Shai Hulud Malware Exploits NPM Supply Chain Vulnerabilities
First seen 23 Dec 2025, 18:00 UTC
•

•33.2
Export
Article Content
Browse articles
The Shai Hulud malware has been identified as a significant threat in NPM supply chain attacks, turning developers into unwitting distributors of malicious code. This malware typically executes during npm install operations, affecting developer workstations and CI/CD systems. The attack compromises the integrity of software development processes, posing risks to developers and their projects.
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
More articles in this cluster
Continue Reading
TeamPCP Compromises Microsoft DurableTask and GitHub Actions in Supply Chain Attack
Glassworm Botnet Targeting Developers Disrupted by CrowdStrike and Google
Mini Shai-Hulud Supply Chain Attack Targets SAP npm Packages
Shai Hulud npm Worm Compromises Over 26,000 Repositories
Shai Hulud 3.0 Variant Discovered as Supply Chain Threat
389% Increase in Account Breaches Driven by Phishing Services in 2025