The Shai-Hulud 2.0 (sha1-hulud) software-supply-chain worm continued to compromise organizations for about a month after its initial containment, reaching more than one-third of the Fortune 100 and hundreds of other victims. The main persistence mechanism was the malicious OpenVSX IDE extension asyncapi-preview version 1.0.1; additional infections came from private registries and local caches that retained revoked npm packages. Release of a clean asyncapi-preview v1.1.0 prompted IDE auto-updates and sharply reduced newly compromised public repositories, but exposed secrets remained a material downstream risk.
As of late December, hundreds of cloud credentials, more than 200 AI API keys, and numerous SaaS credentials exposed during the campaign were still valid despite broad token-revocation efforts. Researchers also linked compromised Trust Wallet GitHub and Chrome Web Store credentials to a malicious Trust Wallet browser-extension v2.68 update that led to approximately $7 million in theft; Trust Wallet said the incident was likely connected to the wider campaign. In response to such supply-chain abuse, npm 12 is introducing opt-in controls for lifecycle scripts, Git dependencies, and remote-URL dependencies, although organizations must still review package upgrades and monitor trusted dependencies because the controls do not block malicious runtime behavior.

Trace attribution and downstream blast radius.
15 events from the most recent confirmed update back to the earliest known activity.
Four packages published by the same npm account contained the SHA-256-identical Shai-Hulud payload previously observed in the May @AntV wave after 111 days without new detections. The payload was reportedly not blocked by npm publish-time malware scanning and uses a preinstall script, persistence in VS Code and Claude configuration files, token validation, and package-republication capabilities.
Elastic Security Labs identified the CHAINDROP worm in the trojanized keyv monorepo and reported that it had compromised more than 400 npm packages. The analysis documented npm preinstall-hook propagation, Claude Code and VS Code repository hooks, credential collection and encrypted exfiltration via Ethereum smart-contract-resolved infrastructure, and associated payload and dropper hashes.
A new Mini Shai-Hulud npm supply-chain campaign began with the compromise of keyv@6.0.0 at 09:35 UTC. The campaign reportedly spread to more than 800 packages across thousands of versions, using a preinstall script to download Bun and execute the obfuscated Math_Symbol.js payload.
npm v11.15.0 introduced --allow-remote, a control for explicitly approving direct and transitive dependencies fetched from remote URLs.
npm v11.10.0 introduced allowScripts to control third-party lifecycle scripts and --allow-git to control direct and transitive Git-based dependencies. Both mechanisms require explicit approval under the new controls.
The November 2025 Crypto Stealer campaign used @validate-ethereum-address/core and its aes-core-valid-ipherv dependency to conceal secret-searching and exfiltration logic in the aesCreateIpheriv() function.
GitGuardian found that a recent Shai-Hulud infostealer-worm variant searched 469 credential locations, up from 189 in earlier variants. The expanded search targets developer environments, CI/CD tooling, cloud configurations, and AI development-tool settings.
Trust Wallet stated it had high confidence that the malicious browser-extension v2.68 incident was likely related to the industry-wide Sha1-Hulud incident. Wiz had identified leaked Trust Wallet GitHub and Chrome Web Store credentials that could enable compromise of its extension distribution pipeline.
Following the clean asyncapi-preview release, daily newly compromised public repositories had fallen to only a handful.
A malicious v2.68 update to the Trust Wallet browser extension resulted in approximately $7 million in thefts. Trust Wallet said it would cover affected users' losses.
AsyncAPI published a clean v1.1.0 version of asyncapi-preview to OpenVSX. The higher-versioned release triggered IDE auto-updates and removed most outstanding extension-based infections.
Wiz Research notified AsyncAPI that malicious asyncapi-preview v1.0.1 remained active on developer endpoints. The extension accounted for more than 90% of Shai-Hulud long-tail infections.
From November 25 through December 24, the worm generated roughly 100 to 200 newly compromised public repositories per day despite containment actions by npm and ecosystem partners. Private registries and local package caches accounted for about 5% of these long-tail infections.
The OpenVSX Registry removed the malicious asyncapi-preview v1.0.1 extension, but it remained installed and active on affected developer endpoints and drove persistent infections.
GHArchive recorded 13,686 new public GitHub repositories containing exfiltrated victim data at the outbreak's peak. Wiz captured more than 25,000 repositories during the first day of the incident.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 13 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See attribution and downstream blast radius, and whether this package or vendor reaches your builds.
14 references tracked. Mallory keeps watching after this page renders.
itpro.com
Open sourcemalware.news
Open sourcecryptika.com
Open sourcecybersecuritynews.com
Open sourceopen-vsx.org
Open sourcewiz.io
Open sourcetrustwallet.com
Open sourceasyncapi.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.