Shai-Hulud: the npm worm that publishes itself through its victims

Reading Time: 5 min
18
techkahwa.net | 24 September 2025

A self-replicating worm called Shai-Hulud has been spreading through the npm registry since 15 September, stealing developer credentials and pushing infected versions of the packages its victims maintain. On 23 September the US Cybersecurity and Infrastructure Security Agency (CISA) issued an alert describing “over 500 packages” compromised and told developers to pin their npm dependencies to versions released before 16 September 2025.

A worm, not just a bad package

Supply-chain attacks on npm are not new. Someone slips malicious code into a package, people install it, damage follows. What makes Shai-Hulud different is that it spreads by itself.

Here is the loop, based on reporting from Wiz Research, Palo Alto Networks’ Unit 42 and CISA:

  1. A developer installs a compromised package.
  2. The malicious code searches the machine for secrets. It uses TruffleHog, a legitimate open-source secret scanner, to find GitHub Personal Access Tokens and cloud keys for AWS, GCP and Azure.
  3. Stolen secrets are published to a new public GitHub repository named “Shai-Hulud”, created under the victim’s own account.
  4. With the victim’s credentials, the worm reaches the packages that person maintains, injects itself and publishes new infected versions.
  5. Anyone who installs those versions becomes the next victim, and the loop starts again.

There is a second, nastier step. According to Wiz and Unit 42, the worm also takes private GitHub repositories and flips them to public, adding a “-migration” suffix to the name. For a company, that can mean internal source code sitting on the open internet.

What caught my attention is the use of TruffleHog. Security teams use that tool to find leaked secrets so they can revoke them. Here, attackers turned the same tool into the harvesting engine. Good tools do not choose their users.

By the numbers

Item Figure Source
Attack start 15 September 2025 Wiz Research
Packages compromised, CISA count Over 500 CISA
Packages compromised, Wiz early count Over 100 Wiz Research
GitHub users with secrets exposed, early count 36 Wiz Research
Users with private repos forced public, early count 8 Wiz Research
Safe pinning cutoff Versions released before 16 September 2025 CISA

A word on the package numbers. They grew as researchers looked harder and as the worm kept moving. Wiz’s early count was over 100, and CISA’s alert on 23 September says over 500. The honest reading is a range, somewhere from over 100 to over 500 depending on when and who counted, and CISA’s figure is the most recent official one.

Why it matters

Modern JavaScript projects pull in long chains of dependencies, and most developers never read the code of the packages they install. That trust is what npm runs on. A worm that uses real maintainers’ accounts to publish real-looking updates attacks that trust directly. The infected versions come from the right account, under the right package name.

The damage also does not stay on the developer’s laptop. Cloud keys for AWS, GCP and Azure open the door to production systems, customer data and bills that can grow very fast if an attacker starts spinning up resources.

For developers in the Arab world, this is not a distant story. npm is the same registry whether you build in Riyadh, Cairo, Amman or Casablanca, and many startups and agencies in the region ship JavaScript every day with small teams and no dedicated security staff. That is exactly the profile a worm like this exploits.

What to do now

Based on CISA’s guidance and the research published so far, these are sensible steps for any team using npm:

  • Pin dependencies to versions released before 16 September 2025, as CISA advises, and check your lockfiles.
  • Rotate credentials. If a developer machine or CI runner installed packages since 15 September, treat GitHub tokens and cloud keys on it as exposed and replace them.
  • Check GitHub for traces. Look for any repository named “Shai-Hulud” under your accounts, and any repository with a “-migration” suffix that you did not create.
  • Review what you publish. If you maintain npm packages, check recent versions for releases you did not make.

What to watch

  • Updated package counts from CISA and the research teams as the investigation continues.
  • Registry-side responses from npm and GitHub on how packages are published and how tokens are protected.
  • Follow-up reports from Wiz and Unit 42 on how far the stolen secrets were used.

Sources

  • CISA, alert on the widespread supply chain compromise impacting the npm ecosystem, 23 September 2025, https://www.cisa.gov/news-events/alerts/2025/09/23/widespread-supply-chain-compromise-impacting-npm-ecosystem
  • Wiz Research, analysis of the Shai-Hulud npm supply chain attack, September 2025, https://www.wiz.io/blog/shai-hulud-npm-supply-chain-attack
  • Palo Alto Networks Unit 42, analysis of the npm supply chain attack, September 2025, https://unit42.paloaltonetworks.com/npm-supply-chain-attack/