shai_hulululud npm Package Uses Prompt Injection and Token Flooding to Disrupt AI Malware Scanners

Suspected
Discovered Jun 16, 2026

Socket identified shai_hulululud@1.0.48596 as a deliberately packed npm package that appears designed to probe or disrupt AI-assisted malware review with prompt-injection text, safety-triggering comments, context flooding, and obfuscated JavaScript.

1
Affected Packages
9
Observables
3
Sources

Timeline

1 of 1 rows

Timeline
DateEventDescriptionSource
Jun 16, 2026Fresh source reviewReviewed direct and primary sources for the last-two-weeks supply-chain refresh; this preview intentionally excludes older Halting Problems article data.Direct source

Affected Software

1 of 1 rows

Affected Software
PackageEcosystemVersion RangeStatusConfidenceSource
shai_hulululudnpm1.0.48596Malicious90%Direct source

IOC Clipboard

9 IOCs
urlhttps://registry.npmjs.org/shai_hulululud
urlhttps://registry.npmjs.org/shai_hulululud/-/shai_hulululud-1.0.48596.tgz
urlhttps://socket.dev/blog/npm-package-uses-prompt-injection-and-token-flooding-to-disrupt-ai-malware-scanners
hash9dcce285116e31a5c8f8e3a4ed596a791e62c3e47185e4ee36c489422b1fbbbc
hash8478bad8f0661d2a5ea65a8dc4bf86114f77d939
file_pathshai_hulululud-1.0.48596.tgz
file_pathindex.js
commandeval(
commandshai_hulululud

Provenance & Sources

3 of 3 rows

Provenance & Sources
SourceTypeReliabilityClaimsEvidence
Direct sourcedirect95%1https://registry.npmjs.org/shai_hulululud
Direct sourcedirect95%1https://registry.npmjs.org/shai_hulululud/-/shai_hulululud-1.0.48596.tgz
Primary researchprimary research95%1https://socket.dev/blog/npm-package-uses-prompt-injection-and-token-flooding-to-disrupt-ai-malware-scanners