logo

Shai-Hulud: When a Supply-Chain Incident Turns Into a Worm by Lucie Cardiet

ID: f77e4fd1-60a2-529a-b2cd-82e2eaadd186

STIX ID: report--f77e4fd1-60a2-529a-b2cd-82e2eaadd186

Feed Name: Vectra AI Blog

Threat Score
85/100

Date Published: 2025-11-26

Date Updated: 2026-05-01

...
...

**Shai-Hulud** is a supply-chain worm targeting JavaScript development workflows that runs automatically when infected packages are installed, evades Node-focused defenses by using the Bun runtime, harvests a wide range of credentials and cloud metadata, publicly exfiltrates secrets by creating repositories under victims' GitHub accounts, spreads through compromised maintainers and repositories, installs self-hosted GitHub Actions runners for durable persistence, and includes an optional wiper — making it a stealthy, high-impact threat that leverages normal development trust to scale.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.