Shai-Hulud is a self-propagating npm software supply-chain campaign first identified in September 2025. It compromises trusted JavaScript packages and uses installation-time or package-execution payloads to harvest developer, cloud, and CI/CD credentials. The campaign uses secret-scanning tooling, environment collection, cloud metadata access, and GitHub credential theft to identify npm tokens and other reusable credentials. Stolen publishing permissions are then used to inject malicious code into additional packages controlled by compromised maintainers, creating worm-like propagation across the npm ecosystem. Shai-Hulud has exfiltrated stolen data through attacker-created public GitHub repositories and abused GitHub workflows, commits, and self-hosted runners for command-and-control, credential exposure, and persistence. It has also forced private repositories public in some infections and introduced malicious workflow modifications. A later wave observed in November 2025 expanded cloud credential collection and included a destructive fallback intended to erase user data when reusable GitHub or npm credentials were unavailable. Subsequent activity has been reported as Mini Shai-Hulud, with broader multi-ecosystem propagation and developer-environment persistence techniques. Similarities or embedded references to Shai-Hulud alone are insufficient to attribute other supply-chain compromises, particularly activity explicitly assessed as false-flag use of related nomenclature.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
41 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
3 malware families attributed to this actor across reporting.
5 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named npm worm activity associated with a software supply-chain compromise affecting popular npm packages. The operation uses compromised maintainer access to publish malicious package versions, steals cloud and developer credentials, republishes trojanized packages using stolen tokens/OIDC trusted publishing, stages exfiltrated data in GitHub repositories, and establishes persistence via developer tooling and OS autostart mechanisms.
Referenced only for comparison; the article explicitly says the malware is not attributed to this campaign.
Named as a self-propagating npm malware/worm campaign used as comparative context for the evolution of npm supply-chain threats; not directly tied in the content to the main axios incident attribution.
Conducted npm supply-chain compromise campaigns by trojanizing packages, harvesting GitHub/npm/cloud credentials, propagating automatically across maintainer-owned packages, exfiltrating secrets via GitHub workflows/webhooks, and in a later wave adding destructive file-wiping behavior when token theft failed.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.