Threat Advisories:
🎧 Hive Force Labs: October First Threat Research
👥 Play Count: Loading...

Shai-Hulud: Massive npm Supply Chain Attack Infects Hundreds of Packages

Red | Attack Report
Download PDF

A major supply chain attack, dubbed “Shai-Hulud,” is targeting the npm ecosystem through phishing campaigns against maintainers, allowing attackers to compromise accounts and inject self-propagating malware into popular packages. The malicious code, often hidden in bundle.js, scans for and exfiltrates secrets while some variants attempt to expose private repositories and deploy malicious GitHub Actions. With at least 180 and possibly over 500 packages affected, including widely used utilities and vendor libraries, the incident represents one of the most severe threats to the JavaScript ecosystem.

What’s new on HivePro

Get through updates and upcoming events, and more directly in your inbox