<img height="1" width="1" style="display: none" alt="" src="https://px.ads.linkedin.com/collect/?pid=1098858&amp;fmt=gif">

640 NPM Packages Hit by Destructive 'Shai-Hulud' Worm Attack

A new Shai-Hulud worm variant infects 640 NPM packages, targeting major platforms and threatening developer systems globally.
Content Team

A devastating supply chain attack has infected 640 NPM packages with the upgraded Shai-Hulud worm, targeting major platforms like AsyncAPI, PostHog, and Postman with over 130 million monthly downloads combined. The malware spreads through preinstall scripts, dramatically expanding its reach across developer machines and CI/CD pipelines.

Unlike the September version that infected 180 packages, this iteration is far more destructive. If it can't find GitHub or NPM tokens to steal, it wipes all user data on Windows systems and erases files on Unix machines. The worm also hijacks DNS, launches privileged Docker containers, and creates backdoors through GitHub Actions.

Security researchers warn they're seeing 1,000 new malicious packages published every 30 minutes, with over 25,000 infected repositories identified. Organizations should immediately scan for compromises, rotate all credentials, and strengthen pipeline security.

Source: Security Week

Share this article
Share on facebook Share on linkedin Share on twitter Share on email
blog_book_a_demo_cta_3x
Have questions about protecting your software?
Our escrow experts are standing by to help.
Book a free demo