logo

Malicious NPM packages: Are you exposed?

ID: 0b342900-da80-50a8-b04a-0305f8d36910

STIX ID: report--0b342900-da80-50a8-b04a-0305f8d36910

Feed Name: Sysdig Blog

Threat Score
85/100

Date Published: 2025-09-25

Date Updated: 2026-05-01

...
...

Sysdig Threat Research Team describes the Shai-Hulud NPM supply-chain worm — a self‑propagating malware that rapidly infected hundreds of JavaScript packages, stole credentials, and replicated to additional packages — and promotes Sysdig’s Threat Intelligence Feed which provides real‑time detection, impact confirmation, and investigation queries to help organizations assess and respond to exposure.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.