Shai Hulud 2.0 is a threat campaign tracked across 3 threat clusters and 2 intelligence report mentions on ThreatCluster. First observed November 26, 2025; most recent activity April 9, 2026.
Shai Hulud 2.0 is a threat campaign described in the CC-4722 - SHA1 report (2025-11-26). It appears to be an evolution of earlier Shai Hulud activity, featuring modular malware and staged infection chains designed to achieve persistence and data exfiltration, with emphasis on evasion and adaptable behavior. The campaign is significant due to its multi-stage capabilities and targeted approach against organizations.
The Shai Hulud worm has compromised more than 26,000 public repositories in a supply chain attack. The attack targeted various npm packages, exploiting vulnerabilities that allowed unauthorized access to these…
A recent Cloudsmith survey indicates that most engineering teams are unprepared for the EU Cyber Resilience Act's requirements regarding software bills of materials (SBOMs). Only 25% of engineering teams automatically…
A new wave of the Shai-Hulud malware has compromised nearly 500 npm packages, affecting over 26,000 GitHub repositories. This self-replicating worm, which targets developers' credentials and secrets, has been linked to…