logo

"Shai-Hulud" Worm Compromises npm Ecosystem in Supply Chain Attack (Updated September 19)

ID: 97b1f04a-4886-5436-8165-932c626a3617

STIX ID: report--97b1f04a-4886-5436-8165-932c626a3617

Feed Name: Palo Alto Networks Unit 42

Threat Score
90/100

Date Published: 2025-09-17

Date Updated: 2026-04-28

Author: Unit 42

...
...

Unit 42 describes "Shai-Hulud 2.0," a large-scale npm supply-chain worm that executes during the pre-install phase to guarantee execution across developer machines and CI/CD pipelines; it harvests npm/GitHub/cloud credentials and exfiltrates them to public GitHub repositories, self-propagates by publishing compromised package versions, and implements an aggressive fallback that can securely overwrite a user’s entire home directory if exfiltration fails. The report provides IOCs (file SHA256 hashes and a webhook URL), hunting queries, and mitigation recommendations including credential rotation, dependency auditing, and enforcement of MFA.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.