logo

New Shai-Hulud malware wave compromises 600 npm packages

ID: 8a983e35-44a6-5280-8d88-5c0953dcd753

STIX ID: report--8a983e35-44a6-5280-8d88-5c0953dcd753

Feed Name: Bleeping Computer

Threat Score
90/100

Date Published: 2026-05-19

Date Updated: 2026-05-19

Author: Bill Toulas

...
...

The Shai-Hulud supply-chain campaign published hundreds of malicious npm package versions (over 600 packages / 323 unique packages reported) to steal developer and CI/CD secrets, exfiltrating data via a Session P2P network and GitHub repositories; the malware is obfuscated, encrypts stolen data, can self-propagate by republishing infected packages, and abuses OIDC tokens to create apparently valid Sigstore provenance attestations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.