logo

Shai-Hulud was the best thing to happen to supply chain security

ID: 8fb657f0-174e-5d78-bba5-c8b8ee9618a9

STIX ID: report--8fb657f0-174e-5d78-bba5-c8b8ee9618a9

Feed Name: Aikido Security's Blog

Threat Score
90/100

Date Published: 2026-08-24

Date Updated: 2026-08-26

...
...

This report documents a sustained, evolving supply-chain campaign that weaponized npm publishing and CI pipelines—starting from phishing and long-lived token theft and escalating to Pwn Requests, runner-memory OIDC extraction, and direct abuse of OIDC endpoints—resulting in thousands of compromised repositories and hundreds of malicious package releases across npm and other ecosystems; adoption of npm Trusted Publishing rose only after high-impact waves forced behavior change.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.