Sha1-Hulud is a malware campaign focused on software supply-chain compromise in the Node Package Manager ecosystem. It is known for trojanizing npm packages to target developer workstations, CI/CD-adjacent environments, and downstream code repositories. Activity attributed to Sha1-Hulud was observed in multiple waves during 2025, including an initial campaign and a more advanced follow-on operation sometimes referred to as Sha1-Hulud 2.0. The campaign is characterized by malicious package preinstall execution, credential theft, propagation through stolen package-publishing credentials, and abuse of developer tooling and source-code hosting workflows. Reported credential collection includes npm tokens, GitHub tokens, API keys, cloud credentials, and session material. The malware has also been observed using automated secret-scanning functionality to harvest additional credentials from victim environments. A notable feature of the later campaign is worm-like propagation: stolen npm credentials are used to trojanize and republish additional packages, expanding the compromise across the npm ecosystem and into dependent repositories. The malware also abuses GitHub Actions by installing a runner and deploying malicious workflow logic to enable remote code execution through the victim’s GitHub environment. Sha1-Hulud supports Linux, macOS, and Windows, indicating deliberate cross-platform targeting of modern development environments. It also incorporates destructive behavior intended as a punitive or anti-analysis measure. If the malware detects interference or analysis, it attempts to irreversibly destroy victim files, including overwriting data on affected systems. This combination of supply-chain compromise, credential theft, propagation, remote execution, and destructive capability makes Sha1-Hulud a high-impact threat to software publishers and organizations that rely on npm packages. Known targeting includes widely used npm packages associated with software and SaaS vendors such as Zapier, ENS Domains, PostHog, and Postman. The campaign’s operational profile is most consistent with financially motivated theft and follow-on abuse of compromised developer and package-publishing accounts.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
21 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Sha1-Hulud is conducting large-scale supply chain attacks by trojanizing npm packages, stealing credentials, propagating itself via compromised developer accounts, and enabling remote code execution through GitHub Actions. The latest campaign includes destructive self-destruct features and cross-platform support.
Sha1-Hulud is conducting a large-scale software supply chain attack by compromising npm packages to steal credentials via malicious preinstall scripts. The campaign has affected over 25,000 repositories and several high-profile packages.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.