A new variant of the Shai-Hulud malware, dubbed "Sha1-Hulud: The Second Coming," has compromised over 70 npm packages, including those associated with Zapier and ENS Domains. The attack involves malicious code that steals developer credentials and publicly exposes them by creating thousands of GitHub repositories labeled with the campaign's name. This incident represents a significant escalation in supply chain attacks within the JavaScript ecosystem, with the malware demonstrating advanced self-propagation capabilities and surpassing the impact of previous Shai-Hulud campaigns within hours of detection.
Security researchers have urged immediate action for developers and organizations using npm packages, recommending checks for compromised package versions, auditing of GitHub accounts for unauthorized repositories, and remediation steps such as removing affected node_modules directories and clearing npm caches. The attack highlights the ongoing risks posed by supply chain threats in open-source ecosystems and the need for vigilant monitoring and rapid response to emerging malware campaigns.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
18 events from the most recent confirmed update back to the earliest known activity.
On 2026-05-11, StepSecurity said the revived Mini Shai-Hulud campaign had compromised additional legitimate npm packages from maintainers including UiPath and DraftLab, not just TanStack. The attackers used hijacked CI/CD credentials and GitHub Actions OIDC publishing flows to release malicious packages that still carried valid SLSA Build Level 3 provenance attestations, marking a broader supply-chain escalation.
On 2026-05-11, ten malicious versions of official @tanstack/* packages were published within minutes in a live npm supply-chain attack linked by StepSecurity to the self-propagating Shai-Hulud worm. The trojanized TanStack Router-related packages carried a large obfuscated payload to steal GitHub tokens, npm tokens, and CI/CD secrets, and maintainers were notified as the incident unfolded.
Later updates to the Mini Shai-Hulud investigation identified additional trojanized packages, including intercom-client@7.0.5 on npm and lightning@2.6.2 and 2.6.3 on PyPI. The newly observed payloads broadened credential theft in Kubernetes and HashiCorp Vault environments and used GitHub commit-based fallback discovery with keywords such as "beautifulcastle."
StepSecurity reported that the official npm package intercom-client@7.0.4 was maliciously published on 2026-04-30 through a hijacked GitHub Actions OIDC publishing pipeline. The tainted release added a preinstall-stage payload that expanded the campaign beyond GitHub and npm token theft to harvesting AWS, GCP, Azure, private key, and other API secrets.
Following disclosure of the 'Mini Shai-Hulud' supply-chain attack, maintainers released clean replacement versions for affected SAP-related npm packages including mbt and several @cap-js packages. The action was intended to remove the malicious preinstall payload and restore safe package distribution.
StepSecurity disclosed a coordinated npm supply-chain attack affecting SAP development ecosystem packages including mbt v1.2.48, @cap-js/sqlite v2.2.2, @cap-js/postgres, and @cap-js/db-service. The campaign reused Shai-Hulud-style credential theft and GitHub repo creation but added a new evasion technique by downloading the Bun runtime and executing a heavily obfuscated payload during installation.
By early December, analysis estimated the second wave had infected more than 800 packages, exposed roughly 400,000 raw secrets, and published them across about 30,000 GitHub repositories. Researchers also warned that many leaked npm tokens were still valid as of December 1, creating continued risk of further supply-chain abuse.
StepSecurity reported that in late November its Harden Runner detected Shai-Hulud activity in CNCF Backstage workflows by flagging anomalous connections to bun.sh and TruffleHog infrastructure. The case showed the malware attempting to download tooling and register a self-hosted GitHub Actions runner for persistence.
PostHog later disclosed that the incident was its biggest security event and traced the initial compromise to a CI/CD workflow misconfiguration that exposed a high-privilege GitHub token. The company said it revoked compromised tokens, removed malicious versions, issued clean releases, and began hardening its publishing and workflow controls.
By November 26, reporting said the Shai-Hulud v2 campaign had spread from npm to Maven, with at least one Maven Central package compromised. This represented a cross-ecosystem escalation beyond the original npm-focused outbreak.
The campaign reporting noted public acknowledgements from affected organizations including PostHog and Postman. Their statements confirmed that prominent package ecosystems had been caught up in the second-wave compromise.
As the worm rapidly created public repositories under victims' GitHub accounts to leak secrets, GitHub started removing compromised repositories. Reports noted cleanup was difficult because new exposed repositories were appearing at a very high rate.
On November 24, 2025, multiple security firms and news outlets disclosed an active second-wave npm supply-chain attack dubbed Shai-Hulud 2.0. Early reporting described a self-replicating worm stealing secrets, publishing them to public GitHub repositories, and spreading through trojanized npm packages.
Aikido reported the first observed compromised packages on November 24 included go-template and multiple AsyncAPI packages, followed shortly by PostHog and Postman packages. This marked the visible breakout of the renewed campaign across prominent projects.
Arctic Wolf and other reports said malicious package versions were uploaded between November 21 and November 23, 2025. These trojanized releases seeded the second-wave infection across the npm ecosystem.
Researchers said the new Shai-Hulud 2.0 variant had been active since at least November 21, 2025. This wave introduced a more aggressive preinstall-stage infection chain and automated propagation through compromised maintainer accounts.
Multiple references describe the November campaign as a second wave following an earlier Shai-Hulud incident in September 2025. That first wave established the malware family and its npm-focused supply-chain behavior before the later escalation.
Trend Micro reported the broader Shai-Hulud campaign was first observed in a targeted phishing attack that marked the start of the malware activity later linked to the npm worm. This earlier activity set the stage for the later second-wave supply-chain compromise.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
41 references tracked. Mallory keeps watching after this page renders.
github.com
Open sourceox.security
Open sourceinfoworld.com
Open sourcestepsecurity.io
Open sourcebleepingcomputer.com
Open sourcethehackernews.com
Open sourcesocket.dev
Open sourcestepsecurity.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.