logo

Shai-Hulud: The novel self-replicating worm infecting hundreds of NPM packages

ID: 6ccd64fa-493e-578f-b312-2e72ce9a5d1a

STIX ID: report--6ccd64fa-493e-578f-b312-2e72ce9a5d1a

Feed Name: Sysdig Blog

Threat Score
85/100

Date Published: 2025-09-16

Date Updated: 2026-05-01

...
...

Sysdig TRT discovered an active NPM supply-chain worm dubbed Shai-Hulud that executes as a package post-install script (bundle.js), harvests GitHub/NPM/AWS/GCP credentials (including via IMDS), exfiltrates them (e.g., to webhook.site), makes private GitHub repos public (creating copies with a "-migration" suffix), and self-propagates by using maintainer credentials and NPM APIs to update other packages; ~200 infected packages were observed and the report provides detection mappings for Sysdig Secure and Falco plus remediation guidance (package rollbacks, credential rotation, runtime controls).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.