Shai Hulud Campaign is a threat campaign tracked across 4 threat clusters and 2 intelligence report mentions on ThreatCluster. First observed November 13, 2025; most recent activity November 25, 2025.
The Shai Hulud Campaign is an active threat operation known for exploiting GitHub Actions security gaps to breach CI/CD pipelines and deploy payloads. A separate campaign, IndonesianFoods, leverages npm to publish a large set of malicious packages. Together, these incidents underscore the growing risk of supply-chain and automation-platform abuse in modern software development, impacting developers and organizations relying on GitHub Actions and npm.
The Shai Hulud worm has compromised more than 26,000 public repositories in a supply chain attack. The attack targeted various npm packages, exploiting vulnerabilities that allowed unauthorized access to these…
A large-scale spam campaign known as the IndonesianFoods worm has targeted the npm ecosystem, deploying over 43,000 malicious packages across at least 11 user accounts. This attack, which has been ongoing for more than…
A new wave of the Shai-Hulud malware has compromised nearly 500 npm packages, affecting over 26,000 GitHub repositories. This self-replicating worm, which targets developers' credentials and secrets, has been linked to…
A large-scale spam campaign, known as the IndonesianFoods worm, has inundated the npm registry with over 100,000 spam packages. This campaign, which has been ongoing for more than two years, utilizes at least 11…