logo

Shai-Hulud npm Worm Returns, Poisoning Over 1,280 npm Packages

ID: a88fe8f2-1fbb-5a8a-bf48-7ae8e0536a67

STIX ID: report--a88fe8f2-1fbb-5a8a-bf48-7ae8e0536a67

Feed Name: HackRead

Threat Score
88/100

Date Published: 2026-08-04

Date Updated: 2026-08-04

Author: Deeba Ahmed

...
...

A fast-moving software supply-chain campaign injected a Shai-Hulud infostealer into Keyv and hundreds of npm packages by pushing malicious files and a "preinstall" lifecycle script to maintainers' repositories; the payload harvests npm/GitHub tokens, cloud keys, Vault tokens, private keys, and service tokens, then exfiltrates data to a public GitHub repo or fallback host. The campaign propagated by abusing package publishing and stolen credentials, affecting hundreds to over a thousand packages with combined billions of monthly downloads; organizations should treat any workstation or CI that executed affected versions as credential-exposed, remove affected releases, rotate credentials, inspect repositories and logs, and trigger immediate rescans.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.