logo

Shai-Hulud 2.0 NPM malware attack exposed up to 400,000 dev secrets

ID: 0a20e2d5-839a-5419-9073-ad49ff8f14d9

STIX ID: report--0a20e2d5-839a-5419-9073-ad49ff8f14d9

Feed Name: Bleeping Computer

Threat Score
78/100

Date Published: 2025-12-02

Date Updated: 2026-07-18

Author: Bill Toulas

...
...

Shai-Hulud 2.0 is a large-scale NPM supply-chain malware campaign that compromised hundreds of packages (impacting over 800 package versions), harvested roughly 400,000 raw secrets with TruffleHog, and published the stolen data across about 30,000 GitHub repositories; researchers found hundreds of still-valid credentials (including NPM tokens), infections primarily landed via preinstall hooks, targeted a small set of high-impact packages, and included a conditional destructive wipe payload, creating a significant active risk of follow-on supply-chain attacks.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.