logo

Stories from the SOC: The second coming of Shai Hulud

ID: 2f36fcf5-aa7f-5a38-86a1-ee81b4b4f718

STIX ID: report--2f36fcf5-aa7f-5a38-86a1-ee81b4b4f718

Feed Name: Expel Blog

Threat Score
90/100

Date Published: 2025-12-23

Date Updated: 2026-04-27

Author: Isa Judd; Ben Nahorney

...
...

This report details "Shai Hulud: The Second Coming," a large-scale NPM supply-chain malware campaign that executes via preinstall scripts to install a Bun-based payload which harvests cloud, registry, and VCS credentials (including via TruffleHog), exfiltrates stolen secrets to attacker-controlled public GitHub repositories, registers persistent self-hosted GitHub Actions runners for backdoor access, and self-propagates by publishing compromised package versions; the report includes indicators of compromise, observed scope (tens of thousands of repositories and hundreds of packages), and remediation guidance such as credential rotation, package cleanup, and CI hardening.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.