logo

Return of the Shai-Hulud worm affects over 25,000 GitHub repositories

ID: 855ae072-1ada-578a-8ba9-c9a2a867889a

STIX ID: report--855ae072-1ada-578a-8ba9-c9a2a867889a

Feed Name: Sysdig Blog

Threat Score
90/100

Date Published: 2025-11-24

Date Updated: 2026-05-01

...
...

Sysdig Threat Research details the second coming of the Shai-Hulud worm: a supply-chain NPM malware campaign that has trojaned ~800–1,000 packages and exfiltrated credentials from tens of thousands of GitHub repositories. The worm executes during package installation, steals tokens and cloud/GitHub secrets, attempts to republish/propagate via NPM, installs self-hosted GitHub Actions runners as a backdoor, and can irreversibly shred user files if propagation fails; the report includes code excerpts, detection rules, and remediation recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.