216.73.216.6

Shai-Hulud 2.0: Aggressive & Automated, One Of Fastest Spreading NPM Supply Chain Attacks Ever Observed

· Published 27/11/2025 03:00 · Modified 21/12/2025 18:07

Export JSON

Essential information

Published
27/11/2025 03:00
Modified
21/12/2025 18:07
Tags
2025-11-27 automation backdoor credential harvesting github npm shai-hulud 2.0 supply chain attack worm
Related entities
4 observables, 17 techniques (mitre), 1 malware

Description

In November 2025, security researchers identified , an aggressive and automated supply-chain attack targeting the ecosystem. This second wave of the Shai-Hulud campaign demonstrated unprecedented and propagation speed, compromising hundreds of packages within hours. The malware behaves like a , automatically harvesting credentials and cloud secrets, and spreading to new accounts. It uses Actions as a persistent and creates public repositories for exfiltration. The attack represents a significant escalation in supply-chain attack sophistication, affecting major projects and organizations, and resulting in tens of thousands of attacker-created repositories.

External references