logo

Massive Malicious NPM Package Attack Threatens Software Supply Chains

ID: 7903ad03-60f7-5747-8048-ce39d12e2d57

STIX ID: report--7903ad03-60f7-5747-8048-ce39d12e2d57

Feed Name: Recorded Future Blog

Threat Score
90/100

Date Published: 2025-10-06

Date Updated: 2026-04-28

...
...

### Executive Summary: The Shai-Hulud campaign is an active, worm-like supply-chain attack that trojanized over 700 NPM packages (including high-profile packages) to execute a bundle.js payload which runs credential discovery tools, steals developer and CI/CD tokens, and creates persistent GitHub Actions workflows to exfiltrate secrets to hard-coded webhooks; Recorded Future provides technical analysis, IOCs, and mitigation recommendations including removing compromised package versions, rotating tokens, and auditing CI/CD and repository workflows.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.