Shai-Hulud 2.0 NPM malware attack exposed up to 400,000 dev secrets
ID: 0a20e2d5-839a-5419-9073-ad49ff8f14d9
STIX ID: report--0a20e2d5-839a-5419-9073-ad49ff8f14d9
Feed Name: Bleeping Computer
Shai-Hulud 2.0 is a large-scale NPM supply-chain malware campaign that compromised hundreds of packages (impacting over 800 package versions), harvested roughly 400,000 raw secrets with TruffleHog, and published the stolen data across about 30,000 GitHub repositories; researchers found hundreds of still-valid credentials (including NPM tokens), infections primarily landed via preinstall hooks, targeted a small set of high-impact packages, and included a conditional destructive wipe payload, creating a significant active risk of follow-on supply-chain attacks.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
