A self-propagating worm named Shai Hulud has compromised hundreds of npm packages, including high-profile ones from CrowdStrike and others, by leveraging compromised maintainer accounts. The malware harvests secrets from CI/CD environments and cloud metadata, exfiltrates them via GitHub repositories and malicious workflows, and automatically republishes itself to other packages. This incident marks a significant escalation in open source supply chain attacks, with rapid propagation and widespread exposure of sensitive data.
Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
7 events from the most recent confirmed update back to the earliest known activity.
JFrog reported an active 2026-05-19 wave of the Shai-Hulud supply-chain campaign that compromised 325 legitimate npm packages, mainly in the @antv ecosystem, and also identified related compromises in the PyPI package durabletask and npm package @cap-js/openapi. The report described new delivery and propagation details, including optionalDependencies-based payload fetching, Linux-focused PyPI malware with AWS Systems Manager and Kubernetes lateral movement, and warned that revoking stolen GitHub tokens can trigger destructive dead-man-switch behavior.
A local Python IOC scanner for Mini Shai-Hulud and Shai-Hulud npm supply-chain compromise indicators was published on GitHub. The tool checks for malicious files, hashes, compromised package versions, suspicious npm scripts, obfuscated payloads, stored npm tokens, and other local artifacts, with the bundled IOC feed reviewed on 2026-05-11.
Elastic Security Labs published an updated response to the Shai-Hulud Worm 2.0 npm supply-chain compromise. The publication added another vendor-backed defender resource covering the campaign and response guidance.
A GitHub repository published KQL-based Microsoft Defender hunting and detection guidance for the Shai-Hulud worm. This added publicly available defender-focused technical content for identifying related activity in enterprise telemetry.
Trend Micro published research on the evolved Shai-Hulud 2.0 campaign, describing its targeting of cloud and developer ecosystems. The report represents an additional public technical analysis of the malware and its operational scope beyond the earlier GitLab disclosure.
GitLab's Vulnerability Research team reported an active large-scale npm supply-chain campaign using an evolved Shai-Hulud variant that spreads by republishing infected packages with stolen npm tokens. GitLab also published indicators of compromise and detection guidance, describing credential theft, GitHub-based exfiltration, possible GitHub Actions runner persistence, and a destructive dead man's switch.
Initial story creation
22 references tracked. Mallory keeps watching after this page renders.
research.jfrog.com
Open sourcegithub.com
Open sourceelastic.co
Open sourcegithub.com
Open sourcetrendmicro.com
Open sourceapiiro.com
Open sourceaikido.dev
Open sourceupwind.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.