TI Mindmap HUB
Threat Intelligence Report

The wshu.net npm Campaign Delivers a Multi-Stage Infostealer

๐Ÿ“… June 23, 2026 ๐Ÿ“ฐ safedep.io ๐Ÿ” 0 CVE(s) referenced

A coordinated npm supply chain attack used 15 seemingly innocuous packages to deliver a highly obfuscated, multi-stage infostealer targeting developer credentials, crypto wallets, cloud tokens, and browser data across multiple platforms, with persistence and stealth tactics that evade typical detection.

vendor

Sign in to access the full report including:
detailed analysis, IOCs, MITRE ATT&CK mapping, and STIX bundle.

๐Ÿ” Sign In to Read Full Report

You'll need to accept our Terms of Service to access the platform.

๐Ÿ“Š Visual Mindmap
๐ŸŽฏ IOC Extraction
โš”๏ธ MITRE ATT&CK TTPs
๐Ÿ“ฆ STIX 2.1 Bundle