npm · registry.npmjs.org
@panguard-ai/panguard-guard
Known Indicator Filename: package/bundled-rules/yara-rules/community/baderj/shai-hulud.yar
Why PkgRadar flagged 1.5.5
| Severity | Signal | Evidence |
|---|---|---|
| high | Known Indicator Filename | package/bundled-rules/yara-rules/community/baderj/shai-hulud.yar · package/bundled-rules/yara-rules/community/baderj/shai-hulud.yar |
| high | Known Indicator Filename | package/bundled-rules/sigma-rules/community/2025/Malware/Shai-Hulud/file_event_lnx_mal_shai_hulud_workflow.yml · package/bundled-rules/sigma-rules/community/2025/Malware/Shai-Hulud/file_event_lnx_mal_shai_hulud_workflow.yml |
| high | Known Indicator Filename | package/bundled-rules/sigma-rules/community/2025/Malware/Shai-Hulud/github_mal_shai_hulud_npm_attack.yml · package/bundled-rules/sigma-rules/community/2025/Malware/Shai-Hulud/github_mal_shai_hulud_npm_attack.yml |
| high | Known Indicator Filename | package/bundled-rules/sigma-rules/community/2025/Malware/Shai-Hulud/proc_creation_lnx_mal_shai_hululd_exfiltration.yml · package/bundled-rules/sigma-rules/community/2025/Malware/Shai-Hulud/proc_creation_lnx_mal_shai_hululd_exfiltration.yml |
| high | DNS / OAST exfiltration | matched "burpcollaborator.net" · package/bundled-rules/sigma-rules/community/network/dns/net_dns_external_service_interaction_domains.yml |
Scanned versions
| Version | Verdict | Score | Scanned (UTC) |
|---|---|---|---|
1.5.5 | High risk | 142 | 2026-06-14 |
1.5.6 | High risk | 142 | 2026-06-14 |
1.6.0 | Review | 5 | 2026-06-14 |
2.0.3 | High risk | 142 | 2026-06-14 |
Related campaigns
- panguard0414 — 14 releases, max score 266
Block this in CI
pkgradar gate --ecosystem npm @panguard-ai/[email protected]