Shai-Hulud V2 Campaign is a threat campaign tracked across 1 threat cluster and 1 intelligence report mention on ThreatCluster. First observed December 3, 2025; most recent activity December 3, 2025.
Shai-Hulud V2 is a threat campaign identified by ThreatLabz that targets the npm supply chain by leveraging malicious npm packages to impact downstream Node.js projects. Its significance stems from the npm ecosystem's widespread use, which enables broad dissemination of malicious payloads through dependency chains, creating a high-impact supply-chain risk in cybersecurity.
A new wave of the Shai-Hulud malware has compromised nearly 500 npm packages, affecting over 26,000 GitHub repositories. This self-replicating worm, which targets developers' credentials and secrets, has been linked to…