logo

Return of Shai-Hulud: The “Second Coming” of the NPM Supply Chain Compromise

ID: 2f81eaa2-e443-59fe-859b-0ae29dd972be

STIX ID: report--2f81eaa2-e443-59fe-859b-0ae29dd972be

Feed Name: Pulsedive Blog

Threat Score
90/100

Date Published: 2025-11-26

Date Updated: 2026-04-28

Author: Pulsedive Threat Research

...
...

On Nov 21–25, 2025 security vendors reported Shai-Hulud 2.0, a supply-chain campaign that compromised multiple popular npm packages (including packages tied to Zapier, ENS Domains, PostHog, and Postman). The malicious package code injects GitHub workflows that exfiltrate system and cloud secrets (AWS/GCP/Azure) — encoding collected data and committing it to public GitHub repositories — and contains destructive routines to overwrite and delete user files if GitHub/NPM tokens are not found; researchers observed environment dumps containing sensitive values and vendors were actively removing repositories.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.