SafeDep
Install GitHub App
Start for Free
SafeDep
Install GitHub App
Start for Free

Summary

Note: This report is updated by a verification record

Confirmed malicious package as part of coordinated supply chain attack targeting npm ecosystem

Verification Record

Confirmed malicious package as part of coordinated supply chain attack targeting npm ecosystem

Details

Note: This report is updated by a verification record

Part of the Shai Hulud Second Coming supply chain attack campaign. This malicious package was designed to steal credentials and exfiltrate sensitive data from developer environments.

zuper-sdk@1.0.57Malicious
Verified
Analysed at: 4/12/26, 5:30 AM
Source: -
SHA256:
Confidence: High