logo

Self-propagating supply chain attack hits 187 npm packages

ID: c2cdeaa2-217a-5f82-907c-e0b09e1aceab

STIX ID: report--c2cdeaa2-217a-5f82-907c-e0b09e1aceab

Feed Name: Bleeping Computer

Threat Score
88/100

Date Published: 2025-09-16

Date Updated: 2026-07-18

Author: Ax Sharma

...
...

Security researchers attribute a large, active npm supply-chain campaign called 'Shai-Hulud' that began with compromise of @ctrl/tinycolor and has expanded to at least 187 packages, including packages under CrowdStrike's npm namespace. Compromised releases include a bundle.js that downloads and runs TruffleHog to locate developer and CI secrets, validates credentials, creates malicious GitHub Actions workflows, exfiltrates data to a hardcoded webhook, and automatically repackages and republishes infected packages to propagate further; users are advised to audit environments, rotate secrets and CI tokens, and pin dependencies.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.