Bleepingcomputer
Shai-Hulud Malware Compromises 25K GitHub Repositories via npm Packages
First seen 24 Nov 2025, 15:26 UTC
•

•32.6
Export
Article Content
Browse articles
The Shai-Hulud malware has re-emerged, infecting over 500 trojanized npm packages and compromising secrets from more than 25,000 developers within three days. The malicious packages, including those from popular services like Zapier and Postman, were added to the npm registry and automatically posted encoded data to GitHub. This supply-chain attack is a continuation of a campaign that first surfaced in September 2025.
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
More articles in this cluster
Continue Reading
MuddyWater Targets U.S. Entities Amid Geopolitical Tensions
Data Destruction and Disk Wiping Techniques Targeting Organizations
Critical Vulnerabilities and Exploits Targeting Cisco, Canvas, and Microsoft Systems
Checkmarx Jenkins Plugin Compromised by TeamPCP Malware Attack
UAC-0099 Uses GuardBreaker to Manipulate AI Security in Ukraine
Megalodon Campaign Infects Over 5,500 GitHub Repositories with Malware