logo

FAQ: The Shai-hulud npm worm attack explained

ID: 65f4569f-cc2d-5f1d-bbfc-857b5a844597

STIX ID: report--65f4569f-cc2d-5f1d-bbfc-857b5a844597

Feed Name: ReversingLabs Blog

Threat Score
85/100

Date Published: 2025-09-30

Date Updated: 2026-04-29

Author: Paul Roberts

...
...

Shai-hulud is a self-propagating worm observed in the npm registry that compromises maintainer accounts to add malicious postinstall scripts which execute a bundle that searches for and exfiltrates environment tokens (npm, GitHub, AWS, GCP) and attempts to copy private GitHub repos; attackers exfiltrate data to attacker-created GitHub repositories and propagate by automatically publishing infected versions of packages, affecting hundreds of projects including high-download libraries and prompting recommendations for improved registry controls, 2FA, token hygiene, and automated detection.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.