216.73.217.22

Shai-Hulud worm infects npm packages

· Published 25/09/2025 14:10 · Modified 25/09/2025 19:01

Export JSON

Essential information

Published
25/09/2025 14:10
Modified
25/09/2025 19:01
Tags
2025-09-25 data theft github npm package-infection self-propagating shai-hulud supply chain attack worm
Related entities
9 techniques (mitre)

Description

A malware called has infected over 500 packages, including one with over two million weekly downloads. The steals sensitive data, exposes private repositories, and hijacks victim credentials to spread further. It executes when an infected package is installed, collecting system information and tokens. The malware exfiltrates secrets from repositories, migrates private repositories to public, and self-replicates by infecting the victim's most downloaded packages. Notable infected libraries include those from CrowdStrike. The infection started with ngx-bootstrap version 18.1.4. Prevention measures include using specialized solutions for monitoring open-source components and implementing comprehensive security systems.

External references