A supply-chain malware campaign known as Shai-Hulud compromised hundreds of packages in the npm ecosystem and later spread into both npm and PyPI, using stolen maintainer credentials and trusted publishing workflows to push trojanized releases. Early reporting said the worm affected more than 500 npm packages, searched infected developer and CI/CD environments for GitHub Personal Access Tokens, cloud API keys, and other secrets, and exfiltrated them to attacker-controlled infrastructure and public GitHub repositories. GitHub removed hundreds of malicious packages, while CISA urged organizations to review dependencies, check for cached malicious packages, rotate credentials, and enforce phishing-resistant MFA for developer accounts.
Later waves became more aggressive and broader in scope. Researchers said a second campaign hit hundreds more npm packages and had a blast radius exceeding 27,000 repositories, abusing preinstall and other lifecycle hooks to steal secrets, hijack GitHub Actions, self-propagate into additional packages, and in some cases deploy a conditional wiper-like payload. A subsequent Mini Shai-Hulud wave affected more than 170 packages across npm and PyPI, including packages tied to TanStack, Mistral AI, OpenSearch, Guardrails AI, UiPath, and others; it used files such as router_init.js, invoked Bun through malicious package scripts, targeted npm, GitHub, cloud, Kubernetes, Vault, and CI/CD credentials, and demonstrated that provenance and OIDC-based trusted publishing can still be abused when attacker-controlled code runs inside legitimate release workflows.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
14 events from the most recent confirmed update back to the earliest known activity.
OX Security said npm v12 is expected in July 2026 and will disable automatic install scripts, block Git dependencies by default, and require opt-in for remote URL dependencies. The article framed these changes as partial mitigations that would not stop attacks based on maintainer compromise, native builds, or malicious code executed at require() or import() time.
Cynet released a detailed analysis of the latest Mini Shai-Hulud wave, describing JavaScript and Python variants, affected packages, and indicators including malicious hashes and the domain filev2.getsession.org. The report highlighted worm-like propagation, CI/CD targeting, and links to AI-assisted development workflows.
Aikido reported that Mini Shai-Hulud had expanded into a broader npm compromise affecting 373 malicious package-version entries across 169 package names, including TanStack and Mistral-related packages. The report described credential theft, GitHub workflow abuse, and trusted publishing abuse via OIDC-minted npm tokens.
A new wave of the Shai-Hulud supply-chain campaign was discovered affecting both npm and PyPI, with more than 170 packages reportedly compromised. The malware targeted developer machines, CI/CD runners, and build systems to steal credentials and propagate through legitimate publishing workflows.
ZDI published its blog post detailing the disclosure timelines and technical dispute over two Windows-related module resolution and local attack issues involving npm CLI and Discord. The publication framed both as zero-day advisories after the vendors declined to treat them as security vulnerabilities.
Following additional discussions in December 2025, ZDI notified Discord of its intent to publish a zero-day advisory for the disputed issue. Discord had maintained that the reported behavior was out of scope because it involved local attacks.
After urging reassessment of the npm CLI issue, ZDI informed the vendor of its intent to publish a zero-day advisory. This followed the vendor's earlier position that the behavior was not a security vulnerability.
Researchers said the second wave affected more than 27,000 repositories across about 350 users and included packages linked to organizations such as Zapier, ENS Domains, PostHog, and Postman. They also noted more aggressive capabilities including cross-victim exfiltration, self-healing, Linux privilege escalation, and a conditional destructive payload.
A second major campaign, dubbed Sha1-Hulud or Shai-Hulud 2.0, compromised hundreds of npm packages uploaded between November 21 and 23, 2025. Researchers said it abused compromised maintainer accounts and used preinstall execution to steal secrets and spread further.
CISA warned organizations to monitor for malicious dependencies and cached packages following the npm ecosystem compromise. The agency recommended credential rotation, dependency checks, and phishing-resistant MFA for developer accounts.
In response to the Shai-Hulud campaign, GitHub said it removed more than 500 packages from npm and blocked new packages containing the malware's indicators of compromise. This was part of mitigation efforts to contain the supply-chain attack.
A major npm supply-chain attack tracked as Shai-Hulud compromised more than 500 packages. The malware stole credentials such as GitHub personal access tokens and cloud API keys and exfiltrated them to attacker-controlled infrastructure and a public repository.
ZDI notified Discord of a security issue involving behavior the company later classified as out of scope because it required local access. This began the disclosure process for the second disputed case described in the report.
ZDI submitted a report about dangerous module resolution behavior involving npm CLI on Windows. The vendor acknowledged the report the same day and responded that the behavior was by design rather than a security issue.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
7 references tracked. Mallory keeps watching after this page renders.
ox.security
Open sourcecynet.com
Open sourceaikido.dev
Open sourcethezdi.com
Open sourcezerodayinitiative.com
Open sourcethehackernews.com
Open sourcecybersecuritydive.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.