logo

Shai-Hulud: Ongoing Package Supply Chain Compromise Delivering Data-Stealing Malware (Campaign)

ID: 63d4c47c-3f21-547a-8f25-3d0d5dd08ad7

STIX ID: report--63d4c47c-3f21-547a-8f25-3d0d5dd08ad7

Feed Name: Wiz Cloud Threat Landscape

Threat Score
90/100

Date Published: 2025-09-15

Date Updated: 2026-05-01

Author: [email protected] (Wiz Threat Research)

...
...

On 2025-09-15, malicious versions of multiple popular npm packages were published containing post-install scripts that use TruffleHog to harvest secrets (environment variables, cloud IMDS keys, and repository credentials) and exfiltrate them to attacker-controlled GitHub repositories named "Shai-Hulud" and a webhook. Valid GitHub tokens are validated and abused to: create public dumps, push GitHub Actions that exfiltrate repository secrets, and migrate private organizational repos to public attacker-controlled accounts; the campaign is self-propagating and is linked to earlier GitHub token theft in the s1ngularity campaign.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.