logo

Shai-Hulud V2 Poses Risk to NPM Supply Chain

ID: 20b12de5-a825-51d5-b90b-cf117399ae7b

STIX ID: report--20b12de5-a825-51d5-b90b-cf117399ae7b

Feed Name: Zscaler Security Research Blog

Threat Score
90/100

Date Published: 2026-01-12

Date Updated: 2026-05-01

...
...

Shai-Hulud V2 is a highly capable npm supply-chain worm that executes via preinstall hooks using the Bun runtime, harvests tokens and cloud credentials from developer and CI/CD environments, exfiltrates stolen data to attacker-owned GitHub repositories, propagates by publishing infected npm packages with stolen tokens, installs self-hosted GitHub Actions runners as persistent backdoors, and includes a dead-man switch to destruct data; the report provides detailed technical analysis, code snippets, and operational impacts.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.