Shai Hulud Campaign — Campaign Analysis & Threat Activity

Threat entity extracted from intelligence sources

Frequency
2
occurrences
First Seen
November 13, 2025
Last Seen
November 25, 2025

Shai Hulud Campaign is a threat campaign tracked across 4 threat clusters and 2 intelligence report mentions on ThreatCluster. First observed November 13, 2025; most recent activity November 25, 2025.

Overview

The Shai Hulud Campaign is an active threat operation known for exploiting GitHub Actions security gaps to breach CI/CD pipelines and deploy payloads. A separate campaign, IndonesianFoods, leverages npm to publish a large set of malicious packages. Together, these incidents underscore the growing risk of supply-chain and automation-platform abuse in modern software development, impacting developers and organizations relying on GitHub Actions and npm.

Related Threat Clusters

Recent Intelligence Reports

  • Shai Hulud Attacks Continue Through GitHub Actions Security Gaps — Aikido.Dev · November 25, 2025
  • “IndonesianFoods” npm Worm Publishes 44,000 Malicious Packages — Infosecurity-Magazine · November 13, 2025

CVSS v3.1 Breakdown