logo

Shai-Hulud 2.0 Supply Chain Attack (Campaign)

ID: 58aa31f9-07e4-5f48-ad06-c7a008e64e9c

STIX ID: report--58aa31f9-07e4-5f48-ad06-c7a008e64e9c

Feed Name: Wiz Cloud Threat Landscape

Threat Score
90/100

Date Published: 2025-11-24

Date Updated: 2026-05-01

Author: [email protected] (Wiz Threat Research)

...
...

Shai-Hulud 2.0 is an ongoing supply-chain campaign that trojanized hundreds of npm packages to steal credentials from developer machines and CI/CD pipelines; attackers exfiltrate secrets into attacker-controlled GitHub repositories, deploy persistent backdoors by registering compromised machines as self-hosted runners, and have harvested thousands of sensitive items (including cloud credentials and GitHub tokens), impacting over 25,000 repositories and generating roughly 1,000 new exfiltration repositories every 30 minutes.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.