npm Supply Chain Attack
ID: e6db48b2-fcfc-5a7d-a1ff-f79651bdd98c
STIX ID: report--e6db48b2-fcfc-5a7d-a1ff-f79651bdd98c
Feed Name: FortiGuard Threat Signals
On September 8 and November 24, 2025, a supply-chain campaign attributed to "Shai Hulud" compromised an npm maintainer and multiple developer services (Zapier, ENS, AsyncAPI, PostHog, Postman), publishing malicious package versions and deploying a self‑replicating worm that impacted over 500 packages and roughly 25,000 repositories across ~350 users; the malware scanned for and exfiltrated credentials including GitHub PATs and cloud API keys (AWS, GCP, Azure). The incident poses high risk to frontend JavaScript applications (notably payment/crypto flows); mitigations advised include pinning and blocking malicious dependency versions, rotating tokens, enforcing phishing-resistant MFA, auditing CI/CD, enabling secret scanning, and blocking known exfiltration domains.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
