sha1_hulud
Sha1-Hulud is a threat actor responsible for a significant supply chain attack targeting npm repositories. Between November 21 and 23, 2025, the Sha1-Hulud campaign compromised hundreds of npm packages, including those from high-profile organizations such as Zapier, ENS Domains, PostHog, and Postman. The attack leveraged the widespread use of npm packages to maximize impact across the software supply chain. There is no direct attribution to a nation-state or known cybercriminal group, and no aliases or sub-groups are mentioned in the available content. The primary tactic involved compromising legitimate packages to distribute malicious code to downstream users and organizations.
Know when an actor pivots toward your sector
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Tradecraft
21 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
Recent activity
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Sha1-Hulud is conducting large-scale supply chain attacks by trojanizing npm packages, stealing credentials, propagating itself via compromised developer accounts, and enabling remote code execution through GitHub Actions. The latest campaign includes destructive self-destruct features and cross-platform support.
Sha1-Hulud is conducting a large-scale software supply chain attack by compromising npm packages to steal credentials via malicious preinstall scripts. The campaign has affected over 25,000 repositories and several high-profile packages.
The version that knows your environment.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.