logo

Shai-hulud is a call to action on AppSec

ID: 475f7b0e-1ac7-5e74-adbe-7301d42e9925

STIX ID: report--475f7b0e-1ac7-5e74-adbe-7301d42e9925

Feed Name: ReversingLabs Blog

Threat Score
85/100

Date Published: 2026-01-14

Date Updated: 2026-04-29

Author: Jaikumar Vijayan

...
...

Trigger.dev's post-mortem examines the Shai-hulud npm worm incident in which a malicious package used preinstall scripts to steal developer GitHub tokens and propagate across hundreds of npm packages and thousands of repositories, allowing attackers to clone 669 repositories, create exfiltration repos, and attempt automated malicious pushes; GitHub branch protections limited the worst damage. The report outlines mitigations Trigger.dev adopted (disabling npm scripts, moving to ephemeral OIDC tokens, enabling branch protection, upgrading to npm 10) and emphasizes organization-wide supply-chain controls, package provenance/attestation, binary analysis, dependency pinning, runtime monitoring, and elimination of long-lived local credentials.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.