Blog
Shai-Hulud 2.0: The Worm Strikes Back
The malware plaguing the npm software registry spreads like the sandworms of Dune, replicating across hundreds of packages in a massive supply chain attack.
Even people who have never heard of “npm” have likely benefitted from its existence. Npm is the world’s largest Javascript registry, with over 17 million developers using it to download millions of npm packages and more than 150,000 companies using code from the library to build their products and keep operations running smoothly. However, downloading packages from the npm registry may have gotten riskier in recent months, thanks to the emergence of a nasty malware dubbed “Shai-Hulud”.
The Malware
Fans of Frank Herbert’s famous science-fiction series Dune know the “Shai-Hulud” to be alien sandworms large enough to swallow a town whole; terrors on the fictional planet of Arrakis. The malware plaguing the npm software registry takes on the name of these Dune monsters due to being a special type of malware called a “worm”, meaning it is designed not only to infect a target with a malicious payload, but to replicate and spread to other targets on their own. What it lacks in size compared to its namesake, the Shai-Hulud malware makes up for in how quickly it can spread to hundreds of npm packages before being contained.
The Shai-Hulud malware first made an appearance on September 15th, 2025, when security researchers from several organizations began detecting instances of it in hundreds of npm packages, resulting in a large-scale supply chain compromise as unwitting users downloaded the infected packages. While this outbreak was eventually contained, Shai-Hulud would make a comeback just a few months later in November 2025, this time under the name “Shai-Hulud 2.0.”
A technical breakdown for how Shai-Hulud 2.0 operated can be pieced together from data gathered by researchers at Datadog and BlackDuck:
- Initial access to an npm package was likely achieved through developer credentials stolen through phishing campaigns.
- This package was then trojanized by adding two malicious files, “setup_bun.js” and “bun_environment.js”, which triggered upon being downloaded by a user.
- Once downloaded, the now malicious package would harvest credentials from the user’s local filesystem and cloud environment, such as those for AWS, Google Cloud, and Azure. Notably, the package would also look for npm credentials that could give it access to other npm packages owned by the victim.
- Harvested credentials were then sent to a public GitHub repository with the description “Sha1-Hulud: The Second Coming.”
- Shai-Hulud’s payload also set up the GitHub self-install worker on the compromised machine, theoretically allowing an attacker to use GitHub features to remotely execute code.
- Shai-Hulud then self-propagated by using the victim’s npm credentials to backdoor up to 100 of the packages published by the victim on npm.
- Finally, if the malware was unable to replicate or exfiltrate data, it attempted to delete the victim’s home directory.
The Impact
As already mentioned, the first instance of Shai-Hulud resulted in a high-impact supply chain compromise, and Shai-Hulud 2.0 was similarly impactful. In November 2025, Shai-Hulud 2.0 took over at least 796 unique npm packages that together accounted for over 20 million weekly downloads. In an attempt to gauge the extent of the malware’s infections, researchers Christophe Tafani-Dereeper and Sebastian Obregoso at Datadog Security Labs scraped data from the GitHub Events API to find recently created repositories with the landmark description ““Sha1-Hulud: The Second Coming.”, and found over 14,000 repositories.
However, the researchers stressed that should be treated as a lower bound, “since some infected users with no GitHub credentials available on their system will see their data exfiltrated through the user of another compromised GitHub account.” Thankfully, most of the compromised packages have been taken down, but the number of repositories shows that, for the few hours they were up, they caused a lot of damage.
Thus far, there have been no reports of the masterminds behind Shai-Hulud using the command-and-control channel the malware set up on each compromised machine.
What Can You Do?
Shai-Hulud has reared its head twice already to great effect, so it’s not unlikely that hackers will attempt to use this worm again down the road. If you’re concerned about your ability to handle such supply-chain attacks, we at Crimson Vista offer several tools to improve your security posture and awareness, including a security-team-for-contract to bolster your own internal resources. Or, if you’re worried you may have already been impacted by a malware like Shai-Hulud, then we offer investigative services like DataVeracity which can provide a breach analysis for your company. Hackers are persistent, and the only way to truly protect your company against them is to be equally as persistent in protecting your systems and data.
Sources
Continue
Keep reading.
Psychology-Aware Security Design
Cybersecurity products need affordances that guide people toward the right actions under stress. Psychology-aware design is how defenders catch up with attackers who already use it.
AI: The New Face of Cybersecurity
OpenAI and Anthropic AI agents are escaping sandboxes and exploiting vulnerabilities at machine speed. Learn what the Hugging Face breach reveals about AI's growing role in offensive and defensive cybersecurity.
The Limitations of Hashing for Data Anonymization
Why using hashing alone is an incomplete anonymization process