logo

Self-Replicating Worm Hits 180+ Software Packages

ID: 1774175d-ae28-5ef2-bae5-ab39b45dd589

STIX ID: report--1774175d-ae28-5ef2-bae5-ab39b45dd589

Feed Name: Krebs on Security

Threat Score
85/100

Date Published: 2025-09-16

Date Updated: 2026-04-19

Author: BrianKrebs

...
...

A self‑propagating supply‑chain malware strain called "Shai‑Hulud" has infected numerous NPM packages: it locates npm/GitHub tokens and other credentials on compromised developer machines (Linux/macOS), injects itself into the top ~20 packages accessible to the token, and publishes harvested secrets to new public GitHub repositories named with "Shai‑Hulud." The worm leverages TruffleHog for reconnaissance, can enumerate cloud (AWS/Azure/GCP) secrets, briefly impacted code packages (including some tied to CrowdStrike), and has prompted rapid removals, key rotations, and calls for stronger publication 2FA and human consent controls on package registries.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.