Malware in hamus.js
Malware discovered in the npm package hamus.js. Systems with this package installed or running should be considered fully compromised. All secrets and keys must be rotated from a different computer.
- Disclosed
- Last updated
- Blast radius
- Any system with hamus.js installed or running; full system compromise possible
- Ecosystems
- Attack vectors
- Affected entities
- hamus.js
The npm package hamus.js has been identified as containing malware. According to the GitHub Advisory (GHSA-rx3m-fvv8-f2j8), any computer with this package installed or running should be considered fully compromised.\n\nImmediate remediation is critical: all secrets and keys stored on affected computers must be rotated immediately from a different, uncompromised system. While the package should be removed, there is no guarantee that removal will eliminate all malicious software that may have been installed as a result of the package's execution.\n\nThe full system compromise risk means that additional security measures beyond package removal may be necessary to fully remediate the threat.
Indicators of compromise
- Packages
- hamus.js
Remediation
- Immediately rotate all secrets and keys from a different, uncompromised computer
- Remove the hamus.js package from all affected systems
- Conduct a full security audit of any system that had hamus.js installed
- Consider the affected system(s) potentially compromised and plan for full remediation or replacement
- Review system logs and network activity for signs of unauthorized access or data exfiltration
Sources
- GitHub Advisory GHSA-rx3m-fvv8-f2j8 · GitHub Advisory Database
Cite this entry
"Malware in hamus.js." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed August 4, 2026; last updated August 4, 2026. https://supplychainattack.org/incident/malware-in-hamus-js-16mye8
Suggest a correction
Found an error or have a newer source? Corrections to factual errors take priority over new entries.
Related incidents
- activecritical
Malware in @onereach/si-text-message
Malware was discovered in the npm package @onereach/si-text-message. Systems with this package installed are considered fully compromised and require immediate remediation.
npmCompromised package - containedcritical
Malware in @servicetitan/assist-ui
Malware was discovered in the npm package @servicetitan/assist-ui. Systems with this package installed or running are considered fully compromised and require immediate remediation.
npmCompromised package - containedcritical
Malware in @onereach/orest-cli
Malware was discovered in the npm package @onereach/orest-cli. Systems with this package installed or running should be considered fully compromised, with all secrets and keys requiring immediate rotation from a different computer.
npmCompromised package - activecritical
Malware in @servicetitan/install
Malware was discovered in the npm package @servicetitan/install. Systems with this package installed or running should be considered fully compromised, requiring immediate rotation of all secrets and keys from a different computer.
npmCompromised package