logo

What We Know About the NPM Supply Chain Attack

ID: 2fb5fe8a-9536-5655-b03a-c64a9a5d8ac9

STIX ID: report--2fb5fe8a-9536-5655-b03a-c64a9a5d8ac9

Feed Name: TrendAI Security Blog

Threat Score
86/100

Date Published: 2025-01-01

Date Updated: 2026-08-11

...
...

This TrendAI research blog details a large-scale NPM supply-chain attack where attackers phished a package maintainer, injected malicious code into popular JavaScript packages, and deployed a self-propagating worm called Shai-Hulud that abuses post-install scripts and GitHub workflows to exfiltrate secrets, clone and publish private repositories, and deliver cryptojacking payloads; the report describes observed infection mechanics, use of TruffleHog for credential harvesting, initial telemetry (including ~500 impacted packages and cryptojacker reports), and recommended mitigations such as auditing dependencies, rotating credentials, and enforcing MFA.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.