmed update back to the earliest known activity.
Socket Threat Research analyzed the npm package shai_hulululud@1.0.48596 and found it was designed to interfere with AI-assisted malware scanners using prompt-injection text in comments, context flooding, and obfuscated JavaScript. The package was assessed as protestware or a potential adversarial test case rather than a conventional credential-stealing payload.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution and downstream blast radius, and whether this package or vendor reaches your builds.
4 references tracked. Mallory keeps watching after this page renders.
schneier.com
Open sourcesecurityonline.info
Open sourceschneier.com
Open sourcesocket.dev
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.