Shai-Hulud: The novel self-replicating worm infecting hundreds of NPM packages
ID: b507f1b7-b076-5685-a3fb-5ef4aa7ea350
STIX ID: report--b507f1b7-b076-5685-a3fb-5ef4aa7ea350
Feed Name: Sysdig Blog
Threat Score
**Shai-Hulud** is a novel, self-propagating NPM supply-chain worm discovered on September 15, 2025 that infects packages via a postinstall bundle.js, steals GitHub/NPM/AWS/GCP credentials, exfiltrates them (via webhook.site), and attempts to propagate by modifying package.json of maintainer packages and creating public repositories with stolen data; approximately 200 packages were identified and the report provides detection rules and mitigation guidance for Falco and Sysdig Secure.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
