Sha1-Hulud Supply Chain Attack — Campaign Analysis & Threat Activity

Threat entity extracted from intelligence sources

Frequency
1
occurrences
First Seen
November 24, 2025
Last Seen
November 24, 2025

Sha1-Hulud is a high-profile supply chain attack campaign that has compromised 800+ npm packages and thousands of GitHub repositories.

Overview

Sha1-Hulud is a high-profile supply chain attack campaign that has compromised 800+ npm packages and thousands of GitHub repositories. It underscores the pervasive risk of dependency-driven intrusions and the potential for widespread impact across the JavaScript ecosystem and downstream projects that rely on compromised packages.

Related Threat Clusters

Recent Intelligence Reports

  • Sha1-Hulud Supply Chain Attack: 800+ npm Packages and Thousands of GitHub Repos Compromised — Cybersecuritynews · November 24, 2025

Related Entities

CVSS v3.1 Breakdown