Mitigating Risks from the Shai-Hulud NPM Worm
ID: 06f268c2-ea80-514c-8e2e-0264200e0b31
STIX ID: report--06f268c2-ea80-514c-8e2e-0264200e0b31
Feed Name: Zscaler Security Research Blog
Threat Score
On September 15, 2025 ReversingLabs researchers discovered a self-replicating worm called "Shai-Hulud" in the npm registry that spreads by hijacking maintainer accounts and injecting malicious code into public and private packages; more than 200 packages and 500 versions were compromised between September 14–18, and the worm seeks sensitive data (tokens, keys, private repositories), posing a significant supply-chain risk to build environments and dependent projects.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
