logo

Shai-Hulud worm returns stronger and more automated than ever before

ID: ccbef360-2c85-5158-88a8-a8ae2d29a10f

STIX ID: report--ccbef360-2c85-5158-88a8-a8ae2d29a10f

Feed Name: CyberScoop

Threat Score
85/100

Date Published: 2025-11-24

Date Updated: 2026-04-21

Author: Matt Kapko

...
...

Security researchers have identified an ongoing supply-chain campaign using a Shai‑Hulud worm that trojanized nearly 500 npm packages and exposed developer tokens, impacting more than 26,000 GitHub repositories; the malware steals credentials, uses stolen npm tokens to propagate automatically, creates malicious preinstall artifacts and public repos with stolen data, and has been observed downloading to real environments before package removal, increasing the likelihood of downstream exploitation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.