logo

Shai-Hulud 2.0: Responding to the npm Worm Threatening CI/CD Security

ID: 961c5bf4-b376-522d-9ba9-3aa979c1ddc0

STIX ID: report--961c5bf4-b376-522d-9ba9-3aa979c1ddc0

Feed Name: HackerOne Blog

Threat Score
90/100

Date Published: 2025-11-26

Date Updated: 2026-06-12

...
...

**Executive Summary:** Shai-Hulud 2.0 is a self‑replicating npm/GitHub worm that steals environment variables, GitHub tokens, and cloud credentials, uses stolen credentials to re‑upload itself across maintainers' package libraries, and may delete files if attacker infrastructure is removed; the report states over 1,000 npm packages and 27,000+ GitHub repositories were infected within hours and provides immediate remediation steps for developers and CI/CD pipelines.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.