logo

Shai-Hulud: Ongoing Package Supply Chain Worm Delivering Data-Stealing Malware

ID: 5e2372bb-ecde-503b-83d5-646adc96c9a4

STIX ID: report--5e2372bb-ecde-503b-83d5-646adc96c9a4

Feed Name: Wiz Blog

Threat Score
92/100

Date Published: 2025-09-16

Date Updated: 2026-05-01

...
...

On September 15, 2025 malicious versions of numerous npm packages were published containing post‑install scripts that harvest secrets (env vars, cloud IMDS keys, etc.) and exfiltrate them to attacker GitHub repos named “Shai‑Hulud.” The payload also scans for and validates GitHub/npm tokens and abuses discovered tokens to automatically publish further malicious package versions, producing a self‑propagating npm worm that has poisoned many packages and exposed multiple users’ secrets; the report lists affected packages and advises revoking/regenerating leaked tokens and keys.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.