Modified Shai-Hulud Worm Detected Testing Payload on npm Registry
Cybersecurity researchers have uncovered a new variant of the Shai-Hulud worm on the npm registry, exhibiting subtle modifications compared to the previous wave detected last month. The compromised npm package, “@vietmoney/react-big-calendar“, was originally uploaded in March 2021 by a user named “hoquocdat” and was recently updated to version 0.26.2 on December 28, 2025. Since its initial […]
Modified Shai-Hulud Worm Detected Testing Payload on npm Registry Read More »









