Shai-Hulud Continues: Hades Payload Hits Leo/RStreams npm Packages
JFrog Security Research identified a new Shai-Hulud/Hades npm wave affecting 20 packages in the Leo/RStreams ecosystem. The malicious packages belong to a legitimate package family used for AWS-native event streaming, Lambda-based event handlers, and serverless data pipelines. Our scanners detected the malicious versions shortly after publication. The payload is not a major functional rewrite of the previous Hades wave we covered in Shai-Hulud - Miasma: The Spreading Blight Hits Red Hat npm Packages. Instead, this wave looks like another turn of the same worm: same broad credential theft and propagation machinery, but with fresh package targets, new campaign text, and a small operator-seeding addition. /img/RealTimePostImage/post/shai-hulud-alright-lets-see-if-this-works.png ## What Is Leo/RStreams? Leo, now commonly referred to as RStreams, is an AWS-native event streaming and messaging platform. It provides a light abstraction over AWS services such as Kinesis, Firehose, S3, Lambda, and DynamoDB. Developers use the Leo/RStreams Node SDK to push, pull, transform, and offload data through event queues. This makes the affected package set especially sensitive. These libraries tend to show up close to cloud infrastructure, event pipelines, and CI/CD systems, exactly the places where npm installation can run with access to AWS credentials, GitHub tokens, npm publishing credentials, and application secrets. Across the affected package set, npm reported approximately ~127K downloads in the last month at the time of analysis. The full affected package list appears in the IOC section. ## Delivery Through binding.gyp This wave uses the same evasive binding.gyp execution technique we described in previous Shai-Hulud reporting. Instead of relying only on an obvious preinstall or install script in package.json, the malicious package can place execution inside binding.gyp. When npm sees a package with binding.gyp and no explicit install script, it falls back to running node-gyp rebuild. During that process, node-gyp expands shell commands embedded in