logo

How to Triage npm Malware Incidents | Free npm SBOM Tool for Fast Response

ID: 202db209-a877-57c8-a5bf-f333af3e6281

STIX ID: report--202db209-a877-57c8-a5bf-f333af3e6281

Feed Name: Abstract Security Blog

Threat Score
85/100

Date Published: 2025-11-24

Date Updated: 2026-04-26

...
...

A new, active npm supply-chain campaign—an evolved Shai-Hulud worm variant—is compromising high-profile npm packages, executing during pre-install to steal developer secrets (with over 25,000 developers reportedly affected and ~16,000 repositories exposing stolen credentials) and in some cases wiping victims' home directories; the report provides triage playbooks, a safe SBOM generation tool, detection guidance, and mitigation steps for rapid incident response.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.