Sha1-Hulud Campaign — Campaign Analysis & Threat Activity

Threat entity extracted from intelligence sources

Frequency
1
occurrences
First Seen
November 25, 2025
Last Seen
November 25, 2025

The Sha1-Hulud (Shai-Hulud) campaign is a re-emergent threat operation that leverages the npm ecosystem to disseminate malicious code, exploiting supply-chain vectors in Node.js projects.

Overview

The Sha1-Hulud (Shai-Hulud) campaign is a re-emergent threat operation that leverages the npm ecosystem to disseminate malicious code, exploiting supply-chain vectors in Node.js projects. It features modular, evolving techniques designed for stealthy distribution and persistence within widely used packages, highlighting the growing risk of dependency-based compromise. Its significance stems from npm's ubiquity and the potential reach of attackers into downstream software ecosystems.

Related Threat Clusters

Recent Intelligence Reports

  • The Second Coming of Shai-Hulud: Attackers Innovating on npm — Sonatype · November 25, 2025

CVSS v3.1 Breakdown