logo

New Shai-Hulud Worm Spells Trouble For npm Users

ID: 8cea9d3a-8014-51b1-bb4e-59432139d3bf

STIX ID: report--8cea9d3a-8014-51b1-bb4e-59432139d3bf

Feed Name: Infosecurity Magazine (News)

Threat Score
88/100

Date Published: 2025-11-25

Date Updated: 2026-04-22

...
...

Security researchers report an active secret-stealing worm called Shai-Hulud 2.0 infecting npm packages: attackers hijack maintainer accounts to publish trojanized packages that exfiltrate secrets (AWS keys, GitHub tokens) to attacker-controlled GitHub repos and propagate by creating malicious versions of other packages. Multiple vendors report hundreds to 700+ infected packages with tens to hundreds of millions of downloads and extremely rapid scaling, and experts recommend auditing dependencies, rotating secrets, disabling postinstall scripts in CI, pinning versions, and enforcing MFA.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.