Shai-Hulud Malware Targets Numerous NPM Packages in Second-Wave NPM Supply-Chain Attack
ID: 765a575e-f50a-5767-9a76-b418fc3fca8a
STIX ID: report--765a575e-f50a-5767-9a76-b418fc3fca8a
Feed Name: Arctic Wolf
On 2025-11-24 researchers identified a renewed supply-chain campaign using Shai-Hulud malware that trojanized numerous npm packages (uploaded 2025-11-21 to 2025-11-23 and continuing) to run during npm preinstall, drop an obfuscated payload that scans for developer and cloud credentials (GitHub tokens, AWS/GCP/Azure keys, npm tokens), exfiltrate them to attacker-controlled GitHub repositories, and self-propagate by publishing malicious package versions with stolen npm tokens; failures may result in deletion of users' home directories. The bulletin provides mitigation steps: review GitHub accounts for unexpected repositories, remove affected npm package versions and clear caches, rotate/revoke exposed secrets, quarantine infected hosts/CI, and contact Arctic Wolf for response.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
