Threat Advisories:
🎧 Hive Force Labs: Critical Threats Affecting You This Week - 5 Minute Audio Intelligence Report
👥 Play Count: Loading...

Shai-Hulud: Massive npm Supply Chain Attack Infects Hundreds of Packages

Red | Attack Report
Download PDF

A major supply chain attack, dubbed “Shai-Hulud,” is targeting the npm ecosystem through phishing campaigns against maintainers, allowing attackers to compromise accounts and inject self-propagating malware into popular packages. The malicious code, often hidden in bundle.js, scans for and exfiltrates secrets while some variants attempt to expose private repositories and deploy malicious GitHub Actions. With at least 180 and possibly over 500 packages affected, including widely used utilities and vendor libraries, the incident represents one of the most severe threats to the JavaScript ecosystem.

What’s new on HivePro

Get through updates and upcoming events, and more directly in your inbox

Cybersecurity Leaders Dinner In Houston

Learn how to reduce your exposure to imminent risk & Network with Industry Peers

Hosted by former CISO, Al Lindseth and Threat Exposure Evangelist, Critt Golden.

Tuesday, October 7th, 2025
6.00 pm to 9.00 pm
Del Friscos Double Eagle Steakhouse, Houston TX