logo

Graph the Planet: Shai-Hulud 2.0

ID: d454a9c4-ba6a-5d6e-949f-a3335553b386

STIX ID: report--d454a9c4-ba6a-5d6e-949f-a3335553b386

Feed Name: SpecterOps Blog

Threat Score
85/100

Date Published: 2026-03-19

Date Updated: 2026-05-01

...
...

This report analyzes the Shai-Hulud 2.0 supply-chain worm campaign that abused GitHub PWN requests and compromised tokens to infect writable NPM packages, propagate via semantic versioning, and exfiltrate developer credentials to thousands of public GitHub repositories; it decomposes infection and propagation paths, highlights credential harvesting and public exfiltration at scale, and recommends defenses including secret scanning, rotating/avoiding long-lived tokens, and inventorying dependency chains.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.