CISA an urgent security alert in response to a large-scale software supply chain attack on npmjs.com, the world’s largest JavaScript package registry. A self-replicating worm, dubbed Shai-Hulud, has infiltrated more than 500 npm packages and injected malicious code that spreads aggressively, exploiting developer credentials and npm publish workflows.

After gaining initial access, possibly through a compromised maintainer account, Shai-Hulud deploys a sophisticated payload that scans for sensitive credentials stored in environment variables and local configuration files.
The malware targets GitHub Personal Access Tokens (PATs) and API keys for AWS, GCP, and Azure, exploiting common CI/CD practices where tokens are inadvertently retained. Once collected, the credentials are exported to an endpoint controlled by the attacker and simultaneously uploaded to a public GitHub repository named Shai-Hulud via the GitHub/user/repos API.
See also: CISA: US Federal Agency Network Breach via GeoServer
Shai-Hulud then uses an automated loop to access the npm registry with stolen tokens. Using the npm CLI, it injects malicious JavaScript into the input file, often index.js, of other packages in the developer's dependency tree.
After insertion, the worm executes the command 'npm version patch && npm publish –access public' to publish a modified version, thus perpetuating its spread.
The worm's self-replication mechanism exploits transitive dependencies: any project that depends on one of the compromised packages can inadvertently become a new host.

Ways of protection
CISA recommends immediate action to detect and remediate this breach:
- Examine all package-lock.json and yarn.lock files to identify packages released after September 16, 2025. Use npm audit and static analysis tools to highlight unexpected code changes or additional postinstall scripts.
- Rotate all developer credentials and revoke exposed GitHub PATs. Implement phishing-resistant multi-factor authentication (MFA) on every developer account, especially for connections to GitHub and the npm registry
- Implement IDS/IPS rules to monitor for abnormal SSH and HTTPS connections. Block outbound traffic to known suspicious destinations, including webhook.site domains, and check firewall logs for unexpected DNS queries and outbound connections to unknown IP ranges.
- Remove unnecessary GitHub applications and OAuth permissions. Enable branch protection rules, secret scanning, and security updates . Check webhooks and repository-level secrets for unauthorized changes.
- Pin dependencies to known safe versions released before September 16, 2025. Set strict semver ranges (e.g., “lodash”: “4.17.21”) in package.json to prevent unintended updates to compromised versions.
See also: Hackers exploit IMDS service to access cloud environments
Enhanced vigilance throughout the development pipeline is critical to stopping the spread of the worm and protecting the integrity of the npm ecosystem.
The Shai-Hulud on npmjs.com reveals once again how vulnerable the global software ecosystem can become when the is software supply chain. This is not a typical malicious library, but a self-replicating worm that deeply exploits developers’ workflows — from CI/CD pipelines to access tokens on GitHub and cloud services.

The significance of the incident is not limited to the npm community. npm is at the heart of almost every modern web or server-side project. A single infection can spread in a chain reaction to hundreds of applications, affecting businesses that may not even know they depend on the infected package. Shai-Hulud's aggressive tactic of releasing new infected versions automatically shows that attackers are betting on the convenience offered by dependency managers — the very tool that was built to make things easier for developers can be weaponized against them.
Development teams need to stop considering dependencies “safe by default” and adopt practices like version pinning, code reviews in external libraries , and constant monitoring for unexpected changes.
See also: Chrome: Vulnerabilities allow data leakage & system crashes
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
At the same time, platforms like GitHub and npm need to strengthen their detection of malicious activity, perhaps with machine learning that detects suspicious publish patterns or anomalies in the code. Shai-Hulud is a warning that attacks on supply chains are becoming increasingly automated and massive, threatening the trust that underpins the entire software industry.
