logo

Inside Shai-Hulud’s Maw: How The NPM Worm Exploits And Propagates

ID: 88f08b43-872d-540f-ba58-cf53703de0e9

STIX ID: report--88f08b43-872d-540f-ba58-cf53703de0e9

Feed Name: Checkmarx Zero

Threat Score
90/100

Date Published: 2025-12-09

Date Updated: 2026-04-27

Author: Bruno Dias

...
...

This report analyzes the Shai-Hulud NPM worm and its evolved variant “The Second Coming,” describing how the malware steals developer credentials and cloud secrets, propagates through injected package scripts and GitHub workflows, exfiltrates data to attacker-controlled repositories, tampers with host/network security, and installs a self-hosted GitHub Actions runner as a persistent backdoor; the second version adds stronger obfuscation, broader cloud targeting (including Azure), destructive fallback (wiping user profiles), and privilege-escalation/network tampering behaviors.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.