A major supply chain attack targeted the npm ecosystem in September 2025, where an infostealer with worm-like characteristics, dubbed Shai-Hulud, compromised over 500 npm packages. The attack leveraged a previous compromise of the s1ngularity/nx project, exploiting CI/CD pipeline credentials and propagating through both direct and indirect dependencies. Security researchers confirmed that attackers exfiltrated GitHub and npm tokens, enabling them to inject malicious code into widely used packages and potentially access internal networks, move laterally, or tamper with software releases.
The incident highlighted the persistent risks associated with CI/CD pipeline security, as attackers exploited overlooked access to secrets such as API keys and deployment tokens. The scale of the attack forced engineering and security teams worldwide to spend significant resources cleaning compromised environments and assessing exposure, even though the direct financial impact was limited. The event underscored the need for enhanced runtime security monitoring, such as eBPF-based sensors, and stricter controls on package publishing and consumption to defend against similar threats in the future.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
9 events from the most recent confirmed update back to the earliest known activity.
Datadog Security Labs publishes analysis advocating runtime security as an approach to detecting software supply-chain attacks, adding defensive guidance to the evolving threat landscape.
The threat model is expanded to include malicious extensions distributed through developer marketplaces such as Microsoft VS Code Marketplace and Open VSX, emphasizing that supply-chain compromise can occur through tooling as well as packages.
Researchers note the emergence of malware embedding LLM-prompt-based logic to drive information-stealing behavior, reflecting AI-assisted evolution in supply-chain and developer-targeted attacks.
The reporting identifies a technique in which QR-code images are used to conceal instructions or payload-delivery logic, helping malicious content evade straightforward inspection in software supply-chain contexts.
The Shai-Hulud activity is highlighted as an example of worm-like behavior in the software supply chain, where malicious changes can spread across many packages rather than remaining isolated to a single dependency.
Researchers describe newer supply-chain techniques that use automated pull requests to abuse GitHub Actions workflows, showing how attackers can scale malicious code introduction through developer collaboration processes.
The reporting cites nation-state activity by the Lazarus Group using open-source package registries including npm and PyPI as part of espionage-oriented operations, expanding the supply-chain threat model beyond financially motivated abuse.
In September 2025, the Chalk and Debug libraries were hijacked in a prominent open-source supply-chain incident, illustrating how attacks on widely used packages can trigger broad downstream disruption and incident-response work across many organizations.
Over roughly the two years preceding late 2025, software supply-chain attacks increasingly moved away from infrastructure-centric compromises such as CI/CD or update-channel tampering and toward phishing, credential theft, and other human-targeted attacks against open-source maintainers.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.