By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
World of SoftwareWorld of SoftwareWorld of Software
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Search
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
Reading: Shai Hulud malware turns developers into unwitting distributors in NPM supply chain attacks – News
Share
Sign In
Notification Show More
Font ResizerAa
World of SoftwareWorld of Software
Font ResizerAa
  • Software
  • Mobile
  • Computing
  • Gadget
  • Gaming
  • Videos
Search
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Have an existing account? Sign In
Follow US
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
World of Software > News > Shai Hulud malware turns developers into unwitting distributors in NPM supply chain attacks – News
News

Shai Hulud malware turns developers into unwitting distributors in NPM supply chain attacks – News

News Room
Last updated: 2025/12/27 at 1:32 AM
News Room Published 27 December 2025
Share
Shai Hulud malware turns developers into unwitting distributors in NPM supply chain attacks –  News
SHARE

A new report out today from managed detection and response company Expel Inc. details a newly identified variant of the Shai Hulud malware that is demonstrating how software supply chain attacks are evolving beyond isolated package compromises into self-propagating campaigns that turn developers themselves into distribution points.

Shai Hulud is a malware campaign first observed in September targeting the JavaScript ecosystem that focuses on supply chain compromise rather than traditional endpoint infection, using trojanized node packet manager or npm packages to steal credentials and propagate itself.

The updated Shai Hulud campaign targets the JavaScript ecosystem by automating the compromise of developer environments and the NPM package registry through a combination of credential harvesting, cloud secret theft and rapid self-propagation.

Once executed, typically during an npm install operation on a developer workstation or continuous integration and continuous delivery system, the malware deploys a two-stage infection chain embedded in malicious npm packages.

The first stage of the new Shai Hulud variant prepares the targeted environment by installing the Bun JavaScript runtime if it is not already present on the system. The second stage then involves the launch of a heavily obfuscated payload running in the background that orchestrates credential harvesting, data exfiltration and propagation.

The malware aggressively searches for sensitive credentials across local systems, including cloud provider keys, npm publishing tokens and GitHub authentication data. It also leverages the TruffleHog security scanning tool to crawl a victim’s home directory for hard-coded secrets buried in source code, configuration files and git history.

If Shai Hulud finds cloud credentials, it goes a step further by querying cloud-native secret managers such as Amazon Web Services Inc.’s Secrets Manager, Microsoft Corp.’s Azure Key Vault and Google LLC’s Cloud Secret Manager to extract additional secrets directly from the cloud.

At this point, Shai Hulud differs from traditional malware by abusing GitHub infrastructure to blend in with legitimate developer traffic instead of using command and control servers. All stolen credentials and system metadata are exfiltrated to newly created public GitHub repositories. Infected machines are also registered as self-hosted GitHub Actions runners to give the attackers persistent remote access.

To sustain the attack, the malware weaponizes compromised developer accounts by injecting malicious code into other npm packages maintained by the victim and automatically publishing updated versions to the registry.

Expel estimates the campaign has touched more than 25,000 repositories and hundreds of packages, including projects associated with widely used developer tools.

The report concludes by noting that Shai Hulud represents a shift in supply chain risk by targeting the trust layer of modern software development. Though the current campaign focuses on npm, Expel warns that similar attacks could emerge across other language ecosystems that rely on comparable trust models, including PyPI, RubyGems and Composer.

Image: News/Ideogram

Support our mission to keep content open and free by engaging with theCUBE community. Join theCUBE’s Alumni Trust Network, where technology leaders connect, share intelligence and create opportunities.

  • 15M+ viewers of theCUBE videos, powering conversations across AI, cloud, cybersecurity and more
  • 11.4k+ theCUBE alumni — Connect with more than 11,400 tech and business leaders shaping the future through a unique trusted-based network.

About News Media

News Media is a recognized leader in digital media innovation, uniting breakthrough technology, strategic insights and real-time audience engagement. As the parent company of News, theCUBE Network, theCUBE Research, CUBE365, theCUBE AI and theCUBE SuperStudios — with flagship locations in Silicon Valley and the New York Stock Exchange — News Media operates at the intersection of media, technology and AI.

Founded by tech visionaries John Furrier and Dave Vellante, News Media has built a dynamic ecosystem of industry-leading digital media brands that reach 15+ million elite tech professionals. Our new proprietary theCUBE AI Video Cloud is breaking ground in audience interaction, leveraging theCUBEai.com neural network to help technology companies make data-driven decisions and stay at the forefront of industry conversations.

Sign Up For Daily Newsletter

Be keep up! Get the latest breaking news delivered straight to your inbox.
By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
Share This Article
Facebook Twitter Email Print
Share
What do you think?
Love0
Sad0
Happy0
Sleepy0
Angry0
Dead0
Wink0
Previous Article Claim Free Rewards Before They Expire Claim Free Rewards Before They Expire
Next Article The 9 top cybersecurity startups from Disrupt Startup Battlefield  |  News The 9 top cybersecurity startups from Disrupt Startup Battlefield  | News
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Stay Connected

248.1k Like
69.1k Follow
134k Pin
54.3k Follow

Latest News

Forgotten tech to sell in January worth £1000s including consoles, DVDs & more
Forgotten tech to sell in January worth £1000s including consoles, DVDs & more
News
Ride1Up Portola e-bike review: A foldable e-bike geared towards the everyman
Ride1Up Portola e-bike review: A foldable e-bike geared towards the everyman
News
The six ways to slash your TV streaming bills and save £100s in 2026
The six ways to slash your TV streaming bills and save £100s in 2026
News
The 9 top cybersecurity startups from Disrupt Startup Battlefield  |  News
The 9 top cybersecurity startups from Disrupt Startup Battlefield  | News
News

You Might also Like

Forgotten tech to sell in January worth £1000s including consoles, DVDs & more
News

Forgotten tech to sell in January worth £1000s including consoles, DVDs & more

8 Min Read
Ride1Up Portola e-bike review: A foldable e-bike geared towards the everyman
News

Ride1Up Portola e-bike review: A foldable e-bike geared towards the everyman

1 Min Read
The six ways to slash your TV streaming bills and save £100s in 2026
News

The six ways to slash your TV streaming bills and save £100s in 2026

9 Min Read
The 9 top cybersecurity startups from Disrupt Startup Battlefield  |  News
News

The 9 top cybersecurity startups from Disrupt Startup Battlefield  | News

4 Min Read
//

World of Software is your one-stop website for the latest tech news and updates, follow us now to get the news that matters to you.

Quick Link

  • Privacy Policy
  • Terms of use
  • Advertise
  • Contact

Topics

  • Computing
  • Software
  • Press Release
  • Trending

Sign Up for Our Newsletter

Subscribe to our newsletter to get our newest articles instantly!

World of SoftwareWorld of Software
Follow US
Copyright © All Rights Reserved. World of Software.
Welcome Back!

Sign in to your account

Lost your password?