logo

Sha1-Hulud: The Second Coming of The New npm GitHub Worm

ID: 57443c49-b328-5e3e-8843-c5732f59d686

STIX ID: report--57443c49-b328-5e3e-8843-c5732f59d686

Feed Name: LevelBlue SpiderLabs Blog

Threat Score
88/100

Date Published: 2025-12-03

Date Updated: 2026-04-28

Author: Karl Sigler

...
...

Sha1-Hulud has re-emerged with a supply-chain attack targeting npm packages: infected packages include a preinstall loader (setup_bun.js) that runs an obfuscated payload (bun_environment.js) to harvest credentials (tokens, API keys, cloud creds), use discovered npm tokens to republish and poison the victim’s maintained packages (worm-like propagation), create public GitHub repositories to exfiltrate data, abuse GitHub Actions to execute arbitrary commands locally, and include a destructive self‑destruct that overwrites/shreds user files; nearly 1,000 packages and tens of thousands of repositories are reported impacted and multiple SHA256 IoCs are listed.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.