logo

Infamous Shai-hulud Worm Resurfaces From the Depths

ID: 26f3ffae-54fb-5719-970a-6ffa9e78b0ec

STIX ID: report--26f3ffae-54fb-5719-970a-6ffa9e78b0ec

Feed Name: Dark Reading

Threat Score
85/100

Date Published: 2025-11-24

Date Updated: 2026-04-21

Author: Alexander Culafi

...
...

A new, more dangerous variant of the Shai-hulud self-replicating worm is actively infecting open-source repositories (notably NPM), impacting over 25,000 repositories and compromising popular packages; it executes malicious code during the preinstall phase to steal credentials (GitHub, Azure, AWS, GCP, NPM) and, if theft/exfiltration fails, can delete writable files under the victim's home directory, indicating both long-term persistence goals and punitive sabotage.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.